offline
- Ivana23
- Novi MyCity građanin
- Pridružio: 04 Sep 2013
- Poruke: 11
|
Zoek.exe Version 4.0.0.4 Updated 31-08-2013
Tool run by Ivana on źet 05.09.2013 at 23:26:56,42.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Ivana\Desktop\New folder\zoek.exe [Quick Scan] [Auto Clean]
==== System Restore Info ======================
5.9.2013 23:28:18 Zoek.exe System Restore Point Created Succesfully.
==== Creating Sample_05.09.2013_2334.zip ======================
Process chrome.exe killed
Copied file C:\Users\Ivana\AppData\Roaming\pack.exe to sample\pack.exe
sample\pack.exe renamed to D3FAF9434A552E3D3D0801B035DD628E
C:\Users\Public\Desktop\sample_05.09.2013_2334.zip created successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1338069029-2438712655-2750520253-1000\Software\Microsoft\Internet Explorer\SearchScopes\{04D1923B-2AB4-659C-49B8-65A007909125} deleted successfully
HKEY_USERS\S-1-5-21-1338069029-2438712655-2750520253-1000\Software\Microsoft\Internet Explorer\SearchScopes\{42D52C74-1A87-49AD-BBF7-2A1FA7EA3CE5} deleted successfully
HKEY_USERS\S-1-5-21-1338069029-2438712655-2750520253-1000\Software\Microsoft\Internet Explorer\SearchScopes\{4D68C31B-010C-378F-EEF8-705543A92BBB} deleted successfully
HKEY_USERS\S-1-5-21-1338069029-2438712655-2750520253-1000\Software\Microsoft\Internet Explorer\SearchScopes\{4E5F75B2-156C-4368-A4C5-8F2A2114347C} deleted successfully
HKEY_USERS\S-1-5-21-1338069029-2438712655-2750520253-1000\Software\Microsoft\Internet Explorer\SearchScopes\{D4F4118C-00A8-4BA9-9694-2F66BC7E492E} deleted successfully
HKEY_USERS\S-1-5-21-1338069029-2438712655-2750520253-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default
user.js not found
---- Lines yahoo removed from prefs.js ----
user_pref("browser.search.defaulturl", "http://search.yahoo.com/search?fr=mkg030&p=");
user_pref("yahoo.ytff.general.dontshowhpoffer", true);
---- Lines yahoo modified from prefs.js ----
---- Lines ask.com removed from prefs.js ----
user_pref("browser.search.defaultengine", "Ask.com");
user_pref("browser.search.defaultenginename", "Ask.com");
user_pref("browser.search.order.1", "Ask.com");
---- Lines ask.com modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1370469744461,\"rdfTime\":1368303951000}}},{\"name\":\"app-profile\",\"addons\":{\"anthonyytmp3download@gmail.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\anthonyytmp3download@gmail.com.xpi\",\"mtime\":1368645602367},\"en-US@dictionaries.addons.mozilla.org\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\en-US@dictionaries.addons.mozilla.org\",\"mtime\":1368646041129,\"rdfTime\":1368646041046},\"ffxtlbr@searchya.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\ffxtlbr@searchya.com\",\"mtime\":1372669427454,\"rdfTime\":1340019688295},\"mwaquickbutton@elmstreet.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\mwaquickbutton@elmstreet.com.xpi\",\"mtime\":1368645423995},\"toolbar@ask.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\toolbar@ask.com\",\"mtime\":1372669427813,\"rdfTime\":1368744339260},\"youtube-cinemode@gmail.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\youtube-cinemode@gmail.com.xpi\",\"mtime\":1368645370385},\"{5ebdca98-43b3-45bb-87e0-716029fb42ab}\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\{5ebdca98-43b3-45bb-87e0-716029fb42ab}\",\"mtime\":1372669428141,\"rdfTime\":1356348356000},\"{635abd67-4fe9-1b23-4f01-e679fa7484c1}\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\",\"mtime\":1372669428312,\"rdfTime\":1366295311000},\"{65030561-c150-4370-836c-7c9d04f7a1b4}\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\{65030561-c150-4370-836c-7c9d04f7a1b4}\",\"mtime\":1372669428359,\"rdfTime\":1367224852000},\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1335817027037,\"rdfTime\":1126801560000}}}]");
