previse procesa s previse cudnim imenom

1

previse procesa s previse cudnim imenom

offline
  • Pridružio: 28 Mar 2008
  • Poruke: 125

Napisano: 15 Sep 2010 17:17

Radi se o ukupno 345 procesa aktivnih trenutno sa veoma cudnim imenom. Eto na slici stoji deo liste, s obzirom da ih je 345 ne mogu svi biti prikazani, ali, cini mi se da exe.exe ekstenzija nije svakidasnja.
Molio bih za pomoc.

Dopuna: 15 Sep 2010 17:18

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Pozdrav i dobro dosao u Ambulantu MyCity foruma.




Arrow Kao sto i sam znas, jer ti jel'te nije prvi put da otvaras temu u Ambulanti, ovde postoje neka pravila kojih se svi pridrzavamo. Da bi smo nastavili diskusiju i resavanje tvog problema potrebno je da detaljno ispratis Uputstvo za otvaranje teme: http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html


*Restartuj racunar, pa onda isprati Uputstvo i postavi potrebne logove uz objasnjenje problema (sto vise informacija das, to cemo bolje i brze resiti slucaj).





goran9888 (AMF Tim)

offline
  • Pridružio: 28 Mar 2008
  • Poruke: 125

Dakle, cak i gora vest, trenutno je aktivno 546 procesa. Ali sam isto primetio posle nekih mozda 20-30 min po slobodnoj proceni brojka aktivnih procesa se vrati na 60tak. Nisam primetio nikakve sporije radnje racunara, ali ne bih da posle s vremenom jednostavno rikne, ili ne daj boze brojka procesa nastavi da se penje.
mycity.rs/must-login.png

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

U toku resavanja slucaja, zamolio bih te da se pridrzavas sledeceg:
Detaljno citati moja uputstva (ili uputstva kolega koji ce me zamenjivati) i raditi iskljucivo po njima;
Ne traziti istovremeno pomoc na drugom mestu;
Nemoj koristiti druge programe za uklanjanje malware-a, osim onih za koje budes dobio uputstvo;
U toku intervencije ne koristiti USB memorijske uredjaje, dok to ne budem zatrazio;
Ukoliko ne odgovorim u roku od 48h, osvezi temu novim post-om;
Ukoliko se ne javis u roku od 5 dana, zatvoricemo slucaj.

Za vise informacija o pravilima Ambulante MyCity foruma: LINK

-------------------------------------------------------------------------------------


Arrow Aktiviraj prikaz skrivenih fajlova i foldera: http://www.mycity.rs/Uputstva/Kako-videti-skrivene-fajlove.html



Arrow Uploaduj mi sledece fajlove, preko ovog linka: http://www.mycity.rs/ambulanta-upload.php

C:\Users\ketla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FFF68.exe.exe
C:\Windows\E88D4.exe
C:\Windows\SysWow64\l3xg9ld.dll






goran9888 (AMF Tim)

offline
  • Pridružio: 28 Mar 2008
  • Poruke: 125

Uspeo sam da upload-ujem, ali jedva. Trenutno je aktivno 1830 procesa i ne bih da zvucim paranoicno, ali cini mi se sve se vise razmnozavaju. Racunar je prespor, jedva ovo kucam.

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Arrow Pokreni racunar u Safe mode i odatle isprati uputstvo za OTL.
Kako uci u Safe mode Windows-a? http://www.mycity.rs/Uputstva/Kako-uci-u-Safe-Mode-2.html


-------------------------------------------------------------------------------------





Arrow Ponovo pokreni program OTL dvoklikom na ikonicu;

U beli okvir prozora gde piše Custom Scans/Fixes iskopirati sledeći tekst:

:files
C:\Users\ketla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe.exe
C:\Users\ketla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\kill.bat
C:\Users\ketla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mel.bat*.bat
C:\Windows\E88D4.exe

