You have tried to login from an untrusted proxy server

You have tried to login from an untrusted proxy server

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 141
  • Gde živiš: SRBIJA

Pozdrav imam problem od skoro, za sada ne bi da ispostujem proceduru otvaranja jer ne znam sta bi vam postavio pa cu cekati upustvo od nekog ko ce mi pomoci jer ne znam odakle bi krenuo.
Igram jednu online igru i od skoro mi na mom kucnom racunaru kad hocu da se ulogujem iskace ovakva poruka:
"You have tried to login from an untrusted proxy server. This login attempt might compromise your eRepublik account.
If you wish to continue with the procedure, we kindly ask you to send us a message (English only) to proxy_connect@erepublik.com
Thanks for your support and understanding!"
Pisao sam im na taj isti mail ali mi niko jos nije odgovorio.
Probao sam da nadjem resenje i sam ali po nalazima sa interneta koliko vidim uglavnom je problem za takav problem netacno vreme na racunaru sto kod mene nije problem.
Jedini nacin da se ulogujem je da ispred adrese dodam i onda kada udjem isto izbrisem i normalno funkcionise sve!!!!
Isto to mi se ne desava na drugom racunaru na kome sve normalno funkcionise.
Sta da vam postavim da proverimo i nadjemo resenje ako ga uopste ima?

offline
  • Més que un club
  • Glavni vokal @ Harpun
  • Pridružio: 27 Feb 2009
  • Poruke: 3897
  • Gde živiš: Novi Sad,Klisa

Pozdrav, nebojsa77ns
Isprati ovo uputstvo, i u skladu sa tim dostavi odgovarajuće logove
http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html


NIx Car (AMF Tim)

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 141
  • Gde živiš: SRBIJA

OTL logfile created on: 12/02/2013 11:37:39 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Popa\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.75 Gb Total Physical Memory | 1.15 Gb Available Physical Memory | 30.73% Memory free
7.50 Gb Paging File | 3.45 Gb Available in Paging File | 45.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 65.66 Gb Total Space | 29.89 Gb Free Space | 45.52% Space Free | Partition Type: NTFS
Drive D: | 200.00 Gb Total Space | 49.07 Gb Free Space | 24.54% Space Free | Partition Type: NTFS
Drive E: | 200.00 Gb Total Space | 129.45 Gb Free Space | 64.73% Space Free | Partition Type: NTFS

Computer Name: POPA-PC | User Name: Popa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/02/12 11:37:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Popa\Desktop\OTL.exe
PRC - [2013/02/10 16:45:12 | 000,607,232 | ---- | M] (MyCity) -- C:\Program Files (x86)\MCShield\MCShieldRTM.exe
PRC - [2013/01/26 03:35:08 | 001,248,208 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2012/12/18 20:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/12/14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012/12/14 10:17:03 | 009,876,472 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
PRC - [2012/12/14 10:08:24 | 000,190,968 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
PRC - [2012/11/16 14:24:44 | 000,913,184 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
PRC - [2012/04/10 00:17:18 | 000,162,816 | ---- | M] () -- C:\Program Files (x86)\MyPhoneExplorer\DLL\adb.exe
PRC - [2011/11/22 16:53:28 | 001,327,440 | ---- | M] (Comfort Software Group) -- C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe
PRC - [2011/01/17 20:10:34 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 20:10:34 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2009/12/23 22:34:20 | 000,370,688 | ---- | M] (StarWind Software) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2004/12/13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


========== Modules (No Company Name) ==========

MOD - [2013/02/07 18:51:55 | 012,459,888 | ---- | M] () -- C:\Users\Popa\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll
MOD - [2013/01/26 03:35:06 | 000,460,240 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppgooglenaclpluginchrome.dll
MOD - [2013/01/26 03:35:04 | 004,012,496 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
MOD - [2013/01/26 03:34:19 | 000,597,968 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\libglesv2.dll
MOD - [2013/01/26 03:34:18 | 000,124,368 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\libegl.dll
MOD - [2013/01/26 03:34:16 | 001,552,848 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ffmpegsumo.dll
MOD - [2013/01/04 20:54:20 | 000,985,088 | ---- | M] () -- C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2012/04/10 00:17:18 | 000,162,816 | ---- | M] () -- C:\Program Files (x86)\MyPhoneExplorer\DLL\adb.exe