---- Lines searchya removed from prefs.js ----
---- Lines searchya modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"app-global\",\"addons\":{\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\browser\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1370469744461,\"rdfTime\":1368303951000}}},{\"name\":\"app-profile\",\"addons\":{\"anthonyytmp3download@gmail.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\anthonyytmp3download@gmail.com.xpi\",\"mtime\":1368645602367},\"en-US@dictionaries.addons.mozilla.org\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\en-US@dictionaries.addons.mozilla.org\",\"mtime\":1368646041129,\"rdfTime\":1368646041046},\"ffxtlbr@searchya.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\ffxtlbr@searchya.com\",\"mtime\":1372669427454,\"rdfTime\":1340019688295},\"mwaquickbutton@elmstreet.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\mwaquickbutton@elmstreet.com.xpi\",\"mtime\":1368645423995},\"toolbar@disabled\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\toolbar@disabled\",\"mtime\":1372669427813,\"rdfTime\":1368744339260},\"youtube-cinemode@gmail.com\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\youtube-cinemode@gmail.com.xpi\",\"mtime\":1368645370385},\"{5ebdca98-43b3-45bb-87e0-716029fb42ab}\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\{5ebdca98-43b3-45bb-87e0-716029fb42ab}\",\"mtime\":1372669428141,\"rdfTime\":1356348356000},\"{635abd67-4fe9-1b23-4f01-e679fa7484c1}\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\",\"mtime\":1372669428312,\"rdfTime\":1366295311000},\"{65030561-c150-4370-836c-7c9d04f7a1b4}\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\{65030561-c150-4370-836c-7c9d04f7a1b4}\",\"mtime\":1372669428359,\"rdfTime\":1367224852000},\"{972ce4c6-7e08-4474-a285-3208198ce6fd}\":{\"descriptor\":\"C:\\\\Users\\\\Ivana\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\34ss2gru.default\\\\extensions\\\\{972ce4c6-7e08-4474-a285-3208198ce6fd}\",\"mtime\":1335817027037,\"rdfTime\":1126801560000}}}]");
---- Lines ilivid removed from prefs.js ----
---- Lines ilivid modified from prefs.js ----
---- FireFox user.js and prefs.js backups ----
prefs_05.09.2013_2335_.backup
==== Deleting Files \ Folders ======================
"C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default\searchplugins\SearchYa.xml" not found
"C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default\searchplugins\SearchYa.xml" not found
"C:\ProgramData\193d5ee11dd0ecced3e4ece876327647_c" deleted
"C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default\yahooToolbarSettings" deleted
"C:\Users\Ivana\AppData\Local\speeddial.crx" deleted
"C:\Windows\system32\Tasks\GoforFilesUpdate" deleted
"C:\Users\Ivana\AppData\Roaming\pack.exe" deleted
"C:\Program Files\GoforFiles" deleted
"C:\Users\Ivana\AppData\Roaming\GoforFiles" deleted
"C:\Users\Ivana\AppData\Roaming\SpeedyPC Software" deleted
"C:\Users\Ivana\AppData\Roaming\OpenCandy" deleted
"C:\ProgramData\SpeedyPC Software" deleted
"C:\Users\Ivana\AppData\Local\APN" deleted
"C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default\ilividtoolbargaw" deleted
"C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default\ilividtoolbargaw" deleted
"C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default\ilividtoolbargaw" deleted
==== Files Recently Created / Modified ======================
====== C:\Windows ====
