problem sa facebook mezom (redirekcija)

problem sa facebook mezom (redirekcija)

offline
  • Pridružio: 22 Apr 2012
  • Poruke: 1

Pozdrav za sve,
Od pre nekoliko dana imam problem sa facebook mezom. Kad pokusam da se logujem otara mi se vk mreza. Molim za pomoc.


OTL logfile created on: 4/22/2012 2:49:39 PM - Run 1
OTL by OldTimer - Version 3.2.40.0 Folder = C:\Users\Ognjen i Kristina\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 42.53% Memory free
4.00 Gb Paging File | 2.59 Gb Available in Paging File | 64.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 48.73 Gb Total Space | 4.38 Gb Free Space | 8.99% Space Free | Partition Type: NTFS
Drive D: | 195.31 Gb Total Space | 189.54 Gb Free Space | 97.04% Space Free | Partition Type: NTFS
Drive E: | 221.62 Gb Total Space | 221.31 Gb Free Space | 99.86% Space Free | Partition Type: NTFS

Computer Name: OGNJENIKRISTINA | User Name: Ognjen i Kristina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/04/22 14:32:12 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Ognjen i Kristina\Downloads\OTL.exe
PRC - [2012/02/23 20:39:33 | 000,232,960 | ---- | M] () -- C:\Windows\l1rezerv.exe
PRC - [2012/02/23 20:13:53 | 000,130,560 | ---- | M] () -- C:\Windows\systemup.exe
PRC - [2012/02/04 18:07:11 | 000,424,568 | ---- | M] (http://www.express-files.com/) -- C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe
PRC - [2012/02/04 18:07:11 | 000,188,024 | ---- | M] (http://www.express-files.com/) -- C:\Program Files (x86)\ExpressFiles\EFupdater.exe
PRC - [2012/01/25 18:00:53 | 000,737,656 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012/01/13 16:39:56 | 000,137,536 | ---- | M] (Facebook Inc.) -- C:\Users\Ognjen i Kristina\AppData\Local\Facebook\Update\FacebookUpdate.exe
PRC - [2012/01/10 16:00:21 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/01/06 12:17:22 | 000,551,669 | ---- | M] () -- C:\Win\lsass.exe
PRC - [2011/12/11 10:57:55 | 000,378,880 | ---- | M] () -- C:\Windows\update.7.1\svchostdriver.exe
PRC - [2011/12/11 10:46:01 | 000,257,024 | ---- | M] () -- C:\Windows\sysdriver32.exe
PRC - [2011/11/30 17:40:58 | 000,102,712 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Linkury.exe
PRC - [2011/11/29 17:50:40 | 000,182,576 | ---- | M] (Blabbers Communications LTD) -- C:\Program Files (x86)\BrowserCompanion\BCHelper.exe
PRC - [2011/09/01 20:18:54 | 004,862,384 | ---- | M] (Exent Technologies Ltd.) -- C:\Program Files (x86)\Free Ride Games\GPlayer.exe
PRC - [2011/03/17 10:15:46 | 000,382,272 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2011/03/17 10:15:04 | 000,842,048 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe
PRC - [2009/08/17 01:32:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/03/08 12:52:46 | 000,076,800 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko9.dll
MOD - [2012/02/23 20:39:33 | 000,232,960 | ---- | M] () -- C:\Windows\l1rezerv.exe
MOD - [2012/02/23 20:13:53 | 000,130,560 | ---- | M] () -- C:\Windows\systemup.exe
MOD - [2012/01/10 16:00:21 | 002,124,760 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/01/06 12:17:22 | 000,551,669 | ---- | M] () -- C:\Win\lsass.exe
MOD - [2011/12/11 17:48:00 | 008,013,664 | ---- | M] () -- C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
MOD - [2011/12/11 17:48:00 | 000,139,264 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll
MOD - [2011/12/11 17:48:00 | 000,118,784 | ---- | M] () -- C:\Windows\assembly\GAC\Microsoft.VisualStudio.OLE.Interop\7.1.40304.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.OLE.Interop.dll
MOD - [2011/11/30 17:41:44 | 000,016,184 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.Utilities.dll