:otl
O1 - Hosts: 127.0.0.1 virustotal.com
O1 - Hosts: 127.0.0.1 www.virustotal.com
O1 - Hosts: 127.0.0.1 virustotal
O1 - Hosts: 127.0.0.1 virscan.com
O1 - Hosts: 127.0.0.1 www.virscan.com
O1 - Hosts: 127.0.0.1 virscan
O1 - Hosts: 127.0.0.1 http://virscan.com
O1 - Hosts: 127.0.0.1 virustotal
O1 - Hosts: 127.0.0.1 virscan
O1 - Hosts: 127.0.0.1 http://virusscan.jotti.org/
O1 - Hosts: 127.0.0.1 virusscan.jotti.org/
O1 - Hosts: 127.0.0.1 www.virusscan.jotti.org/
O1 - Hosts: 127.0.0.1 scanner.novirusthanks.org/
O1 - Hosts: 127.0.0.1 http://scanner.novirusthanks.org/
O1 - Hosts: 127.0.0.1 www.scanner.novirusthanks.org/
@C:\ProgramData\Microsoft:dFqDOxwiu0AAhzXTEm9X54jb
@C:\ProgramData\TEMP:D1B5B4F1
@C:\ProgramData\Microsoft:kVnmsdq6yydSZbt5VxhnC
@C:\Users\ketla\AppData\Local\Temp:0KeH6RDYOVFMg6Aaj9HGO
@C:\Program Files\Common Files\Microsoft Shared:Py76tSykgpxMaMXTEpgjD7J
@C:\ProgramData\Microsoft:mfLAQGwsPkjMXeUKbhpiyzL8yU

[Reboot]



Klikni taster Run Fix;


Log koji dobiješ iskopiraj ovde u poruci.





goran9888 (AMF Tim)

offline
  • Pridružio: 28 Mar 2008
  • Poruke: 125

Mislim da nije iskopiralo sve, ali to sam proverio posto sam vec dao odgovor, tako da evo prikacicu i tekst file sa logom. (valjda ima neki limit dozvoljenih karaktera ne?)

Previse je velik, 1.6 Mb, kacim preko sajta nadam se da je dozvoljeno.

speedyshare.com/files/24284745/09172010_000315.log

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Postavi mi u sledecoj poruci novi OTL log.

offline
  • Pridružio: 28 Mar 2008
  • Poruke: 125

Napisano: 17 Sep 2010 0:40

OTL logfile created on: 17/09/2010 00:37:39 - Run 2
OTL by OldTimer - Version 3.2.12.1 Folder = C:\Users\ketla\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 80.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450.31 Gb Total Space | 206.68 Gb Free Space | 45.90% Space Free | Partition Type: NTFS
Drive D: | 15.15 Gb Total Space | 2.76 Gb Free Space | 18.20% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 95.60 Mb Free Space | 96.54% Space Free | Partition Type: FAT32
Drive F: | 3.96 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LUKA-PC
Current User Name: ketla
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/09/15 19:10:15 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\ketla\Desktop\OTL.exe