========== Services (SafeList) ==========

SRV:64bit: - [2012/11/16 14:24:44 | 000,913,184 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV:64bit: - [2012/07/04 07:20:54 | 000,238,080 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/12/18 20:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/12/14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2012/11/09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/12/23 22:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Running] -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2004/12/13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/01/25 17:18:05 | 000,530,488 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2012/11/16 13:57:30 | 000,209,808 | ---- | M] (ESET) [File_System | System | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2012/11/16 13:57:30 | 000,062,024 | ---- | M] (ESET) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:64bit: - [2012/08/23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/07/04 07:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/07/04 06:10:56 | 000,359,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/06/18 13:34:44 | 000,019,032 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
DRV:64bit: - [2012/06/18 13:34:42 | 000,012,384 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)
DRV:64bit: - [2012/03/28 13:06:58 | 000,187,632 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:64bit: - [2012/03/28 13:06:56 | 000,148,528 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2012/03/28 13:06:56 | 000,038,288 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\EpfwLWF.sys -- (EpfwLWF)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/10/24 05:04:32 | 000,223,232 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hw_quusbmdm.sys -- (HWHandSet)
DRV:64bit: - [2011/10/24 04:51:40 | 000,116,864 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hw_usbdev.sys -- (hw_usbdev)
DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/12/30 08:01:08 | 000,392,296 | ---- | M] (Realtek ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rtlh64.sys -- (RTL8169)
DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV - [2009/12/30 10:20:56 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = search.conduit.com?SearchSource=10&ctid=CT3220468
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DC 39 AE CF B2 EA CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3220468
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\PROGRAM FILES\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD [2013/01/04 20:50:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013/01/04 20:50:20 | 000,000,000 | ---D | M]

[2013/01/08 15:51:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Popa\AppData\Roaming\Mozilla\Firefox\extensions
[2013/01/08 15:51:23 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\Popa\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}