MOD - [2011/11/30 17:41:40 | 000,024,888 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.SocialNetsSharer.dll
MOD - [2011/11/30 17:41:38 | 000,033,592 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.SetBrowsersSettingsAutoUpdater.dll
MOD - [2011/11/30 17:41:38 | 000,019,256 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.SideBySide.dll
MOD - [2011/11/30 17:41:34 | 000,013,112 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.ProcessDownMonitor.dll
MOD - [2011/11/30 17:41:30 | 000,330,040 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.FilesManager.dll
MOD - [2011/11/30 17:41:30 | 000,066,360 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
MOD - [2011/11/30 17:41:28 | 000,033,592 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Resources.AutomaticUpdates.dll
MOD - [2011/11/30 17:41:24 | 000,015,672 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Personalization.Common.dll
MOD - [2011/11/30 17:41:22 | 000,076,600 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Personalization.BusinessLogic.dll
MOD - [2011/11/30 17:41:16 | 000,018,232 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Infrastructure.Utilities.dll
MOD - [2011/11/30 17:41:14 | 000,052,024 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
MOD - [2011/11/30 17:41:06 | 000,024,376 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Infrastructure.Core.dll
MOD - [2011/11/30 17:41:06 | 000,012,088 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.Infrastructure.BusinessEntities.dll
MOD - [2011/11/30 17:41:04 | 000,013,112 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.GUI.Multimedia.Loader.dll
MOD - [2011/11/30 17:41:02 | 000,838,456 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.GUI.MainClient.dll
MOD - [2011/11/30 17:41:00 | 000,080,184 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.GUI.Docking.dll
MOD - [2011/11/30 17:40:58 | 000,541,496 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Smartbar.GUI.Controls.dll
MOD - [2011/11/30 17:40:58 | 000,102,712 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Linkury.exe
MOD - [2011/11/30 17:35:52 | 000,040,960 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\MACTrackBarLib.dll
MOD - [2011/08/07 13:54:44 | 000,362,029 | ---- | M] () -- C:\Program Files (x86)\BrowserCompanion\sqlite3.dll
MOD - [2011/08/01 17:24:44 | 006,271,648 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2009/07/14 07:00:27 | 000,220,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c0f61f9b73571f26b6e0e0757bc5f460\CustomMarshalers.ni.dll
MOD - [2009/07/14 06:56:04 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\0929bf4ca3bc8e8b2131f27cdf500c7e\System.Web.Services.ni.dll
MOD - [2009/07/14 06:56:03 | 011,804,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\3871fc2b96345aa6f3be81d9e3c97160\System.Web.ni.dll
MOD - [2009/07/14 06:55:32 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll
MOD - [2009/07/14 06:55:26 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll
MOD - [2009/07/14 06:55:09 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll
MOD - [2009/07/14 06:55:06 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b1350e31ff09cc583b34854816d8036\System.Configuration.ni.dll
MOD - [2009/07/14 06:55:05 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll
MOD - [2009/07/14 06:55:00 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll
MOD - [2009/06/10 23:22:50 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/12/11 10:57:55 | 000,378,880 | ---- | M] () [Auto | Running] -- C:\Windows\update.7.1\svchostdriver.exe -- (ddservice)
SRV - [2011/12/11 10:46:01 | 000,257,024 | ---- | M] () [Auto | Running] -- C:\Windows\sysdriver32.exe -- (srvsysdriver32)