========== Modules (SafeList) ==========

MOD - [2010/09/15 19:10:15 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\ketla\Desktop\OTL.exe
MOD - [2009/08/21 01:20:03 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16400_none_4209f94e2b866170\comctl32.dll
MOD - [2009/07/14 03:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV:64bit: - File not found [Auto | Stopped] -- C:\Windows\SysNative\nagasoft\vjocx.dll -- (vvdsvc)
SRV:64bit: - [2010/03/23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\stacsv64.exe -- (STacSV)
SRV:64bit: - [2010/02/26 21:34:42 | 000,030,520 | ---- | M] (Hewlett-Packard Company) [Auto | Stopped] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv)
SRV:64bit: - [2009/12/22 12:44:28 | 001,030,600 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2009/07/14 03:41:56 | 000,195,072 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService)
SRV:64bit: - [2009/07/14 03:41:53 | 001,361,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\PeerDistSvc.dll -- (PeerDistSvc)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:24 | 000,689,152 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\cscsvc.dll -- (CscService)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/07/12 23:18:24 | 001,924,400 | ---- | M] (Validity Sensors, Inc.) [Auto | Stopped] -- C:\Windows\SysNative\vcsFPService.exe -- (vcsFPService)
SRV:64bit: - [2009/03/12 17:39:54 | 000,086,016 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe -- (mi-raysat_3dsmax2010_64)
SRV:64bit: - [2009/03/02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Stopped] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters)
SRV - [2010/09/13 16:43:06 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/01/25 17:55:49 | 000,079,360 | ---- | M] (Autodesk) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2009/10/14 16:42:38 | 000,583,640 | ---- | M] (PC Tools) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2009/09/24 11:59:26 | 001,695,368 | ---- | M] (NanJing Nagasoft Co, LTD.) [Auto | Stopped] -- C:\Windows\SysWOW64\nagasoft\vjocx.dll -- (vvdsvc)
SRV - [2009/07/12 23:04:26 | 001,656,112 | ---- | M] (Validity Sensors, Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\vcsFPService.exe -- (vcsFPService)
SRV - [2008/10/25 12:44:08 | 000,065,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2008/03/10 01:04:52 | 000,065,536 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe -- (mi-raysat_3dsMax2009_32)
SRV - [2007/11/20 11:52:30 | 000,045,700 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\cebas\ip-clamp\ipclamp.exe -- (IPClampService)
SRV - [2007/10/24 13:43:48 | 000,139,268 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\DCPFLICS\DCPFLICS.exe -- (DCPFLICS)
SRV - [2006/12/19 09:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Stopped] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/05/27 22:32:56 | 000,320,560 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/03/23 14:53:06 | 000,505,344 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2010/02/26 21:34:48 | 000,030,008 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt)
DRV:64bit: - [2010/02/26 21:34:30 | 000,041,272 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer)
DRV:64bit: - [2009/12/01 16:01:16 | 000,019,912 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
DRV:64bit: - [2009/12/01 16:01:08 | 000,013,264 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)
DRV:64bit: - [2009/11/12 06:14:28 | 000,084,584 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2009/10/10 04:41:20 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009/08/21 01:20:18 | 000,356,096 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2009/08/21 01:20:18 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2009/08/21 01:20:18 | 000,092,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2009/08/21 01:20:18 | 000,063,488 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 03:45:55 | 000,200,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmbus.sys -- (vmbus)
DRV:64bit: - [2009/07/14 03:45:55 | 000,046,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmstorfl.sys -- (storflt)
DRV:64bit: - [2009/07/14 03:45:55 | 000,034,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\storvsc.sys -- (storvsc)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:42:58 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vms3cap.sys -- (s3cap)
DRV:64bit: - [2009/07/14 01:42:44 | 000,021,760 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VMBusHID.sys -- (VMBusHID)
DRV:64bit: - [2009/07/14 01:24:27 | 000,514,048 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\csc.sys -- (CSC)
DRV:64bit: - [2009/07/08 01:45:50 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/06/10 22:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/22 23:52:30 | 000,215,040 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/05/18 15:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/05/09 02:14:20 | 000,015,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr)
DRV:64bit: - [2009/04/29 09:48:32 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C8 A2 07 BA 02 51 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files (x86)\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (Ask.com)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2.0\Extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\Components [2010/01/23 01:42:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2.0\Extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\Plugins [2010/08/04 00:31:32 | 000,000,000 | ---D | M]