====== C:\Users\Ivana\AppData\Local\Temp ====
====== C:\Windows\system32 =====
2013-09-05 20:57:51 7F4B65E5482BE5B4421D90C36E5D59C6 29536 ----a-w- C:\Windows\System32\uxtuneup.dll
2013-09-05 19:05:16 FC8A8BD8D9B0717B473B8FCD04EDE58A 31584 ----a-w- C:\Windows\System32\TURegOpt.exe
2013-09-05 19:05:16 13970A0219211E14A0C5DF858A364FDC 21344 ----a-w- C:\Windows\System32\authuitu.dll
====== C:\Windows\system32\drivers =====
2013-08-14 11:56:55 4E8B9BE71B807B3BAEDB7F4243F85E3C 1293760 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-08-14 11:54:33 B37B08F2E5EEB1A37E448E09BACE1101 31232 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2013-09-05 19:04:35 -------- d-----w- C:\Program Files\TuneUp Utilities 2013
2013-09-05 19:03:22 -------- d-----w- C:\Program Files\VideoLAN
======= C: =====
2013-09-05 20:09:14 0D82E328857421BEC7410E9252A9A343 3280 ------w- C:\bootsqm.dat
2013-09-05 12:51:29 5D1EDDE6A0D29AE347CB667D820BD165 103680 ----a-w- C:\uglorpog.sys
====== C:\Users\Ivana\AppData\Roaming ======
2013-09-05 19:04:42 -------- d-----w- C:\users\Ivana\AppData\Roaming\TuneUp Software
2013-09-05 19:03:52 -------- d-----w- C:\users\Ivana\AppData\Roaming\vlc
2013-09-05 19:03:52 -------- d-----w- C:\users\Ivana\AppData\Roaming\Ignite
2013-09-05 19:02:13 -------- d-----w- C:\users\Ivana\AppData\Local\Ignite
2013-08-30 20:58:10 407AAB8C27CF7081EECE071C90A65B83 17 ----a-w- C:\users\Ivana\AppData\Local\resmon.resmoncfg
====== C:\Users\Ivana ======
2013-09-05 21:08:44 323B4AD6F1374F3621ABF748307E3287 1037222 ----a-w- C:\Users\Ivana\Downloads\adwcleaner (2).exe
2013-09-05 19:24:06 -------- d-sh--w- C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-09-05 19:05:12 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
2013-09-05 19:04:32 -------- d-----w- C:\ProgramData\TuneUp Software
2013-09-05 19:04:25 -------- d-sh--w- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-09-05 19:03:46 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2013-09-05 19:02:16 2E43371C02C0D900BDD63D916500D5EB 22259528 ----a-w- C:\Users\Ivana\Downloads\vlc-2.0.1-win32.exe
2013-09-05 19:01:52 F0F2F429747400052855181202B4461F 1177968 ----a-w- C:\Users\Ivana\Downloads\littlealchemy_vlc_201Setup.exe
2013-09-05 12:54:16 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Users\Ivana\Desktop\x12qx15s.exe
2013-09-05 12:53:50 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Users\Ivana\Downloads\kcsv3ez4.exe
2013-09-05 12:51:15 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Users\Ivana\Downloads\w8u985vk.exe
2013-09-05 12:50:41 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Users\Ivana\Downloads\51rldul5.exe
2013-09-05 12:26:12 323B4AD6F1374F3621ABF748307E3287 1037222 ----a-w- C:\Users\Ivana\Downloads\adwcleaner (1).exe
2013-09-04 23:43:40 323B4AD6F1374F3621ABF748307E3287 1037222 ----a-w- C:\Users\Ivana\Downloads\adwcleaner.exe
2013-09-04 22:21:03 8B968045D75783A09592C3105F2865DA 688992 ----a-w- C:\Users\Ivana\Downloads\dds.com
2013-09-04 22:09:27 0A8655152C01512CB7DD9B8C35F229A1 4327208 ----a-w- C:\Users\Ivana\Downloads\rcpsetupst_RC1_ZZ_F_1.exe
====== C: exe-files ==
2013-09-05 21:08:44 323B4AD6F1374F3621ABF748307E3287 1037222 ----a-w- C:\Users\Ivana\Downloads\adwcleaner (2).exe
2013-09-05 19:25:19 C4D9C534D96E4D5EB8DADDCD4C0FCB43 32773544 ----a-w- C:\Users\Ivana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2KMX1YH0\TuneUpUtilities2014_en-US[1].exe
2013-09-05 19:23:24 C4D9C534D96E4D5EB8DADDCD4C0FCB43 32773544 ----a-w- C:\Users\Ivana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2KMX1YH0\TuneUpUtilities2014_en-US (1).exe