========== Chrome ==========

CHR - homepage: google.rs/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
CHR - homepage: google.rs/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - Extension: Google \u0434\u0438\u0441\u043A = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google \u043F\u0440\u0435\u0442\u0440\u0430\u0433\u0430 = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: eRepublik Advanced = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebeenikkcpgaekfgbnflbaaihalfifkk\4.1.0.0_0\
CHR - Extension: Qualys BrowserCheck = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejhnkognlohdkpjkjongioociddgoibk\1.5.48.1_0\
CHR - Extension: Mibbit webchat = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbadbkkklnhamjjeagmknajgmbgcmnpi\1.12_0\
CHR - Extension: Windows Media Player Extension for HTML5 = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak\1.0_0\
CHR - Extension: Pulse = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\iehllpiamddoghfbfbgmajdcifkpjopm\1.2.0_0\
CHR - Extension: Gmail = C:\Users\Popa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [TNOD UP] C:\Program Files\ESET\TNod User & Password Finder\TNODUP.exe (Tukero[X]Team)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [FreeAC] C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe (Comfort Software Group)
O4 - HKCU..\Run: [MCShield Monitor] C:\Program Files (x86)\MCShield\MCShieldRTM.exe (MyCity)
O4 - Startup: C:\Users\Popa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0B4663B3-E476-4A9F-A1F0-39AFE24C1A54}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/12 11:37:23 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Popa\Desktop\OTL.exe
[2013/02/11 15:01:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Playrix Entertainment
[2013/02/10 19:26:09 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Roaming\Awem
[2013/02/10 19:26:03 | 000,000,000 | ---D | C] -- C:\games
[2013/02/10 18:17:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TNod User & Password Finder
[2013/02/09 21:46:55 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Roaming\Media Player Classic
[2013/02/09 20:27:26 | 000,000,000 | ---D | C] -- C:\Users\Popa\Desktop\New folder (2)
[2013/02/09 19:55:47 | 000,401,408 | ---- | C] (Kingston Technology Inc) -- C:\Users\Popa\Desktop\Kingston Format Utility.exe
[2013/02/06 19:07:54 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Roaming\Building the Great Wall of China
[2013/02/06 19:07:50 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2013/02/06 19:07:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Building the Great Wall of China
[2013/02/06 19:06:24 | 000,000,000 | ---D | C] -- C:\Users\Popa\Desktop\Building.the.Great.Wall.of.China.v1.0-TE
[2013/02/06 06:15:46 | 000,262,560 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/02/06 06:15:29 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/02/06 06:15:29 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/02/06 06:15:29 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/02/02 12:36:42 | 000,000,000 | ---D | C] -- C:\Users\Popa\Desktop\U8110
[2013/01/31 17:38:40 | 000,000,000 | ---D | C] -- C:\ADCDA2
[2013/01/31 17:08:24 | 000,000,000 | ---D | C] -- C:\Users\Popa\Documents\Autodata
[2013/01/27 11:19:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard Company
[2013/01/27 11:19:39 | 000,000,000 | ---D | C] -- C:\DriveKey
[2013/01/26 06:07:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicISO
[2013/01/26 05:03:13 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Roaming\PowerISO
[2013/01/25 18:34:50 | 000,000,000 | ---D | C] -- C:\Users\Popa\Desktop\Android USB Driver
[2013/01/25 17:20:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%
[2013/01/25 17:19:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Alcohol Soft
[2013/01/25 16:05:53 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Local\Downloaded Installations
[2013/01/25 09:00:50 | 000,000,000 | ---D | C] -- C:\ruu_log
[2013/01/25 09:00:12 | 000,000,000 | ---D | C] -- C:\Users\Popa\Desktop\Zdravkovic
[2013/01/24 18:36:17 | 000,000,000 | ---D | C] -- C:\Users\Popa\Desktop\VLADA DRIVERI
[2013/01/23 21:06:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\WinFast
[2013/01/23 21:06:16 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Roaming\InstallShield
[2013/01/23 20:45:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Ulead Systems
[2013/01/23 20:42:22 | 000,000,000 | ---D | C] -- C:\Windows\ulead.dat
[2013/01/23 20:23:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinTV
[2013/01/23 20:21:17 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Local\autorun
[2013/01/23 03:12:05 | 000,223,232 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\hw_quusbmdm.sys
[2013/01/23 03:12:05 | 000,116,864 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\SysNative\drivers\hw_usbdev.sys
[2013/01/23 03:11:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Handset WinDriver
[2013/01/22 22:54:00 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Local\WindowsUpdate
[2013/01/22 16:57:43 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Local\ElevatedDiagnostics
[2013/01/20 17:32:32 | 000,000,000 | ---D | C] -- C:\AMD
[2013/01/19 16:25:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
[2013/01/19 16:25:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nero
[2013/01/19 16:24:17 | 000,000,000 | ---D | C] -- C:\Users\Popa\AppData\Roaming\Nero
[2013/01/19 16:24:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nero
[2013/01/19 14:45:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JDownloader
[2013/01/18 17:10:20 | 000,000,000 | ---D | C] -- C:\Users\Popa\Desktop\SD ICS
[2013/01/15 20:49:27 | 000,000,000 | ---D | C] -- C:\Users\Popa\Documents\SEM
[2013/01/15 20:48:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Siemens Data Suite
[2013/01/15 20:48:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Siemens Data Suite
[2013/01/15 20:48:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Siemens AG Shared
[2013/01/15 20:44:52 | 000,000,000 | ---D | C] -- C:\Users\Popa\Desktop\New folder
[2013/01/15 19:19:52 | 001,533,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WUDFUpdate_01007.dll
[2013/01/15 19:19:52 | 001,490,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WdfCoInstaller01007.dll
[2013/01/15 19:19:52 | 001,490,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfCoInstaller01007.dll
[2013/01/15 19:19:52 | 000,708,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WinUSBCoInstaller.dll
[2013/01/15 19:19:45 | 000,708,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinUSBCoInstaller.dll