[2010/01/23 01:42:42 | 000,000,000 | ---D | M] -- C:\Users\ketla\AppData\Roaming\mozilla\Extensions
[2010/01/23 01:42:42 | 000,000,000 | ---D | M] -- C:\Users\ketla\AppData\Roaming\mozilla\Firefox\Profiles\dbx6c2fl.default\extensions
[2010/08/24 17:04:40 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/08/04 00:31:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/24 17:04:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/09/17 00:05:10 | 000,000,002 | RH-- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Ask Search Assistant BHO) - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files (x86)\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (Ask.com)
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {FE063DB9-4EC0-403E-8DD8-394C54984B2C} - C:\Program Files (x86)\AskTBar\bar\1.bin\ASKTBAR.DLL (Ask.com)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BCWipeTM Startup] C:\Program Files (x86)\Jetico\BCWipe\BCWipeTM.exe (Jetico, Inc.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files (x86)\Registry Mechanic\RMTray.exe (PC Tools )
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} vexcast.com/download/vexcast.cab (VodClient Control Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.101.93.101 83.103.25.250
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/22 12:29:09 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O33 - MountPoints2\{3452386f-0c40-11df-bb78-a11b0fdd3a1c}\Shell - "" = AutoRun
O33 - MountPoints2\{3452386f-0c40-11df-bb78-a11b0fdd3a1c}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/09/17 00:03:15 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/09/15 19:10:15 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\ketla\Desktop\OTL.exe
[2010/09/14 20:12:39 | 000,000,000 | ---D | C] -- C:\Users\ketla\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/09/14 17:12:02 | 000,000,000 | ---D | C] -- C:\Users\ketla\AppData\Roaming\Adobe Mini Bridge CS5
[2010/09/14 16:40:20 | 000,000,000 | ---D | C] -- C:\Users\ketla\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/09/14 16:37:58 | 000,000,000 | ---D | C] -- C:\Users\ketla\AppData\Roaming\PACE Anti-Piracy
[2010/09/14 16:37:58 | 000,000,000 | ---D | C] -- C:\Users\ketla\AppData\Local\PACE Anti-Piracy
[2010/09/14 16:37:58 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE Anti-Piracy
[2010/09/14 16:37:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PACE Anti-Piracy
[2010/09/14 16:37:27 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2010/09/14 12:59:39 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe
[2010/09/14 12:54:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Media Player
[2010/09/14 12:52:28 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/09/14 12:51:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2010/09/13 18:58:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\cebas
[2010/09/13 18:53:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Autodesk
[2010/09/13 16:59:20 | 000,000,000 | ---D | C] -- C:\Users\ketla\Documents\Adobe
[2010/09/13 16:48:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/08/29 00:26:08 | 000,000,000 | ---D | C] -- C:\Users\ketla\Desktop\The Prestige DvDrip[Eng]
[2010/08/24 17:27:00 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\sdbus.sys
[2010/08/24 17:04:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2010/08/24 17:04:36 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2010/08/24 17:04:36 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2010/08/24 17:04:36 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/09/17 00:38:29 | 005,242,880 | -HS- | M] () -- C:\Users\ketla\NTUSER.DAT
[2010/09/17 00:06:06 | 016,047,544 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/17 00:06:06 | 000,704,246 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2010/09/17 00:06:06 | 000,703,252 | ---- | M] () -- C:\Windows\SysNative\perfh00A.dat
[2010/09/17 00:06:06 | 000,700,828 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat
[2010/09/17 00:06:06 | 000,699,122 | ---- | M] () -- C:\Windows\SysNative\perfh010.dat
[2010/09/17 00:06:06 | 000,699,056 | ---- | M] () -- C:\Windows\SysNative\perfh015.dat
[2010/09/17 00:06:06 | 000,689,166 | ---- | M] () -- C:\Windows\SysNative\prfh0816.dat
[2010/09/17 00:06:06 | 000,685,902 | ---- | M] () -- C:\Windows\SysNative\perfh019.dat
[2010/09/17 00:06:06 | 000,673,656 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
[2010/09/17 00:06:06 | 000,653,294 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2010/09/17 00:06:06 | 000,642,218 | ---- | M] () -- C:\Windows\SysNative\perfh00E.dat
[2010/09/17 00:06:06 | 000,633,372 | ---- | M] () -- C:\Windows\SysNative\perfh005.dat
[2010/09/17 00:06:06 | 000,627,932 | ---- | M] () -- C:\Windows\SysNative\perfh01D.dat
[2010/09/17 00:06:06 | 000,626,252 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/09/17 00:06:06 | 000,620,570 | ---- | M] () -- C:\Windows\SysNative\perfh01F.dat
[2010/09/17 00:06:06 | 000,560,840 | ---- | M] () -- C:\Windows\SysNative\perfh008.dat
[2010/09/17 00:06:06 | 000,472,278 | ---- | M] () -- C:\Windows\SysNative\perfh006.dat
[2010/09/17 00:06:06 | 000,458,720 | ---- | M] () -- C:\Windows\SysNative\perfh014.dat
[2010/09/17 00:06:06 | 000,445,430 | ---- | M] () -- C:\Windows\SysNative\perfh001.dat
[2010/09/17 00:06:06 | 000,443,408 | ---- | M] () -- C:\Windows\SysNative\perfh00B.dat