2013-09-05 19:23:16 C4D9C534D96E4D5EB8DADDCD4C0FCB43 32773544 ----a-w- C:\Users\Ivana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2KMX1YH0\TuneUpUtilities2014_en-US.exe
2013-09-05 19:05:16 FC8A8BD8D9B0717B473B8FCD04EDE58A 31584 ----a-w- C:\Windows\System32\TURegOpt.exe
2013-09-05 19:03:49 7408D0E383238743D059FE6C9B81ED46 212369 ----a-w- C:\Program Files\VideoLAN\VLC\uninstall.exe
2013-09-05 19:02:16 2E43371C02C0D900BDD63D916500D5EB 22259528 ----a-w- C:\Users\Ivana\Downloads\vlc-2.0.1-win32.exe
2013-09-05 19:02:13 C0B0A35C487F3F7FC58EA6804DB47D2B 888688 ----a-w- C:\Users\Ivana\AppData\Local\Ignite\Ignite.exe
2013-09-05 19:02:13 5CD73B950A1D76258EF1C73D72DA78CB 145264 ----a-w- C:\Users\Ivana\AppData\Local\Ignite\OfferFinisher.exe
2013-09-05 19:01:52 F0F2F429747400052855181202B4461F 1177968 ----a-w- C:\Users\Ivana\Downloads\littlealchemy_vlc_201Setup.exe
2013-09-05 18:08:39 3DEF79A0391970E29EC34FF3000B5994 70200 ----a-w- C:\Program Files\Avira\AntiVir Desktop\checkt.exe
2013-09-05 18:07:35 834A360FEE94DB61BF69D90B56F59139 599608 ----a-w- C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\update.exe
2013-09-05 18:07:35 4D54B271BF0A2D8C07DFE5BDA67BF89B 44600 ----a-w- C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\updrgui.exe
2013-09-05 12:54:16 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Users\Ivana\Desktop\x12qx15s.exe
2013-09-05 12:53:50 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Users\Ivana\Downloads\kcsv3ez4.exe
2013-09-05 12:51:15 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Users\Ivana\Downloads\w8u985vk.exe
2013-09-05 12:50:41 60BF4AE8CC40B0E3E28613657ED2EED8 377856 ----a-w- C:\Users\Ivana\Downloads\51rldul5.exe
2013-09-05 12:26:12 323B4AD6F1374F3621ABF748307E3287 1037222 ----a-w- C:\Users\Ivana\Downloads\adwcleaner (1).exe
2013-09-04 23:43:40 323B4AD6F1374F3621ABF748307E3287 1037222 ----a-w- C:\Users\Ivana\Downloads\adwcleaner.exe
2013-09-04 22:09:27 0A8655152C01512CB7DD9B8C35F229A1 4327208 ----a-w- C:\Users\Ivana\Downloads\rcpsetupst_RC1_ZZ_F_1.exe
2013-08-30 19:54:32 F36154F2BEB4B535E6F0752C82625D01 7912288 ----a-w- C:\Program Files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\29.0.1547.62\29.0.1547.62_28.0.1500.95_chrome_updater.exe
=== C: other files ==
2013-09-05 21:34:27 DDC2C20A64975B08E2DC5B732D74F45B 788381 ----a-w- C:\Users\Public\Desktop\sample_05.09.2013_2334.zip
2013-09-05 12:51:29 5D1EDDE6A0D29AE347CB667D820BD165 103680 ----a-w- C:\uglorpog.sys
2013-09-05 12:42:07 979F05F6CED2D65749746AA29FE0C07A 25762 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\linkcollector50.zip
2013-09-05 12:42:06 26E3D5540C6BC2EEF5A7F6787305C6D3 233 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\downloadList215.zip
2013-09-04 22:21:03 8B968045D75783A09592C3105F2865DA 688992 ----a-w- C:\Users\Ivana\Downloads\dds.com
2013-09-04 20:41:46 C24517FB8742FAF47C7A37150FD271E7 233 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\downloadList214.zip
2013-09-04 20:41:46 1288DD36783F3F225011CF977DBC5D0F 26531 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\linkcollector49.zip
2013-09-04 17:00:57 BD3F708C22233E67F58C5FB16440E9F2 233 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\downloadList213.zip
2013-09-04 16:54:49 7C2F6D3497CCC516E63883EAF327CB0F 5064 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\downloadList212.zip
2013-09-04 16:54:36 1AF23494B78AD6E79A4FC6F7964ED3DA 4979 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\downloadList211.zip
2013-09-04 16:54:28 5241F024EEED38DCCA55A97FD7072BF1 4979 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\downloadList210.zip
