offline
- ivana230197
- Novi MyCity građanin
- Pridružio: 21 Maj 2015
- Poruke: 4
|
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Mr.X on sub 23.05.2015 at 20:43:06,89.
Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\Mr.X\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
23.5.2015 20:43:54 Zoek.exe System Restore Point Created Successfully.
==== Empty Folders Check ======================
C:\Program Files\Ubisoft deleted successfully
C:\Program Files\Common Files\Blizzard Entertainment deleted successfully
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\Documents and Settings\Mr.X\Local Settings\Application Data\cache deleted successfully
C:\Documents and Settings\Mr.X\Local Settings\Application Data\GHISLER deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\Program Files\Ubisoft not found
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes' Anti-Malware (portable) not found
C:\Program Files\ComPlus Applications deleted
C:\Program Files\WindowsUpdate deleted
C:\Documents and Settings\Mr.X\.android deleted
C:\Documents and Settings\Mr.X\Local Settings\Application Data\CrashRpt deleted
C:\WINDOWS\system32\sasnative32.exe deleted
C:\WINDOWS\system32\GroupPolicy\Machine deleted
C:\WINDOWS\system32\GroupPolicy\User deleted
C:\WINDOWS\system32\GroupPolicy\gpt.ini deleted
"C:\WINDOWS\Installer\2a88b.msi" deleted
"C:\Documents and Settings\Mr.X\Application Data\ViberPC\config.db" deleted
"C:\Documents and Settings\Mr.X\Application Data\ViberPC\info.db" deleted
"C:\Documents and Settings\Mr.X\Application Data\ViberPC" deleted
==== Firefox Extensions ======================
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Documents and Settings\Mr.X\Application Data\Mozilla\Firefox\Profiles\m6mxdzlj.default
28000D7EEB2FD95A36E1A7539F599C3B - C:\Program Files\Windows Media Player\npdrmv2.dll - Microsoft® DRM
5D41BCD19A3D90E4EBB58A6BFB79E4F7 - C:\Program Files\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
8B6884E3E1E5F8ABA5FA0C6A2B13181D - C:\Program Files\Windows Media Player\npwmsdrm.dll - Microsoft® DRM
08ACECEB47FAF053C468D8AFE44709AD - C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll - Google Update
225D76851EFC6144B4BAD941B3E8989D - C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll - Java(TM) Platform SE 8 U31
B66B4D28D7D0C6322FF235C782CD6B76 - C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 8.0.310.13
653FECD9DFDB918F496A2B86B9D9DE36 - C:\Documents and Settings\Mr.X\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
3CD19649B2C3023D65E67C056457A2BC - C:\Documents and Settings\Mr.X\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
9AE02005247DA91AB1743F5208DBEF76 - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash
==== Fake Chromium Profiles Check ======================
Fake profile C:\Documents and Settings\LocalService\Local Settings\Application Data\Google\Chrome deleted
==== Chromium Look ======================
Google Chrome Version: 43.0.2357.65
Bookmark Manager - Mr.X\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Bookmark Manager - Mr.X\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
==== Chromium Startpages ======================
C:\Documents and Settings\Mr.X\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
m:443":{"fullscreen":1},"https://www.youtube.com:443,https://www.youtube.com:443":{"fullscreen":1}},"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Први кориÑник","per_host_zoom_levels":{}},"protection":{"macs":{}},"savefile":{},"selectfile":{"last_directory":"C:\\Documents and Settings\\Mr.X\\Desktop"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13076196246769375"},"sync_promo":{"startup_count":10},"translate_accepted_count":{"en":0},"translate_blocked_languages":["sr"],"translate_denied_count":{"en":2},"translate_last_denied_time":1.431723e+12,"translate_site_blacklist":["www.cswarzone.com"],"translate_too_often_denied":true,"translate_whitelists":{}}
AA05FBE8E3C17EF9265F190","prefs":{"preference_reset_time":"D4971809875AE72C8A422B5679BC940FA0BA3C5CCA250D98834300E3627EA7CE"},"profile":{"reset_prompt_memento":"A45307B4DC191F9473341EE5E1CB37FAFAA0B5799C6E09A9FA76E7C7A87429EF"},"safebrowsing":{"incidents_sent":"ACDB37352C4B9FCDE1F619223FCD2C049138DF9117A9F68DD821DE36208BC38D"},"search_provider_overrides":"6B5352A9F528A993A61065A4DB610A0F22D82A3BF0BE3BA5519CB5EEDEB9B107","session":{"restore_on_startup":"3DB75EC016DBD32D317D1A5A6EAA94EA4FF3FF3E901EF50DC1DCAF7359C5A17F","startup_urls":"698FA73D9AC683B0FE6B48C320E11176914BF272E8476271EFD0EE5E61328917"},"software_reporter":{"prompt_reason":"300A35946F8BB98DC0DE69B387D9F7F6A15BC9EC2123B4EBF324698964DA25D9","prompt_seed":"9A65E429A9823F9F7C9B589749A0ECD1AFA2D1F132422B200E60CDEA83F879BA","prompt_version":"16FA81A2D4191862263529960477C7D16C30114091E3DD87654F138D0FDDCD48"},"sync":{"remaining_rollback_tries":"6732BEC004842BFC8620B2873BEBAC794501C4CF4487FFDDC265D811374F3F63"}},"super_mac":"409309C50E3F5E3956F342A04FCA0C957FC33FE7E0B4C747BEB45449B7E18B73"},"session":{"restore_on_startup":4,"startup_urls":["http://www.google.rs/"]}}