[2010/09/17 00:06:06 | 000,412,160 | ---- | M] () -- C:\Windows\SysNative\perfh012.dat
[2010/09/17 00:06:06 | 000,400,882 | ---- | M] () -- C:\Windows\SysNative\perfh011.dat
[2010/09/17 00:06:06 | 000,388,114 | ---- | M] () -- C:\Windows\SysNative\prfh0404.dat
[2010/09/17 00:06:06 | 000,372,012 | ---- | M] () -- C:\Windows\SysNative\prfh0804.dat
[2010/09/17 00:06:06 | 000,364,782 | ---- | M] () -- C:\Windows\SysNative\perfh00D.dat
[2010/09/17 00:06:06 | 000,151,734 | ---- | M] () -- C:\Windows\SysNative\perfc00E.dat
[2010/09/17 00:06:06 | 000,140,794 | ---- | M] () -- C:\Windows\SysNative\perfc00A.dat
[2010/09/17 00:06:06 | 000,138,406 | ---- | M] () -- C:\Windows\SysNative\perfc015.dat
[2010/09/17 00:06:06 | 000,137,434 | ---- | M] () -- C:\Windows\SysNative\prfc0816.dat
[2010/09/17 00:06:06 | 000,136,594 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat
[2010/09/17 00:06:06 | 000,135,904 | ---- | M] () -- C:\Windows\SysNative\perfc019.dat
[2010/09/17 00:06:06 | 000,133,814 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2010/09/17 00:06:06 | 000,133,128 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2010/09/17 00:06:06 | 000,131,798 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
[2010/09/17 00:06:06 | 000,130,906 | ---- | M] () -- C:\Windows\SysNative\perfc010.dat
[2010/09/17 00:06:06 | 000,127,440 | ---- | M] () -- C:\Windows\SysNative\perfc01D.dat
[2010/09/17 00:06:06 | 000,125,408 | ---- | M] () -- C:\Windows\SysNative\perfc005.dat
[2010/09/17 00:06:06 | 000,125,054 | ---- | M] () -- C:\Windows\SysNative\perfc01F.dat
[2010/09/17 00:06:06 | 000,110,176 | ---- | M] () -- C:\Windows\SysNative\perfc011.dat
[2010/09/17 00:06:06 | 000,110,176 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/09/17 00:06:06 | 000,108,464 | ---- | M] () -- C:\Windows\SysNative\perfc012.dat
[2010/09/17 00:06:06 | 000,108,036 | ---- | M] () -- C:\Windows\SysNative\prfc0804.dat
[2010/09/17 00:06:06 | 000,103,122 | ---- | M] () -- C:\Windows\SysNative\prfc0404.dat
[2010/09/17 00:06:06 | 000,092,868 | ---- | M] () -- C:\Windows\SysNative\perfc008.dat
[2010/09/17 00:06:06 | 000,085,602 | ---- | M] () -- C:\Windows\SysNative\perfc00B.dat
[2010/09/17 00:06:06 | 000,083,494 | ---- | M] () -- C:\Windows\SysNative\perfc006.dat
[2010/09/17 00:06:06 | 000,082,772 | ---- | M] () -- C:\Windows\SysNative\perfc001.dat
[2010/09/17 00:06:06 | 000,080,764 | ---- | M] () -- C:\Windows\SysNative\perfc014.dat
[2010/09/17 00:06:06 | 000,072,882 | ---- | M] () -- C:\Windows\SysNative\perfc00D.dat
[2010/09/17 00:01:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/09/16 16:05:35 | 000,983,065 | -H-- | M] () -- C:\Users\ketla\AppData\Local\IconCache.db
[2010/09/16 16:01:27 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/09/16 11:41:37 | 000,013,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/16 11:41:37 | 000,013,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/15 21:02:39 | 007,227,854 | ---- | M] () -- C:\Users\ketla\Desktop\Sequence 01_4.wmv
[2010/09/15 21:01:00 | 000,000,132 | ---- | M] () -- C:\Users\ketla\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/09/15 20:57:58 | 006,429,161 | ---- | M] () -- C:\Users\ketla\Desktop\Sequence 01_3.wmv
[2010/09/15 20:53:20 | 006,428,934 | ---- | M] () -- C:\Users\ketla\Desktop\Sequence 01_2.wmv
[2010/09/15 19:10:15 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\ketla\Desktop\OTL.exe
[2010/09/15 17:14:20 | 000,199,855 | ---- | M] () -- C:\Users\ketla\Desktop\1713.jpg
[2010/09/14 21:44:01 | 000,091,938 | ---- | M] () -- C:\Users\ketla\Desktop\PREVENTIVO 186 06-09-10 LUCA MATIC.pdf
[2010/09/14 20:42:04 | 006,937,583 | ---- | M] () -- C:\Users\ketla\Desktop\Sequence 01_1.wmv
[2010/09/14 19:00:00 | 007,566,101 | ---- | M] () -- C:\Users\ketla\Desktop\Sequence 01.wmv
[2010/09/14 16:47:44 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2010/09/14 16:47:42 | 000,003,584 | ---- | M] () -- C:\Users\ketla\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/14 16:38:00 | 000,000,021 | ---- | M] () -- C:\Windows\SurCode.INI
[2010/09/14 16:37:51 | 000,189,712 | ---- | M] () -- C:\Users\ketla\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/09/14 16:35:22 | 005,434,208 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/09/13 19:05:45 | 000,000,616 | ---- | M] () -- C:\ipclamp.lic
[2010/09/13 18:58:36 | 000,000,190 | ---- | M] () -- C:\Windows\{6BC52438-5DE4-4102-846E-64C225A0A04E}_WiseFW.ini
[2010/09/10 18:33:41 | 000,000,857 | ---- | M] () -- C:\Users\ketla\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/25 16:51:08 | 735,840,256 | ---- | M] () -- C:\Users\ketla\Desktop\The Killer Inside Me.avi
[2010/08/24 00:59:41 | 000,114,176 | ---- | M] () -- C:\Users\ketla\Desktop\Progetti AM.doc
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/09/15 20:59:50 | 007,227,854 | ---- | C] () -- C:\Users\ketla\Desktop\Sequence 01_4.wmv
[2010/09/15 20:57:03 | 006,429,161 | ---- | C] () -- C:\Users\ketla\Desktop\Sequence 01_3.wmv
[2010/09/15 20:24:51 | 006,428,934 | ---- | C] () -- C:\Users\ketla\Desktop\Sequence 01_2.wmv
[2010/09/15 17:14:19 | 000,199,855 | ---- | C] () -- C:\Users\ketla\Desktop\1713.jpg
[2010/09/14 21:44:01 | 000,091,938 | ---- | C] () -- C:\Users\ketla\Desktop\PREVENTIVO 186 06-09-10 LUCA MATIC.pdf
[2010/09/14 20:40:52 | 006,937,583 | ---- | C] () -- C:\Users\ketla\Desktop\Sequence 01_1.wmv