========== Files - Modified Within 30 Days ==========

[2013/02/12 11:37:31 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Popa\Desktop\OTL.exe
[2013/02/12 10:42:00 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/11 20:42:01 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/10 19:36:05 | 000,001,400 | ---- | M] () -- C:\Users\Popa\Desktop\CradleOfEgyptCE - Shortcut.lnk
[2013/02/10 18:17:03 | 000,001,762 | ---- | M] () -- C:\Users\Public\Desktop\Update NOD32 license.lnk
[2013/02/09 21:46:32 | 010,522,895 | ---- | M] () -- C:\Users\Popa\Desktop\VID_20130209_185329.mp4
[2013/02/09 19:40:37 | 000,778,834 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/02/09 19:40:37 | 000,664,320 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/02/09 19:40:37 | 000,125,056 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/02/07 00:38:29 | 006,409,759 | ---- | M] () -- C:\Users\Popa\Desktop\G-Apps_CM7 (1).zip
[2013/02/07 00:25:05 | 095,414,349 | ---- | M] () -- C:\Users\Popa\Desktop\Gingerbread -V9a-.zip
[2013/02/07 00:22:45 | 000,758,655 | ---- | M] () -- C:\Users\Popa\Desktop\U8110 Camera_fix.zip
[2013/02/06 19:07:50 | 000,002,315 | ---- | M] () -- C:\Users\Popa\Desktop\Building the Great Wall of China.lnk
[2013/02/06 06:15:25 | 000,095,648 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/02/06 06:15:22 | 000,262,560 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/02/06 06:15:22 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/02/06 06:15:22 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/02/06 06:15:21 | 000,861,088 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013/02/06 06:15:21 | 000,782,240 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013/02/06 02:59:05 | 181,041,291 | ---- | M] () -- C:\Users\Popa\Desktop\CradleOfEgyptCollectorsEdition.rar
[2013/02/06 02:57:00 | 142,960,574 | ---- | M] () -- C:\Users\Popa\Desktop\BtGWoCv.rar
[2013/02/03 20:04:59 | 000,787,837 | ---- | M] () -- C:\Users\Popa\Desktop\winter_forest_wallpaper.jpg
[2013/02/03 20:03:04 | 003,286,527 | ---- | M] () -- C:\Users\Popa\Desktop\thin_trees_winter-wallpaper-2880x1800.jpg
[2013/02/03 19:59:59 | 000,700,501 | ---- | M] () -- C:\Users\Popa\Desktop\winter_in_the_park_2_hd_widescreen_wallpapers_1920x1200.jpeg
[2013/02/02 14:30:55 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/02 14:30:55 | 000,010,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/02 12:39:17 | 000,000,400 | ---- | M] () -- C:\Users\Popa\Documents\ax_files.xml
[2013/01/31 10:45:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/01/31 10:45:15 | 3019,251,712 | -HS- | M] () -- C:\hiberfil.sys
[2013/01/28 06:47:32 | 524,605,416 | ---- | M] () -- C:\Users\Popa\Desktop\SrpskaForum.com.Folk.Ep.10.avi
[2013/01/27 22:32:28 | 471,769,088 | ---- | M] () -- C:\Users\Popa\Desktop\www.balkandownload.na.putu.za.montevideo.Ep.03.avi
[2013/01/27 11:19:39 | 000,000,409 | ---- | M] () -- C:\Users\Public\Desktop\HP USB Disk Storage Format Tool.lnk
[2013/01/27 00:31:39 | 000,385,594 | ---- | M] () -- C:\Users\Popa\Desktop\ChkFlsh.zip
[2013/01/26 06:38:19 | 000,000,400 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2013/01/25 17:18:05 | 000,530,488 | ---- | M] () -- C:\Windows\SysNative\drivers\sptd.sys
[2013/01/24 18:57:10 | 000,000,001 | ---- | M] () -- C:\Users\Popa\AppData\Local\llftool.4.25.agreement
[2013/01/23 21:07:42 | 000,294,888 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/23 20:42:23 | 000,000,196 | ---- | M] () -- C:\Windows\ulead32.ini
[2013/01/17 22:27:33 | 000,977,370 | ---- | M] () -- C:\Users\Popa\Desktop\1bmluc3Rhb.apk
[2013/01/16 12:01:27 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/01/16 12:00:51 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013/01/15 20:49:08 | 000,001,628 | ---- | M] () -- C:\Users\Public\Desktop\Mobile.lnk
[2013/01/15 20:48:52 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\Siemens Data Suite.lnk
[2013/01/15 19:19:57 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01007.Wdf
[2013/01/15 13:55:42 | 000,084,108 | ---- | M] () -- C:\Users\Popa\Desktop\10281_433471440032279_2019472019_n.jpg
[2013/01/15 13:51:12 | 000,078,409 | ---- | M] () -- C:\Users\Popa\Desktop\382161_457663787613044_605463717_n.jpg

