UpdateTool.exe

3

UpdateTool.exe

offline
  • Pridružio: 25 Jun 2009
  • Poruke: 533
  • Gde živiš: U kuci!

Uopste ne mogu da kreiram arhivu.

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Ne možeš da je kreiraš zato što si stavio da ti destinacija bude root C:\ particije. Nek ti destinacija bude Desktop.

offline
  • Pridružio: 25 Jun 2009
  • Poruke: 533
  • Gde živiš: U kuci!

Uspio sam nekako da zapakujem i posaljem, nadam se da nista nije izostavljeno.

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Preuzmi Farbar Service Scaner na Desktop

http://download.bleepingcomputer.com/farbar/FSS.exe

Dvoklikom pokreni FSS.exe, stikliraj sve opcije i klikni na Scan

Nedugo zatim, otvorice se log programa u Notepad-u, koji ce biti sacuvan na radnoj povrsini kao FSS.txt

Kopiraj njegov sadrzaj u temu na forumu.

offline
  • Pridružio: 25 Jun 2009
  • Poruke: 533
  • Gde živiš: U kuci!

Farbar Service Scanner Version: 07-10-2012
Ran by IVANA (administrator) on 15-10-2012 at 21:54:01
Running from "C:\Users\IVANA\Desktop"
Microsoft Windows 7 Ultimate Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
WAN connected
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys
[2012-09-12 14:00] - [2012-08-22 19:16] - 1292144 ____A (Microsoft Corporation) A5EBB8F648000E88B7D9390B514976BF

C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll
[2012-10-09 23:13] - [2012-06-02 06:36] - 0140288 ____A (Microsoft Corporation) 96C0E38905CFD788313BE8E11DAE3F2F

C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Pošalji preko linka koji sam ti dao prošli put sljedeći fajl:

C:\Windows\system32\cryptsvc.dll

offline
  • Pridružio: 25 Jun 2009
  • Poruke: 533
  • Gde živiš: U kuci!

Poslao sam.

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow Korak 1

Otvori Notepad i iskopiraj sljedeći tekst:

DeQuarantine::
C:\QooBox\Quarantine\c\windows\system32\URTTemp
Quit::


Snimi na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sljedećoj poruci log koji bude bio napravljen na kraju čišćenja/skeniranja.



Arrow Korak 2

Idi u Start -> Control Panel -> Programs and Features i deinstaliraj sljedeće programe ako ti ne trebaju:

Conduit Engine
Skype Click to Call
uTorrentBar Toolbar
vShare plugin 1.3
VshareComplete




Arrow Korak 3

Preuzmi "Xplode"-ov AdwCleaner i sačuvaj ga na Desktop.
Dvoklikom pokreni program i klikni na dugme Search.
Kada program završi analizu otvoriće se Notepad sa izvještajem.
Kopiraj sadržaj tog izvještaja u temu.

Napomena: Izvještaj ce takođe biti sačuvan na C:\AdwCleaner[R1].txt

offline
  • Pridružio: 25 Jun 2009
  • Poruke: 533
  • Gde živiš: U kuci!

C:\QooBox\Quarantine\c\windows\system32\URTTemp\regtlib.exe -> C:\windows\system32\URTTemp\regtlib.exe
1 File(s) copied


A evo i drugog log-a:


# AdwCleaner v2.005 - Logfile created 10/15/2012 at 22:48:29
# Updated 14/10/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (32 bits)
# User : IVANA - CONEIIVANA-PC
# Boot Mode : Normal
# Running from : C:\Users\IVANA\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\searchplugins\Conduit.xml
File Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\searchplugins\Startsear.xml
File Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\searchplugins\web-search.xml
File Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\searchplugins\Conduit.xml
File Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\searchplugins\Startsear.xml
File Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\searchplugins\web-search.xml
Folder Found : C:\Program Files\Conduit
Folder Found : C:\Program Files\ConduitEngine
Folder Found : C:\ProgramData\~0
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\ProgramData\Premium
Folder Found : C:\Users\IVANA\AppData\Local\APN
Folder Found : C:\Users\IVANA\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda
Folder Found : C:\Users\IVANA\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\IVANA\AppData\LocalLow\Conduit
Folder Found : C:\Users\IVANA\AppData\LocalLow\PriceGong
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\Conduit
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\ConduitCommon
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\CT2786678
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\CT2786678
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\Conduit
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\ConduitCommon
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\CT2786678
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\CT2786678
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\extensions\{4ac04d99-3f4b-4ec5-bd2d-216d59822f8a}
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
Folder Found : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}

***** [Registry] *****

Key Found : HKCU\Software\AppDataLow\Software\PriceGong
Key Found : HKCU\Software\AppDataLow\Software\Toolbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\StartSearch
Key Found : HKLM\SOFTWARE\Classes\CLSID\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Found : HKLM\SOFTWARE\Classes\Interface\{3D782BB2-F2A5-11D3-BF4C-000000000000}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1750559
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{79D60450-56C5-4A8C-9321-6D5BC2A81E5A}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Key Found : HKU\S-1-5-21-4245940820-2503427758-1862393816-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKU\S-1-5-21-4245940820-2503427758-1862393816-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7601.17514

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main - Start Page] = hxxp://startsear.ch/?aff=1&cf=e0b1177e-45f7-11e1-9aa3-001fd05f8d1b

-\\ Mozilla Firefox v12.0 (en-US)

Profile name : default
File : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\0fx3g5lc.default\prefs.js

[OK] File is clean.