C:\Documents and Settings\Mr.X\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
m:443":{"fullscreen":1},"https://www.youtube.com:443,https://www.youtube.com:443":{"fullscreen":1}},"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"Први кориÑник","per_host_zoom_levels":{}},"protection":{"macs":{}},"savefile":{},"selectfile":{"last_directory":"C:\\Documents and Settings\\Mr.X\\Desktop"},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13076196246769375"},"sync_promo":{"startup_count":10},"translate_accepted_count":{"en":0},"translate_blocked_languages":["sr"],"translate_denied_count":{"en":2},"translate_last_denied_time":1.431723e+12,"translate_site_blacklist":["www.cswarzone.com"],"translate_too_often_denied":true,"translate_whitelists":{}}
AA05FBE8E3C17EF9265F190","prefs":{"preference_reset_time":"D4971809875AE72C8A422B5679BC940FA0BA3C5CCA250D98834300E3627EA7CE"},"profile":{"reset_prompt_memento":"A45307B4DC191F9473341EE5E1CB37FAFAA0B5799C6E09A9FA76E7C7A87429EF"},"safebrowsing":{"incidents_sent":"ACDB37352C4B9FCDE1F619223FCD2C049138DF9117A9F68DD821DE36208BC38D"},"search_provider_overrides":"6B5352A9F528A993A61065A4DB610A0F22D82A3BF0BE3BA5519CB5EEDEB9B107","session":{"restore_on_startup":"3DB75EC016DBD32D317D1A5A6EAA94EA4FF3FF3E901EF50DC1DCAF7359C5A17F","startup_urls":"698FA73D9AC683B0FE6B48C320E11176914BF272E8476271EFD0EE5E61328917"},"software_reporter":{"prompt_reason":"300A35946F8BB98DC0DE69B387D9F7F6A15BC9EC2123B4EBF324698964DA25D9","prompt_seed":"9A65E429A9823F9F7C9B589749A0ECD1AFA2D1F132422B200E60CDEA83F879BA","prompt_version":"16FA81A2D4191862263529960477C7D16C30114091E3DD87654F138D0FDDCD48"},"sync":{"remaining_rollback_tries":"6732BEC004842BFC8620B2873BEBAC794501C4CF4487FFDDC265D811374F3F63"}},"super_mac":"409309C50E3F5E3956F342A04FCA0C957FC33FE7E0B4C747BEB45449B7E18B73"},"session":{"restore_on_startup":4,"startup_urls":["http://www.google.rs/"]}}
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/?pc=UP97&ocid=UP97DHP"
"Secondary Start Pages"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/?pc=UP97&ocid=UP97DHP"
"Secondary Start Pages"="http://www.msn.com/?pc=UP97&ocid=UP97DHP"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D2A425F405350054677A7A857BC0C110 deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4F524A2D-5350-4500-76A7-A758B70C1C01} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update deleted successfully
==== Empty IE Cache ======================
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\35OT0DY0 will be deleted at reboot
C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\TOIVZY09 will be deleted at reboot
C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\YW7C3PDU will be deleted at reboot
C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\35OT0DY0 will be deleted at reboot
C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\TOIVZY09 will be deleted at reboot
C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\YW7C3PDU will be deleted at reboot
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Documents and Settings\Mr.X\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Documents and Settings\Mr.X\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=9 folders=9 528498 bytes)
==== Empty Temp Folders ======================
C:\Documents and Settings\Default User\Local Settings\Temp emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp emptied successfully
C:\Documents and Settings\Mr.X\Local Settings\Temp will be emptied at reboot
C:\Documents and Settings\NetworkService\Local Settings\Temp emptied successfully
C:\Documents and Settings\UpdatusUser\Local Settings\Temp emptied successfully
C:\Documents and Settings\Mr.X\Local Settings\Temp will be emptied at reboot
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\Mr.X\LOCALS~1\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\RECYCLER successfully emptied
==== Deleting Files / Folders ======================
"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\35OT0DY0" not found
"C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\TOIVZY09" not found
"C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\YW7C3PDU" not found
"C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\35OT0DY0" not found
"C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\TOIVZY09" not found
"C:\Documents and Settings\Mr.X\Local Settings\Temporary Internet Files\Content.IE5\YW7C3PDU" not found
==== EOF on sub 23.05.2015 at 21:18:28,25 ======================
|