[2010/09/14 19:55:22 | 000,000,132 | ---- | C] () -- C:\Users\ketla\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/09/14 18:58:56 | 007,566,101 | ---- | C] () -- C:\Users\ketla\Desktop\Sequence 01.wmv
[2010/09/14 16:47:42 | 000,003,584 | ---- | C] () -- C:\Users\ketla\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/14 16:38:00 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2010/09/13 19:05:45 | 000,000,616 | ---- | C] () -- C:\ipclamp.lic
[2010/09/13 18:58:34 | 000,000,190 | ---- | C] () -- C:\Windows\{6BC52438-5DE4-4102-846E-64C225A0A04E}_WiseFW.ini
[2010/08/26 22:41:59 | 732,839,936 | ---- | C] () -- C:\Users\ketla\Desktop\Balkanski spijun.avi
[2010/08/26 22:41:16 | 592,788,480 | ---- | C] () -- C:\Users\ketla\Desktop\Cudo nevidjeno DVDRip.avi
[2010/08/25 22:34:57 | 735,840,256 | ---- | C] () -- C:\Users\ketla\Desktop\The Killer Inside Me.avi
[2010/08/24 00:59:41 | 000,114,176 | ---- | C] () -- C:\Users\ketla\Desktop\Progetti AM.doc
[2010/07/30 17:44:32 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010/07/08 17:31:16 | 000,042,496 | ---- | C] () -- C:\Windows\SysWow64\spwini.dll
[2010/06/18 21:46:05 | 016,045,944 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/06/15 08:31:16 | 000,007,867 | ---- | C] () -- C:\Windows\Irremote.ini
[2010/02/09 15:54:59 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\BongoSDK.10.v40.dll
[2010/02/02 04:37:37 | 000,007,606 | ---- | C] () -- C:\Users\ketla\AppData\Local\Resmon.ResmonCfg
[2009/12/20 23:44:35 | 000,000,000 | ---- | C] () -- C:\Users\ketla\AppData\Local\QSwitch.txt
[2009/12/20 23:44:35 | 000,000,000 | ---- | C] () -- C:\Users\ketla\AppData\Local\DSwitch.txt
[2009/12/20 23:44:35 | 000,000,000 | ---- | C] () -- C:\Users\ketla\AppData\Local\AtStart.txt
[2009/12/20 20:36:50 | 000,000,990 | ---- | C] () -- C:\Users\ketla\AppData\Local\7F68A003.il
[2009/12/20 20:36:50 | 000,000,832 | ---- | C] () -- C:\Users\ketla\AppData\Local\IndexIE_7F68A003.il
[2009/09/09 22:48:52 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009/08/03 01:21:54 | 000,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2009/08/03 01:21:54 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2009/08/03 01:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2009/08/03 01:21:52 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\l3xg9ld.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\grcauth2.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\grcauth1.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2009/07/14 01:16:42 | 000,000,204 | ---- | C] () -- C:\Windows\SysWow64\dm1z3qm.dll
[2009/07/14 01:16:42 | 000,000,100 | ---- | C] () -- C:\Windows\SysWow64\prsgrc.dll
[2009/07/14 01:16:42 | 000,000,072 | ---- | C] () -- C:\Windows\SysWow64\ssprs.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\ycirz9f.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\xyt9nbw.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\xg865ij.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\wj3y40q.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\w4yzvjq.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\vb0va0g.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\ttultdr.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\tnzp27s.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\saw1xwv.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\rq6s5eb.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\r6p7i2c.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\qsfaqqr.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\qiytnp7.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\q08oitn.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\oro2h6n.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\nswo6p5.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\kg7i665.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\kambidt.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\k2691bc.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\jj3o7s7.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\je1pkjv.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\iz9g894.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\iz8rxkx.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\iokz40o.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\iobcfeo.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\hscd3md.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\hnmobfd.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\gcmtilx.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\g0efyts.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\f89ozph.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\e9eiwew.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\d42idnp.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\d3yzriv.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\bysg6r4.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\bmjp25q.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\afj3k99.dll
[2009/07/13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/05/29 17:52:26 | 000,204,800 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009/05/29 17:47:06 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2007/09/04 13:56:10 | 000,164,352 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2007/02/05 21:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2007/01/23 15:18:10 | 000,000,618 | ---- | C] () -- C:\Windows\SAP2000v11.ini
< End of report >

