Problemi sa internetom

1

Problemi sa internetom

offline
  • Pridružio: 10 Apr 2014
  • Poruke: 8

Prvo je počeo da izbacuje gomilu onih reklama sa strane,kao i neku reklamu na dnu stranice gde piše kao koliko je sigurna ta stranica.Na to sam nekako navikao,ali sad udjem na neki sajt prvo mi treba pola sata da pogasim sve reklame pa da vidim neku stranicu Bebee Dol Onda na YT plejer sljaka par sekundi onda pozeleni i prebaci se par sekudni pred kraj snimka,tako je na svakom plejeru na internetu negde pozeleni,a negde stane,ali vreme ide i ima zvuk,ali slika je zamrznuta.I da internet se enormno usporio u odnosu na ranije.

Koristim Chrome na windows 7,brzina je po speedtest-u sledeća:

ping:9ms
download:8,69Mbps
upolad:0.08Mpbs

Provajder je ADSL mislim da je onaj paket 10Mbps,tako nešto.

A da ni onaj sajt Browsercheck više ne pomaže,pre je radio pa sam sve držao up to date,ali sad samo vrti do besvesti.Anti virus je avast,on ne prijavljuje ništa ali me ovo ubi.

I da još jedno pitanje,jel se svima promenio Google ili samo meni,pojavio mi se neki toolbar odmah ispod pretrage i više mi ne otvara stranicu u istom tabu,već otvara novi tab?

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: BrowserJavaVersion: 10.45.2
Run by Korisnik at 18:09:58 on 2014-04-10
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.381.1033.18.2015.764 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\UnsignedThemesSvc.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
C:\Windows\system32\conhost.exe
C:\Program Files\PCDApp\dgen.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\Surftastic\updateSurftastic.exe
C:\Program Files\Surftastic\bin\utilSurftastic.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files\CyberLink\Shared files\brs.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Rainmeter\Rainmeter.exe
C:\Windows\system32\SearchIndexer.exe
C:\Users\Korisnik\AppData\Local\FilesFrog Update Checker\update_checker.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Surftastic\bin\FilterApp_C.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Surftastic\bin\Surftastic.BrowserAdapter.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\AVAST Software\Avast\setup\instup.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.whitesmoke.com/home.php?isid=10021
mStart Page = hxxp://search.whitesmoke.com/home.php?isid=10021
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Surftastic: {c6673938-a52b-4dc6-af05-783e7e2c8b65} - c:\program files\surftastic\Surftasticbho.dll
TB: avast! Online Security: {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [Xvid] c:\program files\xvid\CheckUpdate.exe
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [AVG-Secure-Search-Update_0913b] c:\users\korisnik\appdata\roaming\avg 0913b campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid bcf60a70045b47d0a4a7bd2b2bdf75e0-06cc2ba878f3998b5288a1c5c539d3394199042e --CMPID 0913b
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [RemoteControl10] "c:\program files\cyberlink\powerdvd10\PDVD10Serv.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
StartupFolder: c:\users\korisnik\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\users\korisnik\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\users\korisnik\appdata\roaming\micros~1\windows\startm~1\programs\startup\rainme~1.lnk - c:\program files\rainmeter\Rainmeter.exe
StartupFolder: c:\users\korisnik\appdata\roaming\microsoft\windows\start menu\programs\startup\Registration Lock On
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: EnableShellExecuteHooks = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:2
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Zuma/Images/stg_drm.ocx
DPF: {31150A86-0BBA-409F-BEB4-F3922D10BF34} - file:///C:/Users/Korisnik/AppData/Local/Microsoft/Windows%20Sidebar/Gadgets/xplugCam.gadget/en-US/xplug.ocx
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Zuma/Images/armhelper.ocx
TCP: NameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{C3BFA016-3C64-48F2-8FE0-79696CB443F2} : DHCPNameServer = 192.168.1.1 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs= c:\progra~1\assist~1.dll
STS: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\31.0.1650.63\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\korisnik\appdata\roaming\mozilla\firefox\profiles\cx8ept1r.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\browser\plugins\npdevalvr.dll
FF - plugin: c:\program files\nitro\reader 3\npdf.dll
FF - plugin: c:\program files\nitro\reader 3\npnitroie.dll
FF - plugin: c:\program files\nitro\reader 3\npnitromozilla.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1207148.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_12_0_0_77.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2014-1-12 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2014-1-12 180248]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-1-12 775952]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-1-12 410528]
R1 wStLibG;wStLibG;c:\windows\system32\drivers\wStLibG.sys [2014-4-8 52928]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/05/24 16:39:53];c:\program files\cyberlink\powerdvd10\navfilter\000.fcl [2010-6-28 87536]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-1-12 67824]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2014-1-12 50344]
R2 NitroReaderDriverReadSpool3;NitroPDFReaderDriverCreatorReadSpool3;c:\program files\nitro\reader 3\NitroPDFReaderDriverService3.exe [2012-10-30 196624]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-7-14 239648]
R2 UnsignedThemes;Unsigned Themes;c:\windows\UnsignedThemesSvc.exe [2009-7-13 21096]
R2 Update Surftastic;Update Surftastic;c:\program files\surftastic\updateSurftastic.exe [2014-4-4 350496]
R2 Util Surftastic;Util Surftastic;c:\program files\surftastic\bin\utilSurftastic.exe [2014-4-7 350496]
R2 uxpatch;uxpatch;c:\windows\system32\drivers\uxpatch.sys [2009-7-13 25448]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswstm.sys [2014-1-12 64168]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-5-24 327784]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 DefaultTabSearch;DefaultTabSearch;c:\program files\defaulttab\DefaultTabSearch.exe [2013-12-20 574464]
S2 ProtectMonitor;Protect Monitor;c:\program files\pcdapp\StartHelp.exe [2014-4-5 96972]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-7-28 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-5-24 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-5-24 52224]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2014-04-09 23:32:00 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2014-04-09 20:34:56 4296192 -c--a-w- c:\program files\Assistant.dll
2014-04-09 07:30:14 27072 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2014-04-09 07:30:14 234432 ----a-w- c:\windows\system32\drivers\msiscsi.sys
2014-04-09 07:30:14 2048 ----a-w- c:\windows\system32\iologmsg.dll
2014-04-09 07:30:14 149440 ----a-w- c:\windows\system32\drivers\storport.sys
2014-04-09 07:30:12 1212352 ----a-w- c:\windows\system32\drivers\ntfs.sys
2014-04-08 12:38:18 52928 ----a-w- c:\windows\system32\drivers\wStLibG.sys
2014-04-08 09:30:53 62576 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{25bd8eba-5baa-4b09-b518-5c83f3b79c01}\offreg.dll
2014-04-08 08:14:51 7969936 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{25bd8eba-5baa-4b09-b518-5c83f3b79c01}\mpengine.dll
2014-04-07 18:57:09 -------- d-----w- c:\users\korisnik\appdata\roaming\MiniGet
2014-04-07 18:56:08 -------- dc----w- c:\program files\MyPC Backup
2014-04-07 18:55:38 -------- d-----w- c:\users\korisnik\appdata\roaming\DefaultTab
2014-04-07 18:55:36 -------- dc----w- c:\program files\DefaultTab
2014-04-07 18:55:25 -------- d-----w- c:\users\korisnik\appdata\local\ChromeTabManager
2014-04-07 18:55:23 -------- dc----w- c:\program files\WhiteSmoke Search
2014-04-07 18:54:45 -------- dc----w- c:\program files\PCDApp
2014-04-07 18:54:42 -------- d-----w- c:\users\korisnik\appdata\local\41
2014-04-07 18:54:06 -------- dc----w- c:\program files\Surftastic
2014-04-02 15:55:46 -------- dc----w- c:\program files\Counter-Strike Source
2014-03-12 11:05:39 509440 ----a-w- c:\windows\system32\qedit.dll
2014-03-12 11:05:38 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-03-12 11:05:37 185344 ----a-w- c:\windows\system32\wwansvc.dll
2014-03-12 11:05:36 381440 ----a-w- c:\windows\system32\wer.dll
2014-03-12 11:05:36 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
.
==================== Find3M ====================
.
2014-03-11 20:32:10 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 20:32:10 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-07 23:12:00 1806848 ----a-w- c:\windows\system32\jscript9.dll
2014-03-07 23:02:19 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2014-03-07 23:02:07 1129472 ----a-w- c:\windows\system32\wininet.dll
2014-03-07 22:57:17 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2014-03-07 22:56:03 421376 ----a-w- c:\windows\system32\vbscript.dll
2014-01-26 15:55:49 12400 ----a-w- c:\windows\system32\drivers\secdrv.sys
2014-01-12 19:04:35 64168 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-01-12 19:03:55 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-01-12 19:03:55 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-01-12 19:03:55 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-01-12 19:03:55 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-01-12 19:03:54 79720 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-01-12 19:03:54 43152 ----a-w- c:\windows\avastSS.scr
.
============= FINISH: 18:11:31.99 ===============
mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Deinstaliraj sledece programe:

DefaultTab
Surftastic
WhiteSmoke Search





Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog ili ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sledeći tekst:


{c6673938-a52b-4dc6-af05-783e7e2c8b65};c
c:\program files\surftastic;fs
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r
"AVG-Secure-Search-Update_0913b"=-;r
c:\users\korisnik\appdata\roaming\avg 0913b campaign;fs
Update Surftastic;s
Util Surftastic;s
DefaultTabSearch;s
c:\program files\defaulttab;fs
ProtectMonitor;s
c:\program files\pcdapp;fs
c:\program files\MyPC Backup;fs
c:\users\korisnik\appdata\roaming\DefaultTab;fs
c:\program files\WhiteSmoke Search;fs
filesrcm;
startupall;
emptyalltemp;
autoclean;
emptyclsid;


Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 10 Apr 2014
  • Poruke: 8

Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by Korisnik on Thu 04/10/2014 at 19:18:36.93.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Korisnik\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

4/10/2014 7:19:34 PM Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\SearchScopes\{F2ED1F18-1316-40FD-BAAC-FF04B2885341} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3E532CE8-C6D9-4A10-8ACE-4348C96E8B6A} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3E532CE8-C6D9-4A10-8ACE-4348C96E8B6A} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{707DB484-2428-402D-AFB5-D85B387544C7} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{3E532CE8-C6D9-4A10-8ACE-4348C96E8B6A} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{99079A25-328F-4BD4-BE04-00955ACAA0A7} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{9D717F81-9148-4F12-8568-69135F087DB0} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{6E13D095-45C3-4271-9475-F3B48227DD9F} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311551174} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} deleted successfully
HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{fe063412-bea4-4d76-8ed3-183be6220d17} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4F07DA45-8170-4859-9B5F-037EF2970034} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{1984D045-52CF-49cd-DB77-08F378FEA4DB} deleted successfully

==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Update Surftastic deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Update Surftastic deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Util Surftastic deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Util Surftastic deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\DefaultTabSearch deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ProtectMonitor deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ProtectMonitor deleted successfully

==== FireFox Fix ======================

ProfilePath: C:\Users\Korisnik\AppData\Roaming\KompoZer\Profiles\7ocu5avf.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_20140410_0732_.backup

ProfilePath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default

---- Lines delta removed from prefs.js ----
user_pref("extensions.delta.admin", false);
user_pref("extensions.delta.aflt", "babsst");
user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
user_pref("extensions.delta.autoRvrt", "false");
user_pref("extensions.delta.dfltLng", "en");
user_pref("extensions.delta.excTlbr", false);
user_pref("extensions.delta.ffxUnstlRst", true);
user_pref("extensions.delta.id", "ac0a69450000000000006c626d3b9c13");
user_pref("extensions.delta.instlDay", "15928");
user_pref("extensions.delta.instlRef", "sst");
user_pref("extensions.delta.newTab", false);
user_pref("extensions.delta.prdct", "delta");
user_pref("extensions.delta.prtnrId", "delta");
user_pref("extensions.delta.rvrt", "false");
user_pref("extensions.delta.smplGrp", "none");
user_pref("extensions.delta.tlbrId", "base");
user_pref("extensions.delta.tlbrSrchUrl", "");
user_pref("extensions.delta.vrsn", "1.8.22.0");
user_pref("extensions.delta.vrsnTs", "1.8.22.015:13:06");
user_pref("extensions.delta.vrsni", "1.8.22.0");
user_pref("extensions.delta_i.babExt", "");
user_pref("extensions.delta_i.babTrack", "affID=119776&tt=070813_wt3&tsp=4971");
user_pref("extensions.delta_i.srcExt", "ss");
user_pref("extensions.ffxtlbr@delta.com.install-event-fired", true);
---- Lines babylon removed from prefs.js ----
user_pref("extensions.BabylonToolbar.prtkDS", 0);
user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
---- Lines Customized removed from prefs.js ----
user_pref("extensions.testpilot.alreadyCustomizedToolbar", true);
---- Lines 99079a25-328f-4bd4-be04-00955acaa0a7 removed from prefs.js ----
user_pref("extensions.{99079a25-328f-4bd4-be04-00955acaa0a7}.install-event-fired", true);
---- Lines gophoto.it removed from prefs.js ----
user_pref("extensions.gophoto@gophoto.it.install-event-fired", true);
---- Lines defaulttab modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST So
---- Lines Sweet removed from prefs.js ----
user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
user_pref("sweetim.toolbar.previous.browser.startup.homepage", "");
user_pref("sweetim.toolbar.previous.keyword.URL", "");
user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
user_pref("sweetim.toolbar.searchguard.enable", "");
user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "");
user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "");
---- Lines 1FD91A9C-410C-4090-BBCC-55D3450EF433 removed from prefs.js ----
user_pref("extensions.{1FD91A9C-410C-4090-BBCC-55D3450EF433}.install-event-fired", true);
---- Lines extensions.5020355d305ce removed from prefs.js ----
user_pref("extensions.5020355d305ce.epoch", "1366740060");
user_pref("extensions.5020355d305ce.url", "http://jpi-syncer.info/sync/?ext=codecc&pid=152&country=RS®d=120806212133&lsd=130422175757&uid=50250d99d
---- Lines extensions.cjpHS removed from prefs.js ----
user_pref("extensions.cjpHS.epoch", "1397054515");
user_pref("extensions.cjpHS.url", "http://getjpinet.info/sync2/?q=hfZ9ofx6pftQtNbPhd9EtMqLDe49CNU0kVrMCMlNhd9FrHwGrHwFpjsErTUMBzqUojw9rdnEpdw9qdwHrih7
---- Lines extensions.rXuhhU removed from prefs.js ----
user_pref("extensions.rXuhhU.epoch", "1397054515");
user_pref("extensions.rXuhhU.url", "http://jobfirstall.in/sync2/?q=hfZ9oeZNAdkMCyVUojaMg708BNmGWj8ikGhGheDUojwHrjsHrjw4rTa9pchIC7n0rjnEqda5rjn9rdk7tNh
---- FireFox user.js and prefs.js backups ----

user_20140410_0732_.backup
prefs_20140410_0732_.backup

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG-Secure-Search-Update_0913b"=-