Profile name : Sef [Profil par défaut]
File : C:\Users\IVANA\AppData\Roaming\Mozilla\Firefox\Profiles\rl47s1ay.Sef\prefs.js

Found : user_pref("CT2786678..clientLogIsEnabled", true);
Found : user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2786678.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2786678.BrowserCompStateIsOpen_129579220236217502", true);
Found : user_pref("CT2786678.CTID", "CT2786678");
Found : user_pref("CT2786678.CurrentServerDate", "15-10-2012");
Found : user_pref("CT2786678.DSInstall", true);
Found : user_pref("CT2786678.DialogsAlignMode", "LTR");
Found : user_pref("CT2786678.DialogsGetterLastCheckTime", "Sun Oct 14 2012 22:03:53 GMT+0200 (Central Europe[...]
Found : user_pref("CT2786678.DownloadReferralCookieData", "");
Found : user_pref("CT2786678.EMailNotifierPollDate", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central Europe Dayl[...]
Found : user_pref("CT2786678.FeedLastCount5690698542593514850", 331);
Found : user_pref("CT2786678.FeedPollDate2429156812186649977", "Mon Apr 30 2012 02:51:49 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156813040823546", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156813130095866", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156813224203613", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156813230837251", "Mon Apr 30 2012 02:51:44 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156813454291735", "Mon Apr 30 2012 02:51:44 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156813729834876", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156813860870021", "Mon Apr 30 2012 02:51:49 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156814264681793", "Mon Apr 30 2012 02:51:49 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156814863075366", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedPollDate2429156815257761081", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.FeedTTL2429156813040823546", 15);
Found : user_pref("CT2786678.FeedTTL2429156813130095866", 10);
Found : user_pref("CT2786678.FeedTTL2429156813454291735", 5);
Found : user_pref("CT2786678.FeedTTL2429156814264681793", 5);
Found : user_pref("CT2786678.FirstServerDate", "30-4-2012");
Found : user_pref("CT2786678.FirstTime", true);
Found : user_pref("CT2786678.FirstTimeFF3", true);
Found : user_pref("CT2786678.FirstTimeHiddenVer", true);
Found : user_pref("CT2786678.FixPageNotFoundErrors", true);
Found : user_pref("CT2786678.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2786678.HPInstall", false);
Found : user_pref("CT2786678.HasUserGlobalKeys", true);
Found : user_pref("CT2786678.HomePageProtectorEnabled", false);
Found : user_pref("CT2786678.HomepageBeforeUnload", "chrome://branding/locale/browserconfig.properties");
Found : user_pref("CT2786678.Initialize", true);
Found : user_pref("CT2786678.InitializeCommonPrefs", true);
Found : user_pref("CT2786678.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2786678.InstallationType", "Unknown");
Found : user_pref("CT2786678.InstalledDate", "Mon Apr 30 2012 02:51:58 GMT+0200 (Central Europe Daylight Tim[...]
Found : user_pref("CT2786678.IsGrouping", false);
Found : user_pref("CT2786678.IsInitSetupIni", true);
Found : user_pref("CT2786678.IsMulticommunity", false);
Found : user_pref("CT2786678.IsOpenThankYouPage", true);
Found : user_pref("CT2786678.IsOpenUninstallPage", true);
Found : user_pref("CT2786678.IsProtectorsInit", true);
Found : user_pref("CT2786678.LanguagePackLastCheckTime", "Mon Oct 15 2012 15:01:02 GMT+0200 (Central Europe [...]
Found : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2786678.LastLogin_3.12.2.3", "Wed May 30 2012 19:36:41 GMT+0200 (Central Europe Dayligh[...]
Found : user_pref("CT2786678.LastLogin_3.13.0.6", "Tue Jul 17 2012 12:51:46 GMT+0200 (Central Europe Dayligh[...]
Found : user_pref("CT2786678.LastLogin_3.14.1.0", "Mon Aug 27 2012 11:21:06 GMT+0200 (Central Europe Dayligh[...]
Found : user_pref("CT2786678.LastLogin_3.15.1.0", "Mon Oct 15 2012 19:01:03 GMT+0200 (Central Europe Dayligh[...]
Found : user_pref("CT2786678.LatestVersion", "3.14.1.0");
Found : user_pref("CT2786678.Locale", "en");
Found : user_pref("CT2786678.MCDetectTooltipHeight", "83");
Found : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2786678.MCDetectTooltipWidth", "295");
Found : user_pref("CT2786678.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT2786678.OriginalFirstVersion", "3.12.2.3");
Found : user_pref("CT2786678.SearchCaption", "uTorrentBar Customized Web Search");
Found : user_pref("CT2786678.SearchEngineBeforeUnload", "uTorrentBar Customized Web Search");
Found : user_pref("CT2786678.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT278[...]
Found : user_pref("CT2786678.SearchInNewTabEnabled", true);
Found : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Mon Oct 15 2012 15:01:02 GMT+0200 (Central Europ[...]
Found : user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2786678.SearchProtectorEnabled", true);
Found : user_pref("CT2786678.SearchProtectorToolbarDisabled", false);
Found : user_pref("CT2786678.SendProtectorDataViaLogin", true);
Found : user_pref("CT2786678.ServiceMapLastCheckTime", "Mon Oct 15 2012 15:01:02 GMT+0200 (Central Europe Da[...]
Found : user_pref("CT2786678.SettingsLastCheckTime", "Mon Oct 15 2012 19:13:15 GMT+0200 (Central Europe Dayl[...]
Found : user_pref("CT2786678.SettingsLastUpdate", "1350318800");
Found : user_pref("CT2786678.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13");
Found : user_pref("CT2786678.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central Eur[...]
Found : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1312887586");
Found : user_pref("CT2786678.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT2786678.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2786678");
Found : user_pref("CT2786678.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT2786678.UserID", "UN57412202776607379");
Found : user_pref("CT2786678.WeatherNetwork", "");
Found : user_pref("CT2786678.WeatherPollDate", "Mon Apr 30 2012 02:51:43 GMT+0200 (Central Europe Daylight T[...]
Found : user_pref("CT2786678.WeatherUnit", "C");
Found : user_pref("CT2786678.alertChannelId", "1178763");
Found : user_pref("CT2786678.backendstorage.cbcountry_000", "4D45");
Found : user_pref("CT2786678.backendstorage.cbfirsttime", "4D6F6E2041707220333020323031322030323A35313A34372[...]
Found : user_pref("CT2786678.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT2786678.globalFirstTimeInfoLastCheckTime", "Mon Apr 30 2012 02:51:44 GMT+0200 (Central [...]
Found : user_pref("CT2786678.homepageProtectorEnableByLogin", true);
Found : user_pref("CT2786678.initDone", true);
Found : user_pref("CT2786678.isAppTrackingManagerOn", true);
Found : user_pref("CT2786678.myStuffEnabled", true);
Found : user_pref("CT2786678.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2786678.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2786678.navigateToUrlOnSearch", false);
Found : user_pref("CT2786678.revertSettingsEnabled", true);
Found : user_pref("CT2786678.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT2786678.searchProtectorEnableByLogin", true);
Found : user_pref("CT2786678.testingCtid", "");
Found : user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Mon Oct 15 2012 15:01:02 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Mon Apr 30 2012 02:51:44 GMT+0200 (Central E[...]
Found : user_pref("CT2786678.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ConduitSearchList", "uTorrentBar Customized Web Search");
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2786678/CT2786678[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2786678", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2786678",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"ff3[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\IVANA\\AppData\\Roaming\\Mozilla\\F[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.12.2.3");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2786678");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2786678");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2786678");
Found : user_pref("CommunityToolbar.globalUserId", "45906931-2669-4933-a36b-8be165e353fa");
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2786678");
Found : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
Found : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...]
Found : user_pref("browser.search.defaultthis.engineName", "uTorrentBar Customized Web Search");
Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&Sea[...]
Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=2&q=[...]
Found : user_pref("vshare.install.date", "1335747101");
Found : user_pref("vshare.install.finished", "1.0.0");
Found : user_pref("vshare.install.fresh", "false");
Found : user_pref("vshare.install.guid", "{6ef43d87-fcdd-462f-aafd-9cb6ab552a47}");
Found : user_pref("vshare.install.newtab", false);