SRV - [2009/08/17 01:32:00 | 000,239,648 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/02/04 17:47:20 | 000,526,392 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2009/08/11 09:19:18 | 000,084,000 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 22:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2010/11/22 10:25:12 | 000,055,400 | ---- | M] (Exent Technologies Ltd.) [Kernel | Auto | Running] -- C:\Program Files (x86)\Free Ride Games\X5XSEx.sys -- (X5XSEx)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Mystart.incredibar.com/mb124
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 03 67 60 A6 B6 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = plusnetwork.com/?q={searchTerms}&sp=chv
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = search.babylon.com/?q={searchTerms}&AF=109130&babsrc=SP_ss&mntrId=acf339b0000000000000002421ec8049
IE - HKCU\..\SearchScopes\{56EB44D8-613A-40B2-96B6-05614961EEA9}: "URL" = search.softonic.com/MON00005/tb_v1?q={searchTerms}&SearchSource=4&cc=
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2786678
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = mystart.incredibar.com/mb119/?search={searchTerms}&loc=IB_DS&a=6R8mCbrBdD&i=26
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Messenger Plus Smartbar Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..keyword.URL: "http://www.plusnetwork.com/?sp=chv&q="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0: C:\Program Files (x86)\Free Ride Games\npExentCtl.dll (Exent Technologies Ltd.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Ognjen i Kristina\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/10 16:00:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/08/01 17:19:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Extensions
[2012/04/22 12:52:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions
[2012/03/08 16:55:47 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/12/11 17:48:16 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\bbrs_002@blabbers.com
[2012/02/04 18:25:37 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\ffxtlbr@babylon.com
[2012/02/22 21:07:55 | 000,000,000 | ---D | M] (Softonic Toolbar) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\ffxtlbra@softonic.com
[2012/03/12 18:33:24 | 000,000,000 | ---D | M] (wxDfast) -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\info@wxdownloadmanager.com
[2012/04/22 12:52:14 | 000,000,000 | ---D | M] ("Messenger Plus! Community Smartbar") -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\extensions\linkuryfirefoxremoteplugin@linkury.com
[2012/01/11 12:47:26 | 000,000,925 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\searchplugins\conduit.xml
[2012/04/22 12:52:14 | 000,002,242 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\searchplugins\Messenger Plus Smartbar Search.xml
[2012/03/12 18:33:14 | 000,002,203 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\searchplugins\MyStart Search.xml
[2012/02/04 17:46:46 | 000,002,060 | ---- | M] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\maohqejq.default\searchplugins\softonic.xml
[2011/08/01 17:19:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/10 16:00:21 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/02/04 18:07:17 | 000,002,310 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/01/10 16:00:19 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/01/10 16:00:19 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - default_search_provider: Messenger Plus Smartbar Search (Enabled)
CHR - default_search_provider: search_url = plusnetwork.com/?q={searchTerms}&sp=chv
CHR - default_search_provider: suggest_url =