==== Deleting Files \ Folders ======================

c:\program files\surftastic not found
c:\users\korisnik\appdata\roaming\avg 0913b campaign not found
c:\program files\defaulttab not found
c:\users\korisnik\appdata\roaming\DefaultTab not found
c:\program files\WhiteSmoke Search not found
c:\program files\MyPC Backup deleted
C:\PROGRA~2\dbmlcjdlpkoahogmmjdcmeoeicnneplo deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\{3DC8E525-A2F3-AD6F-9EBC-D5E7426BD95B} deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\{69172144-BDEF-4CEC-1178-A2B240F2D0EC} deleted
C:\PROGRA~2\27f535f00064b90b deleted
C:\PROGRA~2\JooniCoupon deleted
C:\PROGRA~2\Fun2Save deleted
C:\Program Files\Assistant.dll deleted
C:\Program Files\Uninstall Information\ib_uninst_0 deleted
C:\Program Files\Uninstall Information\ib_uninst_312 deleted
C:\Program Files\BonanzaDeals deleted
C:\Program Files\Sk.Enhancer deleted
C:\Program Files\SProtector deleted
C:\Users\Korisnik\AppData\Roaming\Thinstall deleted
C:\Users\Korisnik\AppData\Roaming\ExpressFiles deleted
C:\Users\Korisnik\AppData\Roaming\Registry Mechanic deleted
C:\Users\Korisnik\AppData\Roaming\GetRightToGo deleted
C:\PROGRA~2\GBox deleted
C:\PROGRA~2\StarApp deleted
C:\PROGRA~2\AVG Security Toolbar deleted
C:\PROGRA~2\Speed Streamer deleted
C:\PROGRA~2\QuickSet deleted
C:\PROGRA~2\Codec deleted
C:\PROGRA~2\InstallMate deleted
C:\PROGRA~2\Tarma Installer deleted
C:\PROGRA~2\Babylon deleted
C:\PROGRA~2\Package Cache deleted
C:\PROGRA~2\Trymedia deleted
C:\Users\Korisnik\AppData\Local\Thinstall deleted
C:\Users\Korisnik\AppData\Local\WebPlayer\AppsHat deleted
C:\Users\Korisnik\AppData\Local\AppsHat Mobile Apps deleted
C:\Users\Korisnik\AppData\Local\WebPlayer deleted
C:\Users\Korisnik\AppData\Local\Cool_Mirage deleted
C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat deleted
C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker deleted
C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com deleted
C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart deleted
C:\Users\Korisnik\AppData\LocalLow\DataMngr deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Nation toolbar deleted
C:\Windows\system32\tasks\AmiUpdXp deleted
C:\Windows\tasks\ParetoLogic Registration3.job deleted
C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job deleted
C:\Windows\tasks\ParetoLogic Update Version3.job deleted
C:\Windows\system32\Tasks\Express FilesUpdate deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\searchplugins\babylon.xml deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\Invalidprefs.js deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\CT1750559 deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\CT2247187 deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\CT2786678 deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\extensions\qea-mh@r-veij.com deleted
C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\extensions\qxp0-yd5@hqetqpnd.org deleted
"C:\ProgramData\ReminderNextRun" deleted
"c:\program files\PCDApp\dgen.exe" deleted
"c:\program files\PCDApp\libcurl-4.dll" deleted
"c:\program files\PCDApp\pthreadGC2.dll" deleted
"C:\Users\Korisnik\AppData\Local\FilesFrog Update Checker\update_checker.exe" deleted
"C:\Users\Korisnik\AppData\Local\FilesFrog Update Checker\update_checker.exe" deleted
"C:\Users\Korisnik\AppData\Roaming\MiniGet" deleted
"c:\program files\PCDApp" not deleted
"C:\Users\Korisnik\AppData\Local\FilesFrog Update Checker" deleted
"C:\Users\Korisnik\AppData\Local\FilesFrog Update Checker" deleted