Dopuna: 17 Sep 2010 0:55

Evo me se javljam iz Normalnog moda. Izgleda sve bajno i krasno. 59 aktivnih procesa, nema kocenja. Hvala i pozz do sutra.

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

-Izvinjavam se sto malo kasnim sa odgovorom;
-Detaljno isprati sledece uputstvo.





----------------------------------------------------------------------------------------
Ponovo pokreni program OTL dvoklikom na ikonicu;

U beli okvir prozora gde piše Custom Scans/Fixes iskopirati sledeći tekst:

:OTL
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\l3xg9ld.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\grcauth2.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\grcauth1.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2009/07/14 01:16:42 | 000,001,024 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2009/07/14 01:16:42 | 000,000,204 | ---- | C] () -- C:\Windows\SysWow64\dm1z3qm.dll
[2009/07/14 01:16:42 | 000,000,100 | ---- | C] () -- C:\Windows\SysWow64\prsgrc.dll
[2009/07/14 01:16:42 | 000,000,072 | ---- | C] () -- C:\Windows\SysWow64\ssprs.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\ycirz9f.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\xyt9nbw.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\xg865ij.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\wj3y40q.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\w4yzvjq.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\vb0va0g.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\ttultdr.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\tnzp27s.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\saw1xwv.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\rq6s5eb.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\r6p7i2c.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\qsfaqqr.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\qiytnp7.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\q08oitn.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\oro2h6n.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\nswo6p5.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\kg7i665.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\kambidt.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\k2691bc.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\jj3o7s7.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\je1pkjv.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\iz9g894.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\iz8rxkx.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\iokz40o.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\iobcfeo.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\hscd3md.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\hnmobfd.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\gcmtilx.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\g0efyts.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\f89ozph.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\e9eiwew.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\d42idnp.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\d3yzriv.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\bysg6r4.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\bmjp25q.dll
[2009/07/14 01:16:42 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\afj3k99.dll



Klikni taster Run Fix;


Log koji dobiješ iskopiraj ovde u poruci.




goran9888 (AMF Tim)

Ko je trenutno na forumu
 

Ukupno su 841 korisnika na forumu :: 44 registrovanih, 6 sakrivenih i 791 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Sale, A.R.Chafee.Jr., aramis s, bankulen, Bogoslov, bojanM84, Cigi, damirZR, dankisha, DENIRO, djboj, dragon986, Drug pukovnik, dzoni19, Džordžino, Filip Marinković, havoc995, Krusarac, kvcali, maiden6657, mane123, MB120mm, Mercury, milosrdni94, mrav pesadinac, nebojsag, nenad81, operniki, panonski mornar, Panonsky, Pohovani_00, repac, ruma, Snorks, sombrero, theNedjeljko, Toni, VanHelsing, vathra, vdeki, VJ, Vlada1389, VladaKG1980, Živković