O1 HOSTS File: ([2012/04/22 13:33:59 | 000,202,984 | -H-- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 facebook.com
O1 - Hosts: 127.0.0.1 af-za.facebook.com
O1 - Hosts: 127.0.0.1 az-az.facebook.com
O1 - Hosts: 127.0.0.1 id-id.facebook.com
O1 - Hosts: 127.0.0.1 ms-my.facebook.com
O1 - Hosts: 127.0.0.1 bs-ba.facebook.com
O1 - Hosts: 127.0.0.1 ca-es.facebook.com
O1 - Hosts: 127.0.0.1 cs-cz.facebook.com
O1 - Hosts: 127.0.0.1 cy-gb.facebook.com
O1 - Hosts: 127.0.0.1 da-dk.facebook.com
O1 - Hosts: 127.0.0.1 de-de.facebook.com
O1 - Hosts: 127.0.0.1 et-ee.facebook.com
O1 - Hosts: 127.0.0.1 en-gb.facebook.com
O1 - Hosts: 127.0.0.1 es-la.facebook.com
O1 - Hosts: 127.0.0.1 eo-eo.facebook.com
O1 - Hosts: 127.0.0.1 eu-es.facebook.com
O1 - Hosts: 127.0.0.1 tl-ph.facebook.com
O1 - Hosts: 127.0.0.1 fo-fo.facebook.com
O1 - Hosts: 127.0.0.1 fr-fr.facebook.com
O1 - Hosts: 127.0.0.1 fy-nl.facebook.com
O1 - Hosts: 127.0.0.1 ga-ie.facebook.com
O1 - Hosts: 127.0.0.1 gl-es.facebook.com
O1 - Hosts: 127.0.0.1 ko-kr.facebook.com
O1 - Hosts: 50053 more lines...
O2 - BHO: (Chatvibes Browser Helper) - {00cbb66b-1d3b-46d3-9577-323a336acb50} - C:\Program Files (x86)\BrowserCompanion\jsloader.dll ( )
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Incredibar.com Helper Object) - {6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.3.27\bh\incredibar.dll (Montera Technologeis LTD)
O2 - BHO: (wxDfast Class) - {8E11F7F5-4E56-43C1-98A7-68FD1B9EC6C4} - C:\ProgramData\wxDfast\bhoclass.dll (Injector)
O2 - BHO: (Chatvibes Browser Helper Verifier) - {963B125B-8B21-49A2-A3A8-E37092276531} - C:\Program Files (x86)\BrowserCompanion\updatebhoWin32.dll ( )
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Softonic Helper Object) - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\softonic\1.5.11.5\bh\softonic.dll (Softonic.com)
O3 - HKLM\..\Toolbar: (Softonic Toolbar) - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\softonic\1.5.11.5\softonicTlbr.dll (Softonic.com)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Incredibar Toolbar) - {F9639E4A-801B-4843-AEE3-03D9DA199E77} - C:\Program Files (x86)\Incredibar.com\incredibar\1.5.3.27\incredibarTlbr.dll (Montera Technologeis LTD)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [2615923.exe] C:\Windows\Temp\2615923.exe ()
O4 - HKLM..\Run: [6122512.exe] C:\Users\Ognjen i Kristina\AppData\Local\Temp\6122512.exe ()
O4 - HKLM..\Run: [6775569.exe] C:\Users\Ognjen i Kristina\AppData\Local\Temp\6775569.exe ()
O4 - HKLM..\Run: [720386.exe] C:\Windows\Temp\720386.exe ()
O4 - HKLM..\Run: [811953.exe] C:\Windows\Temp\811953.exe ()
O4 - HKLM..\Run: [Browser companion helper] C:\Program Files (x86)\BrowserCompanion\BCHelper.exe (Blabbers Communications LTD)
O4 - HKLM..\Run: [ExpressFiles] C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe (http://www.express-files.com/)
O4 - HKLM..\Run: [l1rezerv.exe] C:\Windows\l1rezerv.exe ()
O4 - HKLM..\Run: [run32] C:\Win\lsass.exe ()
O4 - HKLM..\Run: [sysdriver32.exe] C:\Windows\sysdriver32.exe ()
O4 - HKLM..\Run: [sysdriver32_.exe] C:\Windows\sysdriver32_.exe ()
O4 - HKLM..\Run: [systemup] C:\Windows\systemup.exe ()
O4 - HKLM..\Run: [wxpdrv] C:\Windows\update.1\svchost.exe ()
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Exetender] C:\Program Files (x86)\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Ognjen i Kristina\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Linkury Chrome Smartbar] C:\Users\Ognjen i Kristina\AppData\Local\Linkury\Application\Linkury.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8690037-D745-4AB2-A705-04FB4753147F}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\base64 - No CLSID value found
O18:64bit: - Protocol\Handler\chrome - No CLSID value found
O18:64bit: - Protocol\Handler\prox - No CLSID value found
O18 - Protocol\Handler\base64 {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\chrome {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O18 - Protocol\Handler\prox {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (Blabbers Communications Ltd)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O31 - SafeBoot: AlternateShell - services32.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2012/04/22 13:24:02 | 000,000,000 | ---D | C] -- C:\Users\Ognjen i Kristina\AppData\Local\ElevatedDiagnostics
[2012/04/22 13:15:39 | 000,000,000 | RHSD | C] -- C:\Win
[2012/04/15 22:41:48 | 000,000,000 | ---D | C] -- C:\Users\Ognjen i Kristina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Fortress 2012
[2012/04/15 22:41:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Fortress 2012
[2012/04/15 22:37:44 | 000,000,000 | ---D | C] -- C:\ProgramData\F4D561EAD7A13CDB62B2658BA6014588