==== Files Recently Created / Modified ======================

====== C:\Windows ====
====== C:\Users\Korisnik\AppData\Local\Temp ====
2014-04-09 20:34:41 23912DF27A61EA0463C5509BA6A97579 4983808 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\{147E5308-4331-4001-A2EA-0B13CF9D71FE}\Addons\assistant_v3.exe
2014-04-09 20:34:37 E717F6CE3A7429BFA6D7F3CF66737A4B 15968 --s---r- C:\Users\Korisnik\AppData\Local\Temp\{147E5308-4331-4001-A2EA-0B13CF9D71FE}\Setup.exe
2014-04-09 20:34:37 D2B596FA229E1B03704C9E9C3B4D4AA0 93696 --s---r- C:\Users\Korisnik\AppData\Local\Temp\{147E5308-4331-4001-A2EA-0B13CF9D71FE}\Custom.dll
2014-04-09 20:34:37 BE16F8D320DA824F0DB58EF6D75C75C6 177664 --s---r- C:\Users\Korisnik\AppData\Local\Temp\{147E5308-4331-4001-A2EA-0B13CF9D71FE}\_Setup.dll
2014-04-09 20:34:34 AF7CE801C8471C5CD19B366333C153C4 275552 --s---r- C:\Users\Korisnik\AppData\Local\Temp\TsuE2D437F6.dll
2014-04-07 18:57:06 3B59515D6422423C08F40792B281FA18 697949 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\6_Offer_5.exe
2014-04-07 18:55:54 45922155C9628E11441AA869C6287BB7 10372136 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\BackupSetup.exe
2014-04-07 18:55:13 E5F5516144E2F51990E4D91A924AE615 1384560 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\instruct.exe
2014-04-07 09:19:20 CA33F19E3299129600899CA875BC88A4 173168 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\MyPCBackupRevshare.exe
2014-03-30 12:47:53 E2F5147A72BFAD06DD4FCAA87B0D5E19 347648 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\TransmogProvider.dll
2014-03-30 12:47:53 D4325A0D58442D54E9EC1AFDAEFE42A7 242688 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\UnattendProvider.dll
2014-03-30 12:47:53 C1A9CAFB63831DB7C752E3E34798D713 345600 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\WimProvider.dll
2014-03-30 12:47:53 BC72ACDF946DCEBF708F2CE12E2E2F68 159744 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\MsiProvider.dll
2014-03-30 12:47:53 A399514D3B28C9A3453A486BBAAFF1C7 189952 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\wdscore.dll
2014-03-30 12:47:53 9A792DF9EC185DB78926625D538138FF 49152 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\FolderProvider.dll
2014-03-30 12:47:53 65F53BBA060110B4D914CCBA59601A97 220160 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\SmiProvider.dll
2014-03-30 12:47:53 48FCFB47484EA1C24C32D24DEA1A64E4 250880 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\IntlProvider.dll
2014-03-30 12:47:53 4270B20EDB0BB5C22530F55912A3AF08 102912 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\OSProvider.dll
2014-03-30 12:47:52 F7B53B4BD50C13D17F5C54F82CDE7836 82944 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\DismHost.exe
2014-03-30 12:47:52 E8204977BC6E3688C230997A3439D9C9 50688 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\DismCorePS.dll
2014-03-30 12:47:52 D63E6549994AA674244DF0D865CB3E18 230912 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\DismCore.dll
2014-03-30 12:47:52 CC0BDDF6D62624EDA518314145085E0A 318464 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\DmiProvider.dll
2014-03-30 12:47:52 8DEA6A74055FCBC2130F870B2A13ACE8 141312 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\DismProv.dll
2014-03-30 12:47:52 7E3CB248FAB83B591F4E94E8CEB0093E 141312 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\CompatProvider.dll
2014-03-30 12:47:52 66CD52C26F0EEA6FC4B6610BC271DA2C 541184 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\448363D1-5C88-49D9-9870-D30165CB2987\CbsProvider.dll
====== Java Cache =====
2014-03-31 20:34:15 4DB9365FFDEDF03D1369D11D38CC88BA 11440 ----a-w- C:\Users\Korisnik\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34\67a14222-30ae77fa
====== C:\Windows\system32 =====
2014-04-09 23:32:00 BC63D80B6810238266D4334A80783D60 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2014-04-09 23:32:00 AC65D9692CA56D8581F75FCFE0C0C4D6 73216 ----a-w- C:\Windows\System32\mshtmled.dll
2014-04-09 23:31:59 D20FBD7E03F24A2720EAD746EADEE5A2 176640 ----a-w- C:\Windows\System32\ieui.dll
2014-04-09 23:31:59 4C43E955E8F782E722659364341E0529 65024 ----a-w- C:\Windows\System32\jsproxy.dll
2014-04-09 23:31:59 447C9FADAC167AA7031328C11464C7D0 421376 ----a-w- C:\Windows\System32\vbscript.dll
2014-04-09 23:31:58 DCEBA94B909C218BA2E471AEB9913E1C 607744 ----a-w- C:\Windows\System32\msfeeds.dll
2014-04-09 23:31:58 48CB5C9B0942011010F5504F056FBF4E 142848 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-04-09 23:31:57 E8E0342BC443D013E8806EE1B69C1FC7 717824 ----a-w- C:\Windows\System32\jscript.dll
2014-04-09 23:31:57 6D4BC1F977EDF186A8C68152BFB43769 1806848 ----a-w- C:\Windows\System32\jscript9.dll
2014-04-09 23:31:57 62077F806BC59CBD5A404338D710D133 1129472 ----a-w- C:\Windows\System32\wininet.dll
2014-04-09 23:31:57 077B7BE0796C9DA2E8C45F90496CFE36 231936 ----a-w- C:\Windows\System32\url.dll
2014-04-09 23:31:56 46F8078ED1D499BF8149B7FDF915E5D5 1796096 ----a-w- C:\Windows\System32\iertutil.dll
2014-04-09 23:31:55 25B97E6F25AFDA7EA0C9BF3CB137B4D8 1105408 ----a-w- C:\Windows\System32\urlmon.dll
2014-04-09 23:31:54 D15B8C3BD0F2F6F520A10D5CFCE68879 9739264 ----a-w- C:\Windows\System32\ieframe.dll
2014-04-09 23:31:54 8229FB32D999CDD1DFA731E8E2E510A4 1427968 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-04-09 23:31:52 10D0FA4F2A6ADBEEA0FFF10583CC5407 12347904 ----a-w- C:\Windows\System32\mshtml.dll
2014-04-09 07:30:11 F74FFA7654702F81884BDB41EB80DAC2 868352 ----a-w- C:\Windows\System32\kernel32.dll
====== C:\Windows\system32\drivers =====
2014-04-09 07:30:14 F1A449D762657230629D8BFC107ABC14 149440 ----a-w- C:\Windows\System32\drivers\storport.sys
2014-04-09 07:30:14 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2014-04-09 07:30:14 5FB4F271032B6435F3B2252F577A4815 27072 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-04-09 07:30:12 C8DFF8D07755A66C7A4A738930F0FEAC 1212352 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-04-08 12:38:18 C27BA9997D1BB1AC88B5A690656D5456 52928 ----a-w- C:\Windows\System32\drivers\wStLibG.sys
====== C:\Windows\Tasks ======
2014-04-07 18:54:42 A31526228CAF5668FA2E4B98EC5886F1 350 ----a-w- C:\Windows\Tasks\AmiUpdXp.job
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-04-07 18:54:45 -------- dc----w- C:\Program Files\PCDApp
2014-04-02 15:55:46 -------- dc----w- C:\Program Files\Counter-Strike Source
======= C: =====
====== C:\Users\Korisnik\AppData\Roaming ======
2014-04-08 23:00:25 -------- d-----w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-07 18:54:42 -------- d-----w- C:\Users\Korisnik\AppData\Local\41
2014-04-02 16:04:25 -------- d-----w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
====== C:\Users\Korisnik ======
2014-04-09 20:34:30 80F33C57FF51A52B5E62CBFA78041867 323784 ----a-w- C:\Users\Korisnik\Downloads\???????? ????? - ???????? ??????????.exe
2014-04-07 18:52:18 7860B0534C1020CE4BAC37B252A21914 352256 ----a-w- C:\Users\Korisnik\Downloads\Cheats For Cs 1.6.rar__3039_i539768228_il3423283.exe
2014-04-04 09:41:43 D15CF50AD89600B0AEF5B01456D99799 257291214 ----a-w- C:\Users\Korisnik\Downloads\Counter Strike 1.6 FULL v44 - Protocol 48 Clean.exe
2014-04-02 16:04:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source