-\\ Google Chrome v [Unable to get version]

File : C:\Users\IVANA\AppData\Local\Google\Chrome\User Data\Default\Preferences

Found [l.74] : keyword = "startsear.ch",
Found [l.77] : search_url = "hxxp://startsear.ch/?aff=1&src=sp&cf=e0b1177e-45f7-11e1-9aa3-001fd05f8d1b&q={searchTerms}",

-\\ Opera v12.0.1467.0

File : C:\Users\IVANA\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [18559 octets] - [15/10/2012 22:48:29]

########## EOF - C:\AdwCleaner[R1].txt - [18620 octets] ##########

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow

Ponovo pokreni AdwCleaner.
Klikni na dugme Delete i pričekaj da program završi.
Program će zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni na Ok kao potvrdu.
Na sledeća dva prozora koja se otvore (Informations i Restart required) klikni Ok
.
Računar će se restartovati.
Otvoriće se Notepad sa izvještajem.
Kopiraj sadržaj tog izvještaja u temu.


Napomena: Izvještaj ce takođe biti sačuvan na C:\AdwCleaner[S1].txt



Arrow

Kakvo je sad stanje sistema?

Ko je trenutno na forumu
 

Ukupno su 767 korisnika na forumu :: 14 registrovanih, 1 sakriven i 752 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: bojank, Chainsaw, cikadeda, DARKMEN22, FrankyRC, GreenMan, havoc995, ILGromovnik, kybonacci, LepizLoca, miljannis, Nebo_M, Toni, VJ