========== Files - Modified Within 30 Days ==========

[2012/04/22 13:40:37 | 000,713,714 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/22 13:40:37 | 000,615,122 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/04/22 13:40:37 | 000,103,496 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/04/22 13:39:40 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 13:39:40 | 000,014,192 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/22 13:33:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/04/22 13:33:23 | 1610,014,720 | -HS- | M] () -- C:\hiberfil.sys
[2012/04/17 18:44:00 | 000,000,976 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3698507183-3716407587-2362097708-1000UA.job
[2012/04/17 18:34:40 | 000,001,175 | ---- | M] () -- C:\Users\Ognjen i Kristina\Desktop\Milijunas - Shortcut.lnk
[2012/04/08 15:44:00 | 000,000,954 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3698507183-3716407587-2362097708-1000Core.job

========== Files Created - No Company Name ==========

[2012/04/17 18:34:40 | 000,001,175 | ---- | C] () -- C:\Users\Ognjen i Kristina\Desktop\Milijunas - Shortcut.lnk
[2012/02/23 20:39:37 | 000,232,960 | ---- | C] () -- C:\Windows\l1rezerv.exe
[2012/02/23 20:14:01 | 000,130,560 | ---- | C] () -- C:\Windows\systemup.exe
[2012/01/25 22:47:18 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2011/12/11 10:59:27 | 000,246,272 | ---- | C] () -- C:\Windows\unrar.exe
[2011/12/11 10:46:32 | 000,000,000 | ---- | C] () -- C:\Windows\loader2.exe_ok
[2011/12/11 10:46:28 | 000,257,024 | ---- | C] () -- C:\Windows\sysdriver32_.exe
[2011/12/11 10:46:14 | 000,257,024 | ---- | C] () -- C:\Windows\sysdriver32.exe
[2011/12/11 10:40:04 | 001,211,904 | ---- | C] () -- C:\Windows\services32.exe
[2010/12/26 16:15:18 | 000,023,024 | ---- | C] () -- C:\Users\Ognjen i Kristina\AppData\Roaming\UserTile.png
[2010/09/19 09:51:03 | 000,003,584 | ---- | C] () -- C:\Users\Ognjen i Kristina\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/24 19:22:55 | 000,056,320 | ---- | C] () -- C:\Windows\SysWow64\iyvu9_32.dll

< End of report >

mycity.rs/must-login.png

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

U toku riješavanja slučaja, zamolio bih te da se pridržavaš sledećeg:
Detaljno čitati moja uputstva ( ili uputstva kolega koji će me zamjenjivati) i raditi isključivo po njima;
Ne tražiti istovremeno pomoć na drugom mjestu;
Nemoj koristiti druge programe za uklanjanje malware-a, osim onih za koje budeš dobio uputstvo;
U toku intervencije ne koristiti USB memorijske uređaje, dok to ne budem zatražio;
Ukoliko ne odgovorim u roku od 48h, osvježi temu novim post-om;
Ukoliko se ne javiš u roku od 5 dana, zatvorićemo slučaj.

Za više informacija o pravilima Ambulante MyCity foruma: LINK


Arrow

Preuzmi sUBs-ov ComboFix sa sljedeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati fajl, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:provjeriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izvještaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obilježeni tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izvještaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primjetiš da izvještaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje fajla C:\ComboFix.txt uz poruku.

Ko je trenutno na forumu
 

Ukupno su 846 korisnika na forumu :: 6 registrovanih, 0 sakrivenih i 840 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, draggan, Koridor, opt1, Shilok, simazr