====== C: exe-files ==
2014-04-09 23:31:58 BBC3D21C78230F38EF1B77309B82650A 468480 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe
2014-04-09 23:31:58 48CB5C9B0942011010F5504F056FBF4E 142848 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-04-09 20:34:41 23912DF27A61EA0463C5509BA6A97579 4983808 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\{147E5308-4331-4001-A2EA-0B13CF9D71FE}\Addons\assistant_v3.exe
2014-04-09 20:34:41 23912DF27A61EA0463C5509BA6A97579 4983808 ----a-w- C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RD1X3N36\tpq[1].exe
2014-04-09 20:34:37 E717F6CE3A7429BFA6D7F3CF66737A4B 15968 --s---r- C:\Users\Korisnik\AppData\Local\Temp\{147E5308-4331-4001-A2EA-0B13CF9D71FE}\Setup.exe
2014-04-09 20:34:30 80F33C57FF51A52B5E62CBFA78041867 323784 ----a-w- C:\Users\Korisnik\Downloads\???????? ????? - ???????? ??????????.exe
2014-04-08 10:00:54 ED5593648E4A7B14E8667570DE1CBA07 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$I39X19R.exe
2014-04-08 10:00:54 9E99DD8471E01AE8659B9C3DD0A944B3 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$IPI1PIS.exe
2014-04-08 10:00:54 859B3F5964437BD36321BD02A8155268 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$I5G57FE.exe
2014-04-08 10:00:54 6B291B686B406D9667E8984A33DBAE3F 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$IBTHAQQ.exe
2014-04-08 10:00:54 5EE895B8FE0D9CA64B4D9F6B15658B6D 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$IPVIH16.exe
2014-04-08 10:00:54 3F27B7E5C67BD442B8B8F94CA2499415 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$IIWLUGD.exe
2014-04-08 10:00:54 3D4228BCDE0234318CF457406AA69B11 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$ITMI3GA.exe
2014-04-08 10:00:52 F33DE70588E7168A4C5F5F758A2ADFAD 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$ID0SA1Y.exe
2014-04-08 10:00:52 06E9791F10FEA479CA46AEE1824930CC 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$I6JHKZW.exe
2014-04-07 18:57:06 3B59515D6422423C08F40792B281FA18 697949 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\6_Offer_5.exe
2014-04-07 18:57:06 3B59515D6422423C08F40792B281FA18 697949 ----a-w- C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RD1X3N36\Setup_product_8181[1].exe
2014-04-07 18:56:10 B3F12E4C4AAFB56E945ED48D8647B563 85094 -c--a-w- C:\$RECYCLE.BIN\S-1-5-21-457889968-920633692-2427081306-1000\$R5G57FE.exe
2014-04-07 18:55:54 45922155C9628E11441AA869C6287BB7 10372136 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\BackupSetup.exe
2014-04-07 18:55:45 9CAE9C4F3A749FE82B2AB1CB8A28B6DD 1294944 ----a-w- C:\Windows\temp\dts6743\deftabupdate.exe
2014-04-07 18:55:23 C1C04CBB44F365C9B015CADFE8B15F45 197096 ----a-w- C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GRGF8QJY\MyPCBackupRevshare_Install[1].exe
2014-04-07 18:55:21 93003B120AA60A4DE5E20CAA858061D1 2461320 ----a-w- C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GRGF8QJY\DefaultTabSetup[1].exe
2014-04-07 18:55:20 1A6A786C6DAEA391EC284D2171D8F2CB 1593253 ----a-w- C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RD1X3N36\whitesmokesearch[1].exe
2014-04-07 18:55:13 E5F5516144E2F51990E4D91A924AE615 1384560 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\instruct.exe
2014-04-07 18:54:42 6A901F8E4CD3A56D97D6C24EB70A45A3 292936 ----a-w- C:\Users\Korisnik\AppData\Local\41\a18467.exe
2014-04-07 18:54:02 D16C8AABD8B9CE4A89942583E1DA3AE0 2058424 ----a-w- C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\76IPTSYR\Setup[1].exe
2014-04-07 18:52:18 7860B0534C1020CE4BAC37B252A21914 352256 ----a-w- C:\Users\Korisnik\Downloads\Cheats For Cs 1.6.rar__3039_i539768228_il3423283.exe
2014-04-07 09:19:20 CA33F19E3299129600899CA875BC88A4 173168 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\MyPCBackupRevshare.exe
2014-04-04 17:53:34 0B62417DA5719B3EA1D343DA3431C97F 167544 ----a-w- C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RD1X3N36\FLVPlayerUpdate_downloader_by_FLVPlayerUpdate[1].exe
2014-04-04 09:41:43 D15CF50AD89600B0AEF5B01456D99799 257291214 ----a-w- C:\Users\Korisnik\Downloads\Counter Strike 1.6 FULL v44 - Protocol 48 Clean.exe
=== C: other files ==
2014-04-09 07:30:14 F1A449D762657230629D8BFC107ABC14 149440 ----a-w- C:\Windows\System32\drivers\storport.sys
2014-04-09 07:30:14 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\DriverStore\FileRepository\iscsi.inf_x86_neutral_128be931e3e98b62\msiscsi.sys
2014-04-09 07:30:14 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2014-04-09 07:30:14 5FB4F271032B6435F3B2252F577A4815 27072 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-04-09 07:30:12 C8DFF8D07755A66C7A4A738930F0FEAC 1212352 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-04-08 12:38:18 C27BA9997D1BB1AC88B5A690656D5456 52928 ----a-w- C:\Windows\System32\drivers\wStLibG.sys
2014-04-04 12:23:15 65E5164CD2EDC2DF762DCAF25F67E943 107057783 ----a-w- C:\Users\Korisnik\Downloads\THCF(2014).zip
2014-04-04 10:02:51 C8B4174498BE1AE1422363C2EC4060C2 9364601 ----a-w- C:\Users\Korisnik\Downloads\zbot_cs16.zip
2014-04-03 20:53:27 1BE3E0E3ED791E8CFE44E5D9923811B6 2624052 ----a-w- C:\Users\Korisnik\Downloads\cs_italy2_port.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Xvid"="C:\Program Files\XviD\CheckUpdate.exe"
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe"
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe /MINIMIZED"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s"
"RemoteControl10"="C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
"BDRegion"="C:\Program Files\Cyberlink\Shared files\brs.exe"
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"AdobeAAMUpdater-1.0"="C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Xvid"="C:\Program Files\XviD\CheckUpdate.exe"
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe"
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe /MINIMIZED"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" c:\\progra~1\\assist~1.dll"

==== Startup Registry Disabled ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="uTorrent"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\uTorrent\\uTorrent.exe\" /MINIMIZED"


==== Startup Folders ======================

2013-05-20 13:51:09 919 ----a-w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
2011-05-30 13:39:42 1276 ----a-w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
2013-04-21 18:16:37 1843 ----a-w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
2014-03-05 16:53:05 0 ----a-w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Lock On

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [03/11/2014 10:32 PM]
C:\Windows\tasks\AmiUpdXp.job --a------ C:\Users\Korisnik\AppData\Local\41\a18467.exe [04/07/2014 08:53 PM]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [06/17/2011 12:11 AM]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [06/17/2011 12:11 AM]

==== Other Scheduled Tasks ======================

"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\AdobeAAMUpdater-1.0-Korisnik-PC-Korisnik" [C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\Open URL by RoboForm" [C:\Windows\system32\rundll32.exe url.dll,FileProtocolHandler "http://www.roboform.com/uninstall.html?aaa=KICMPMMMNJMJKJMJPMMMCNMMNJPMHMCNLMMMNJNMCNGMMJJMNJCNMMNMOMMJLMHMPMGMKMNMNMMJJNJICMIMCNJMCNKMFMGMCNPMCNHMOMOMNMFMJMCNOMCNIMJMPMOMCNNMJNPICMPMFMFMPMJNHICMOMOMKJIJPIJNBJCMELAJNIGJMIBJGJEJJNKJCMJNNICMJNDJCMKJBJ"]
"C:\Windows\system32\tasks\Run RoboForm TaskBar Icon" [C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe]
"C:\Windows\system32\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe]
"C:\Windows\system32\tasks\{150F0C94-A55C-47AA-AF24-AEF029201BC6}" [C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe]
"C:\Windows\system32\tasks\{311FA76A-5594-44B2-8BC8-6E0664E93D91}" [C:\Program Files\EA GAMES\Medal of Honor Pacific Assault(tm)\mohpa_setup.exe]
"C:\Windows\system32\tasks\{3D6C96A8-0534-4595-83D1-66C52B46D889}" [C:\Users\Korisnik\Desktop\Grand Theft Auto Vice City - PC\gta-vc.exe]
"C:\Windows\system32\tasks\{498AE352-7605-4B6C-965A-71E56BDF27B3}" [C:\Users\Korisnik\Desktop\Login.exe]
"C:\Windows\system32\tasks\{4A692F5F-732E-41E1-BEE8-FD004DCC2972}" [C:\Users\Korisnik\Desktop\Grand Theft Auto Vice City - PC\gta-vc.exe]
"C:\Windows\system32\tasks\{4D24060C-D670-4CA5-9734-C8C43B24F9D5}" [C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe]
"C:\Windows\system32\tasks\{51741DCC-D14C-435E-9EAD-7E8CD25C5DAC}" [C:\Program Files\rFactor\rfactor.exe]
"C:\Windows\system32\tasks\{60A94020-4DB8-4A5D-9939-68FFE5BBFEBD}" [C:\Program Files\Mount&Blade With Fire and Sword\mb_wfas.exe]
"C:\Windows\system32\tasks\{758CBF40-2756-42D2-8D7A-B2ADEB1A96B2}" [C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe]
"C:\Windows\system32\tasks\{8223B055-A479-48AD-9736-6C269C228744}" [C:\Program Files\Mozilla Firefox\firefox.exe]
"C:\Windows\system32\tasks\{8775BA3B-99F2-46F1-A2E9-3DD0A03C865D}" [C:\Program Files\Mozilla Firefox\firefox.exe]
"C:\Windows\system32\tasks\{D1B76BED-D388-4E30-9C93-84FD831D01D7}" [C:\Program Files\Skype\\Phone\Skype.exe]
"C:\Windows\system32\tasks\{E202B4B1-73E2-4703-B646-EFC375108B6B}" [C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe]
"C:\Windows\system32\tasks\{EA8326BF-B4C6-4174-93C3-0B5E865F90B3}" [C:\Program Files\Call of Duty\CoDSP.exe]
"C:\Windows\system32\tasks\{F416B902-6483-48C4-A4FE-591FD9267D31}" [C:\Program Files\Mozilla Firefox\firefox.exe]