========== Files Created - No Company Name ==========

[2013/02/10 19:36:05 | 000,001,400 | ---- | C] () -- C:\Users\Popa\Desktop\CradleOfEgyptCE - Shortcut.lnk
[2013/02/10 18:17:03 | 000,001,762 | ---- | C] () -- C:\Users\Public\Desktop\Update NOD32 license.lnk
[2013/02/09 21:46:14 | 010,522,895 | ---- | C] () -- C:\Users\Popa\Desktop\VID_20130209_185329.mp4
[2013/02/07 00:38:13 | 006,409,759 | ---- | C] () -- C:\Users\Popa\Desktop\G-Apps_CM7 (1).zip
[2013/02/07 00:26:40 | 006,941,943 | ---- | C] () -- C:\Users\Popa\Desktop\01 Ai Se Eu Te Pego.mp3
[2013/02/07 00:26:39 | 000,755,533 | ---- | C] () -- C:\Users\Popa\Desktop\VOJNA AKADEMIJA - Muzika za mobilni.mp3
[2013/02/07 00:22:40 | 000,758,655 | ---- | C] () -- C:\Users\Popa\Desktop\U8110 Camera_fix.zip
[2013/02/07 00:22:04 | 095,414,349 | ---- | C] () -- C:\Users\Popa\Desktop\Gingerbread -V9a-.zip
[2013/02/06 19:07:50 | 000,002,315 | ---- | C] () -- C:\Users\Popa\Desktop\Building the Great Wall of China.lnk
[2013/02/06 02:41:11 | 142,960,574 | ---- | C] () -- C:\Users\Popa\Desktop\BtGWoCv.rar
[2013/02/06 02:39:17 | 181,041,291 | ---- | C] () -- C:\Users\Popa\Desktop\CradleOfEgyptCollectorsEdition.rar
[2013/02/03 20:04:59 | 000,787,837 | ---- | C] () -- C:\Users\Popa\Desktop\winter_forest_wallpaper.jpg
[2013/02/03 20:03:03 | 003,286,527 | ---- | C] () -- C:\Users\Popa\Desktop\thin_trees_winter-wallpaper-2880x1800.jpg
[2013/02/03 19:59:59 | 000,700,501 | ---- | C] () -- C:\Users\Popa\Desktop\winter_in_the_park_2_hd_widescreen_wallpapers_1920x1200.jpeg
[2013/02/02 14:30:56 | 000,977,370 | ---- | C] () -- C:\Users\Popa\Desktop\1bmluc3Rhb.apk
[2013/01/28 17:33:25 | 524,605,416 | ---- | C] () -- C:\Users\Popa\Desktop\SrpskaForum.com.Folk.Ep.10.avi
[2013/01/28 16:42:23 | 471,769,088 | ---- | C] () -- C:\Users\Popa\Desktop\www.balkandownload.na.putu.za.montevideo.Ep.03.avi
[2013/01/27 11:19:39 | 000,000,409 | ---- | C] () -- C:\Users\Public\Desktop\HP USB Disk Storage Format Tool.lnk
[2013/01/27 00:31:37 | 000,385,594 | ---- | C] () -- C:\Users\Popa\Desktop\ChkFlsh.zip
[2013/01/25 17:21:45 | 000,000,400 | ---- | C] () -- C:\Users\Popa\Documents\ax_files.xml
[2013/01/25 17:18:05 | 000,530,488 | ---- | C] () -- C:\Windows\SysNative\drivers\sptd.sys
[2013/01/25 16:00:30 | 002,966,720 | ---- | C] () -- C:\Windows\SysNative\pwNative.exe
[2013/01/25 16:00:26 | 000,019,032 | ---- | C] () -- C:\Windows\SysNative\pwdrvio.sys
[2013/01/25 16:00:26 | 000,012,384 | ---- | C] () -- C:\Windows\SysNative\pwdspio.sys
[2013/01/24 18:57:10 | 000,000,001 | ---- | C] () -- C:\Users\Popa\AppData\Local\llftool.4.25.agreement
[2013/01/23 20:42:22 | 000,000,196 | ---- | C] () -- C:\Windows\ulead32.ini
[2013/01/23 18:42:10 | 000,000,400 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2013/01/19 14:45:56 | 000,002,005 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2013/01/19 14:45:56 | 000,001,949 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2013/01/19 14:45:56 | 000,001,928 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2013/01/16 12:01:27 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2013/01/16 12:00:51 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013/01/15 20:49:08 | 000,001,628 | ---- | C] () -- C:\Users\Public\Desktop\Mobile.lnk
[2013/01/15 20:48:52 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\Siemens Data Suite.lnk
[2013/01/15 19:19:57 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01007.Wdf
[2013/01/15 13:55:40 | 000,084,108 | ---- | C] () -- C:\Users\Popa\Desktop\10281_433471440032279_2019472019_n.jpg
[2013/01/15 13:51:12 | 000,078,409 | ---- | C] () -- C:\Users\Popa\Desktop\382161_457663787613044_605463717_n.jpg
[2013/01/04 23:10:30 | 000,764,302 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/01/04 21:23:40 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2013/01/04 21:23:40 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2013/01/04 21:23:40 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2013/01/04 21:23:38 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2013/01/04 21:23:33 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2013/01/04 20:23:29 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/07/04 06:34:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/07/04 06:34:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011/09/12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >

mycity.rs/must-login.png

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Arrow Racunar je čist što se malware-a tiče. Postavi temu u Windows potforumu i tamo iznesi problem...




Arrow Ponovo pokreni OTL i klikni na CleanUp




Arrow Obavezno poseti temu "Testirajte da li vam je pretraživač ranjiv", pročitaj i isprati link koji stoji u njoj.
Link do teme je: http://www.mycity.rs/Web-browseri/Testirajte-da-li.....anjiv.html



Arrow Takode, isprati i temu "Kako izbeci i ukloniti toolbar-ove" , procitaj i isprati korake u njoj. Link do teme je: http://www.mycity.rs/Zastita/Kako-izbeci-i-ukloniti-toolbar-ove.html



TwinHeadedEagle (AMF Tim)

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 141
  • Gde živiš: SRBIJA

TwinHeadedEagle ::Arrow Racunar je čist što se malware-a tiče. Postavi temu u Windows potforumu i tamo iznesi problem...




Arrow Ponovo pokreni OTL i klikni na CleanUp




Arrow Obavezno poseti temu "Testirajte da li vam je pretraživač ranjiv", pročitaj i isprati link koji stoji u njoj.
Link do teme je: mycity.rs/Web-browseri/Testirajte-da-li.....anjiv.html



Arrow Takode, isprati i temu "Kako izbeci i ukloniti toolbar-ove" , procitaj i isprati korake u njoj. Link do teme je: mycity.rs/Zastita/Kako-izbeci-i-ukloniti-toolbar-ove.html



TwinHeadedEagle (AMF Tim)


"Testirajte da li vam je pretraživač ranjiv" to je cisto tj updejtovano
"Kako izbeci i ukloniti toolbar-ove" ni ovoga nema na mom racunaru koliko ja znam
Hvala u svakom slucaju odo tamo

Ko je trenutno na forumu
 

Ukupno su 590 korisnika na forumu :: 8 registrovanih, 2 sakrivenih i 580 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: aboris, Bluper, Buda Baba, havoc995, Mixelotti, Pancevac, radionica1, TheDictator