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [01/12/2014 09:03 PM]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Korisnik\AppData\Roaming\KompoZer\Profiles\7ocu5avf.default
- Undetermined - %ProfilePath%\extensions\installed-extensions.txt
- KompoZer classic - %ProfilePath%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default
95812430959AE88CDD0301AB3A71913B - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash
01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.1.0.30401.0.dll - Silverlight Plug-In
01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In
AC987EE8037531807C5D7E6217A23501 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
EB41064BC07017F5694CF16B4DEF6B10 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
F3B0E300AFC94E1A775A2D935A7D384F - C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll - Shockwave for Director / Shockwave for Director
C36444D7301A8C881FC7296B092609C7 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update
6768C724599214E4F9ADD9F8FF5097EB - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U45
F1CD6E22E5AE5CEEB7712E546A5FC853 - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.450.18
41601A5A4964B1B4A95EF48556A90ECF - C:\Program Files\Mozilla Firefox\browser\plugins\npdevalvr.dll - DevalVR 3D Plugin
2B78086E45508ED59364CE75179D729B - C:\Program Files\Nitro\Reader 3\npnitromozilla.dll - Nitro PDF plugin for Firefox and Chrome
C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery
28986F0A2342A033345EF9E70D395E4F - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight
B7B85962BFCFEFECE806A2A2025AA60E - C:\Program Files\Nitro\Reader 3\npdf.dll - Nitro PDF Library
4461D2F67A9597EEFC7FA1ED8E251A41 - C:\Program Files\Nitro\Reader 3\npnitroie.dll - Nitro PDF plugin for Internet Explorer


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
dabdfledpacnchclffbandlhdhhojbba - C:\ProgramData\Codecv\dabdfledpacnchclffbandlhdhhojbba.crx[]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[01/12/2014 09:03 PM]
lgnbhdnimikkoodkogjlcllngimhlapp - C:\Program Files\FTDownloader.com\FTDownloader10.crx[]
mpieaakhacmfleokhjcjnpcnmnmpfkid - No path found[]

Web Cake - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh
DefaultTab - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
GoPhoto.it - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk

==== Chrome Fix ======================

C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_b.scorecardresearch.com_0.localstorage deleted successfully
C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_b.scorecardresearch.com_0.localstorage-journal deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc deleted successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page Restore"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{A88948CC-8739-4D0A-B6ED-56E156DB0010}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A88948CC-8739-4D0A-B6ED-56E156DB0010}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page Restore"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{25477387-2310-45df-933D-E9416D3D0303} eSnips Search Url="http://eis.esnips.com/page/search_provider/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d&q={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2A63FC0C-AB64-AEE8-CBC0-2D47C669C181} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C7711827-87C6-4533-64F5-B7663BF191EF} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CCB8A1AD-5F75-0F8C-EA69-E8C383D76935} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F16021C5-C292-DF14-F7D4-4F42107733BA} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{F4B4DC31-1175-AC50-2922-2B555E471BB7} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dabdfledpacnchclffbandlhdhhojbba deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\lgnbhdnimikkoodkogjlcllngimhlapp deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\mpieaakhacmfleokhjcjnpcnmnmpfkid deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{51417852-174C-88D4-34A0-D0FE7858BE47} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{916e5338} deleted successfully

==== Empty IE Cache ======================

C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Korisnik\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Korisnik\AppData\Local\Mozilla\Firefox\Profiles\cx8ept1r.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=597 folders=169 46714824 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Korisnik\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Korisnik\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
"c:\program files\PCDApp" not found

==== EOF on Thu 04/10/2014 at 19:39:54.34 ======================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S0].txt





*******************************************





Ponovo pokreni zoek ;


zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;


U beli okvir prozora iskopiraj sledeći tekst:


autoclean;
C:\Users\Korisnik\AppData\Local\41;fs
C:\Windows\tasks\AmiUpdXp.job;f
Undetermined;ff
dabdfledpacnchclffbandlhdhhojbba;chr
lgnbhdnimikkoodkogjlcllngimhlapp;chr
mpieaakhacmfleokhjcjnpcnmnmpfkid;chr
fjoijdanhaiflhibkljeklcghcmmfffh;chr
kdidombaedgpfiiedeimiebkmbilgmlc;chr
{25477387-2310-45df-933D-E9416D3D0303};c
emptyalltemp;
emptyclsid;
filesrcm;
startupall;
emptyrecycle.bin;





Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 10 Apr 2014
  • Poruke: 8

# AdwCleaner v3.023 - Report created 10/04/2014 at 20:05:49
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Korisnik - KORISNIK-PC
# Running from : C:\Users\Korisnik\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\user.js
File Deleted : C:\Windows\Tasks\AmiUpdXp.job

***** [ Shortcuts ] *****


***** [ Registry ] *****

[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BA2E6290-952E-43E6-B90A-51956DF7D131}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BA2E6290-952E-43E6-B90A-51956DF7D131}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{19751955-59F8-4580-B945-F1352894F56D}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{19751955-59F8-4580-B945-F1352894F56D}
Key Deleted : HKCU\Software\Classes\pokki
Key Deleted : HKLM\SOFTWARE\Classes\FTDownloader
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ftdownloader v4_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ftdownloader v4_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKLM\SOFTWARE\a55de88b235e844
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_aimp_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_aimp_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_call-of-duty-2_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_call-of-duty-2_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_daemon-tools_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_daemon-tools_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_electronic-piano_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_electronic-piano_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_free-fire-screensaver_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_free-fire-screensaver_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_guitar-pro_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_guitar-pro_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A0B10EBE-4E51-4CAE-949B-E6B9E7D68CEA}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Somoto
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKCU\Software\WEDLMNGR
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Delta
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\ParetoLogic
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\Software\Trymedia Systems
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4

***** [ Browsers ] *****

-\\ Internet Explorer v0.0.0.0


-\\ Mozilla Firefox v27.0 (en-US)

[ File : C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default\prefs.js ]

Line Deleted : user_pref("aol_toolbar.default.homepage.check", false);
Line Deleted : user_pref("aol_toolbar.default.search.check", false);
Line Deleted : user_pref("extensions.plugin@getwebcake.com.install-event-fired", true);
Line Deleted : user_pref("extensions.plugins@getwebcake.com.install-event-fired", true);
Line Deleted : user_pref("extentions.webcake.defaultEnableAppsList", "layers,brain/features,newOffers/wc");
Line Deleted : user_pref("extentions.webcake.installId", "8719cd36-8771-4c25-a0ab-d9d5702e569e");

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [7356 octets] - [10/04/2014 20:04:51]
AdwCleaner[S0].txt - [7524 octets] - [10/04/2014 20:05:49]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7584 octets] ##########

A zoek nece da pokrene,jel trebam opet da skidam ili?Kolje se sa Avastom,a kad iskljucim Avast on me baci u neki boot scan i skenira neki djavo Very Happy

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Prekini boot scan, sigurno si ga zakazao kad si petljao oko avasta Smile
Iskljuci Avast pa pokreni zoek.

offline
  • Pridružio: 10 Apr 2014
  • Poruke: 8

Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by Korisnik on Thu 04/10/2014 at 22:10:01.92.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Korisnik\Downloads\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-04-10-173954.log 42178 bytes

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG-Secure-Search-Update_0913b"=-

==== Deleting Files \ Folders ======================

c:\program files\surftastic not found
c:\users\korisnik\appdata\roaming\avg 0913b campaign not found
c:\program files\defaulttab not found
c:\program files\pcdapp not found
c:\program files\MyPC Backup not found
c:\users\korisnik\appdata\roaming\DefaultTab not found
c:\program files\WhiteSmoke Search not found

==== Files Recently Created / Modified ======================

====== C:\Windows ====
====== C:\Users\Korisnik\AppData\Local\Temp ====
2014-04-10 17:40:04 A210F1AC135E5331C314CE5F394FB5A5 413276 ----a-w- C:\Users\Korisnik\AppData\Local\Temp\be29e7f1-71ae-4703-50cb-1d52be512f51\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll
====== Java Cache =====
====== C:\Windows\system32 =====
2014-04-09 23:32:00 BC63D80B6810238266D4334A80783D60 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2014-04-09 23:32:00 AC65D9692CA56D8581F75FCFE0C0C4D6 73216 ----a-w- C:\Windows\System32\mshtmled.dll
2014-04-09 23:31:59 D20FBD7E03F24A2720EAD746EADEE5A2 176640 ----a-w- C:\Windows\System32\ieui.dll
2014-04-09 23:31:59 4C43E955E8F782E722659364341E0529 65024 ----a-w- C:\Windows\System32\jsproxy.dll
2014-04-09 23:31:59 447C9FADAC167AA7031328C11464C7D0 421376 ----a-w- C:\Windows\System32\vbscript.dll
2014-04-09 23:31:58 DCEBA94B909C218BA2E471AEB9913E1C 607744 ----a-w- C:\Windows\System32\msfeeds.dll
2014-04-09 23:31:58 48CB5C9B0942011010F5504F056FBF4E 142848 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-04-09 23:31:57 E8E0342BC443D013E8806EE1B69C1FC7 717824 ----a-w- C:\Windows\System32\jscript.dll
2014-04-09 23:31:57 6D4BC1F977EDF186A8C68152BFB43769 1806848 ----a-w- C:\Windows\System32\jscript9.dll
2014-04-09 23:31:57 62077F806BC59CBD5A404338D710D133 1129472 ----a-w- C:\Windows\System32\wininet.dll
2014-04-09 23:31:57 077B7BE0796C9DA2E8C45F90496CFE36 231936 ----a-w- C:\Windows\System32\url.dll
2014-04-09 23:31:56 46F8078ED1D499BF8149B7FDF915E5D5 1796096 ----a-w- C:\Windows\System32\iertutil.dll
2014-04-09 23:31:55 25B97E6F25AFDA7EA0C9BF3CB137B4D8 1105408 ----a-w- C:\Windows\System32\urlmon.dll
2014-04-09 23:31:54 D15B8C3BD0F2F6F520A10D5CFCE68879 9739264 ----a-w- C:\Windows\System32\ieframe.dll
2014-04-09 23:31:54 8229FB32D999CDD1DFA731E8E2E510A4 1427968 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-04-09 23:31:52 10D0FA4F2A6ADBEEA0FFF10583CC5407 12347904 ----a-w- C:\Windows\System32\mshtml.dll
2014-04-09 07:30:11 F74FFA7654702F81884BDB41EB80DAC2 868352 ----a-w- C:\Windows\System32\kernel32.dll
====== C:\Windows\system32\drivers =====
2014-04-09 07:30:14 F1A449D762657230629D8BFC107ABC14 149440 ----a-w- C:\Windows\System32\drivers\storport.sys
2014-04-09 07:30:14 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2014-04-09 07:30:14 5FB4F271032B6435F3B2252F577A4815 27072 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-04-09 07:30:12 C8DFF8D07755A66C7A4A738930F0FEAC 1212352 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-04-08 12:38:18 C27BA9997D1BB1AC88B5A690656D5456 52928 ----a-w- C:\Windows\System32\drivers\wStLibG.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-04-02 15:55:46 -------- dc----w- C:\Program Files\Counter-Strike Source
======= C: =====
====== C:\Users\Korisnik\AppData\Roaming ======
2014-04-10 17:38:02 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp
2014-04-10 17:38:02 -------- d-----w- C:\Users\Public\AppData\Local\temp
2014-04-10 17:38:02 -------- d-----w- C:\Users\Korisnik\AppData\Local\Temp
2014-04-10 17:38:02 -------- d-----w- C:\Users\Default\AppData\Local\temp
2014-04-10 17:38:02 -------- d-----w- C:\Users\Default User\AppData\Local\temp
2014-04-08 23:00:25 -------- d-----w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-07 18:54:42 -------- d-----w- C:\Users\Korisnik\AppData\Local\41
2014-04-02 16:04:25 -------- d-----w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source
====== C:\Users\Korisnik ======
2014-04-10 18:03:24 04B47DEEB298AE90A0C42DEAED71F8BA 1426178 ----a-w- C:\Users\Korisnik\Downloads\AdwCleaner.exe
2014-04-04 09:41:43 D15CF50AD89600B0AEF5B01456D99799 257291214 ----a-w- C:\Users\Korisnik\Downloads\Counter Strike 1.6 FULL v44 - Protocol 48 Clean.exe
2014-04-02 16:04:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike Source

====== C: exe-files ==
2014-04-10 18:03:24 04B47DEEB298AE90A0C42DEAED71F8BA 1426178 ----a-w- C:\Users\Korisnik\Downloads\AdwCleaner.exe
2014-04-10 17:44:28 3C2A9F3195CDDD8943971DC8A677EF25 294912 ----a-w- C:\Windows\Temp\bcdedit.exe
2014-04-09 23:31:58 BBC3D21C78230F38EF1B77309B82650A 468480 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe
2014-04-09 23:31:58 48CB5C9B0942011010F5504F056FBF4E 142848 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-04-07 18:54:42 6A901F8E4CD3A56D97D6C24EB70A45A3 292936 ----a-w- C:\Users\Korisnik\AppData\Local\41\a18467.exe
2014-04-04 09:41:43 D15CF50AD89600B0AEF5B01456D99799 257291214 ----a-w- C:\Users\Korisnik\Downloads\Counter Strike 1.6 FULL v44 - Protocol 48 Clean.exe
=== C: other files ==
2014-04-09 07:30:14 F1A449D762657230629D8BFC107ABC14 149440 ----a-w- C:\Windows\System32\drivers\storport.sys
2014-04-09 07:30:14 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\DriverStore\FileRepository\iscsi.inf_x86_neutral_128be931e3e98b62\msiscsi.sys
2014-04-09 07:30:14 EB34CE31FABD4DC4343FD2AD16D2CAF9 234432 ----a-w- C:\Windows\System32\drivers\msiscsi.sys
2014-04-09 07:30:14 5FB4F271032B6435F3B2252F577A4815 27072 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2014-04-09 07:30:12 C8DFF8D07755A66C7A4A738930F0FEAC 1212352 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2014-04-08 12:38:18 C27BA9997D1BB1AC88B5A690656D5456 52928 ----a-w- C:\Windows\System32\drivers\wStLibG.sys
2014-04-04 12:23:15 65E5164CD2EDC2DF762DCAF25F67E943 107057783 ----a-w- C:\Users\Korisnik\Downloads\THCF(2014).zip
2014-04-04 10:02:51 C8B4174498BE1AE1422363C2EC4060C2 9364601 ----a-w- C:\Users\Korisnik\Downloads\zbot_cs16.zip
2014-04-03 20:53:27 1BE3E0E3ED791E8CFE44E5D9923811B6 2624052 ----a-w- C:\Users\Korisnik\Downloads\cs_italy2_port.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-457889968-920633692-2427081306-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Xvid"="C:\Program Files\XviD\CheckUpdate.exe"
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe"
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe /MINIMIZED"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s"
"RemoteControl10"="C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
"BDRegion"="C:\Program Files\Cyberlink\Shared files\brs.exe"
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"AdobeAAMUpdater-1.0"="C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Xvid"="C:\Program Files\XviD\CheckUpdate.exe"
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe"
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe /MINIMIZED"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" c:\\progra~1\\assist~1.dll"

==== Startup Registry Disabled ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\uTorrent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="uTorrent"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\uTorrent\\uTorrent.exe\" /MINIMIZED"


==== Startup Folders ======================

2013-05-20 13:51:09 919 ----a-w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
2011-05-30 13:39:42 1276 ----a-w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
2013-04-21 18:16:37 1843 ----a-w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk
2014-03-05 16:53:05 0 ----a-w- C:\Users\Korisnik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration Lock On

==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [03/11/2014 10:32 PM]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [06/17/2011 12:11 AM]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [06/17/2011 12:11 AM]

==== Other Scheduled Tasks ======================

"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\AdobeAAMUpdater-1.0-Korisnik-PC-Korisnik" [C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\Open URL by RoboForm" [C:\Windows\system32\rundll32.exe url.dll,FileProtocolHandler "http://www.roboform.com/uninstall.html?aaa=KICMPMMMNJMJKJMJPMMMCNMMNJPMHMCNLMMMNJNMCNGMMJJMNJCNMMNMOMMJLMHMPMGMKMNMNMMJJNJICMIMCNJMCNKMFMGMCNPMCNHMOMOMNMFMJMCNOMCNIMJMPMOMCNNMJNPICMPMFMFMPMJNHICMOMOMKJIJPIJNBJCMELAJNIGJMIBJGJEJJNKJCMJNNICMJNDJCMKJBJ"]
"C:\Windows\system32\tasks\Run RoboForm TaskBar Icon" [C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe]
"C:\Windows\system32\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe]
"C:\Windows\system32\tasks\{150F0C94-A55C-47AA-AF24-AEF029201BC6}" [C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe]
"C:\Windows\system32\tasks\{311FA76A-5594-44B2-8BC8-6E0664E93D91}" [C:\Program Files\EA GAMES\Medal of Honor Pacific Assault(tm)\mohpa_setup.exe]
"C:\Windows\system32\tasks\{3D6C96A8-0534-4595-83D1-66C52B46D889}" [C:\Users\Korisnik\Desktop\Grand Theft Auto Vice City - PC\gta-vc.exe]
"C:\Windows\system32\tasks\{498AE352-7605-4B6C-965A-71E56BDF27B3}" [C:\Users\Korisnik\Desktop\Login.exe]
"C:\Windows\system32\tasks\{4A692F5F-732E-41E1-BEE8-FD004DCC2972}" [C:\Users\Korisnik\Desktop\Grand Theft Auto Vice City - PC\gta-vc.exe]
"C:\Windows\system32\tasks\{4D24060C-D670-4CA5-9734-C8C43B24F9D5}" [C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe]
"C:\Windows\system32\tasks\{51741DCC-D14C-435E-9EAD-7E8CD25C5DAC}" [C:\Program Files\rFactor\rfactor.exe]
"C:\Windows\system32\tasks\{60A94020-4DB8-4A5D-9939-68FFE5BBFEBD}" [C:\Program Files\Mount&Blade With Fire and Sword\mb_wfas.exe]
"C:\Windows\system32\tasks\{758CBF40-2756-42D2-8D7A-B2ADEB1A96B2}" [C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe]
"C:\Windows\system32\tasks\{8223B055-A479-48AD-9736-6C269C228744}" [C:\Program Files\Mozilla Firefox\firefox.exe]
"C:\Windows\system32\tasks\{8775BA3B-99F2-46F1-A2E9-3DD0A03C865D}" [C:\Program Files\Mozilla Firefox\firefox.exe]
"C:\Windows\system32\tasks\{D1B76BED-D388-4E30-9C93-84FD831D01D7}" [C:\Program Files\Skype\\Phone\Skype.exe]
"C:\Windows\system32\tasks\{E202B4B1-73E2-4703-B646-EFC375108B6B}" [C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe]
"C:\Windows\system32\tasks\{EA8326BF-B4C6-4174-93C3-0B5E865F90B3}" [C:\Program Files\Call of Duty\CoDSP.exe]
"C:\Windows\system32\tasks\{F416B902-6483-48C4-A4FE-591FD9267D31}" [C:\Program Files\Mozilla Firefox\firefox.exe]

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [01/12/2014 09:03 PM]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Korisnik\AppData\Roaming\KompoZer\Profiles\7ocu5avf.default
- Undetermined - %ProfilePath%\extensions\installed-extensions.txt
- KompoZer classic - %ProfilePath%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\cx8ept1r.default
95812430959AE88CDD0301AB3A71913B - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll - Shockwave Flash
01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.1.0.30401.0.dll - Silverlight Plug-In
01D93217A9EE48DD37072B671378CC9C - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll - Silverlight Plug-In
AC987EE8037531807C5D7E6217A23501 - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
EB41064BC07017F5694CF16B4DEF6B10 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat
F3B0E300AFC94E1A775A2D935A7D384F - C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll - Shockwave for Director / Shockwave for Director
C36444D7301A8C881FC7296B092609C7 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll - Google Update
6768C724599214E4F9ADD9F8FF5097EB - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U45
F1CD6E22E5AE5CEEB7712E546A5FC853 - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.450.18
41601A5A4964B1B4A95EF48556A90ECF - C:\Program Files\Mozilla Firefox\browser\plugins\npdevalvr.dll - DevalVR 3D Plugin
2B78086E45508ED59364CE75179D729B - C:\Program Files\Nitro\Reader 3\npnitromozilla.dll - Nitro PDF plugin for Firefox and Chrome
C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery
28986F0A2342A033345EF9E70D395E4F - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrlui.dll - Microsoft® Silverlight
B7B85962BFCFEFECE806A2A2025AA60E - C:\Program Files\Nitro\Reader 3\npdf.dll - Nitro PDF Library
4461D2F67A9597EEFC7FA1ED8E251A41 - C:\Program Files\Nitro\Reader 3\npnitroie.dll - Nitro PDF plugin for Internet Explorer


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[01/12/2014 09:03 PM]


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page Restore"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page Restore"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{25477387-2310-45df-933D-E9416D3D0303} eSnips Search Url="http://eis.esnips.com/page/search_provider/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d&q={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Empty IE Cache ======================

C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Korisnik\AppData\Local\Mozilla\Firefox\Profiles\cx8ept1r.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Korisnik\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=597 folders=169 46714824 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Korisnik\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Korisnik\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Korisnik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on Thu 04/10/2014 at 22:38:46.18 ======================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Ovo sada dobro izgleda, imas li i dalje problem iz opisa?

offline
  • Pridružio: 10 Apr 2014
  • Poruke: 8

Sve šljaka za sad Very Happy Hvala Very Happy

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Nema da fali Smile

Mozes rucno da pobrises alate koje smo koristili.




Idea Preporucujem ti da koristiš program MCShield za zaštitu USB memorijskih uredaja.

Nakon instalacije programa, prikljuci USB memorijske uredaje, koji ce automatski biti skenirani.
Na kraju skeniranja dobices izveštaj da je uredaj cist ili obaveštenje o uklonjenom malware-u.

Ko je trenutno na forumu
 

Ukupno su 536 korisnika na forumu :: 7 registrovanih, 0 sakrivenih i 529 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: ALBION101, kikisp, Krusarac, mackenzie, milenko crazy north, Mixelotti, zlaya011