2013-09-04 16:47:16 40CB786E7CEC40C4213BD729D17B5840 26531 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\linkcollector48.zip
2013-09-04 16:46:38 331BC837DC80F75D61A794610102CC9B 30933 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\linkcollector47.zip
2013-09-04 16:45:58 5529A4AE27F788EE7CC9CF0E37AC198A 233 ----a-w- C:\Users\Ivana\AppData\Local\JDownloader v2.0\cfg\linkcollector46.zip
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-21-1338069029-2438712655-2750520253-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo\PROGRA~1\Yahoo\Messenger\YahooMessenger.exe -quiet"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"
"GoogleChromeAutoLaunch_A0974F4F7ABDBFE34896561F2822A68F"="C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"NeroFilterCheck"="C:\Windows\system32\NeroCheck.exe"
"avgnt"="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe /min"
"Thinstuff TSX Connect Admin"="C:\Program Files\Thinstuff\Remote Desktop Host\TSXConnectAdmin.exe /hide"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo\PROGRA~1\Yahoo\Messenger\YahooMessenger.exe -quiet"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"
"GoogleChromeAutoLaunch_A0974F4F7ABDBFE34896561F2822A68F"="C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window"
==== Startup Registry Disabled ======================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\""
==== Startup Folders ======================
2012-04-09 21:02:59 1280 ----a-w- C:\users\Ivana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [15.05.2013 22:21]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [30.04.2012 22:57]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [30.04.2012 22:57]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default
- Undetermined - %ProfilePath%\extensions\installed-extensions.txt
- United States English Spellchecker - %ProfilePath%\extensions\en-US@dictionaries.addons.mozilla.org
- Power Zoom - %ProfilePath%\extensions\{65030561-c150-4370-836c-7c9d04f7a1b4}
- Firefox default - %ProfilePath%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- YouTube MP3 Download - %ProfilePath%\extensions\anthonyytmp3download@gmail.com.xpi
- Music World Anonymous Quick Button - %ProfilePath%\extensions\mwaquickbutton@elmstreet.com.xpi
- YouTube Cinema Mode . - %ProfilePath%\extensions\youtube-cinemode@gmail.com.xpi
AppDir: C:\Program Files\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
==== Firefox Plugins ======================
Profilepath: C:\Users\Ivana\AppData\Roaming\Mozilla\Firefox\Profiles\34ss2gru.default
101700E93EB905992B518256CB441829 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll - Google Update
ADC539F67D3198679F480974EE203678 - C:\Windows\system32\npdeployJava1.dll - Java Deployment Toolkit 7.0.210.11
C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery
B16EC84E06F26B8B85800F3B07B8D757 - C:\Windows\system32\Macromed\Flash\NPSWF32.dll - Shockwave Flash
6DE7BF0DADC0881F7ED82D9FCC998B89 - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll - Adobe Acrobat
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\system32\npmproxy.dll - Microsoft® Windows® Operating System
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
aaaaabfjnbeinlpljodiajipidiompfl - C:\Users\Ivana\AppData\Local\APN\GoogleCRXs\aaaaabfjnbeinlpljodiajipidiompfl_7.15.24.0.crx[]
ablnpmdakdiclnimkjfcaibpgjhapkbl - C:\Users\Ivana\AppData\Local\CRE\ablnpmdakdiclnimkjfcaibpgjhapkbl.crx[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[22.11.2012 10:30]
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
ablnpmdakdiclnimkjfcaibpgjhapkbl - C:\Users\Ivana\AppData\Local\CRE\ablnpmdakdiclnimkjfcaibpgjhapkbl.crx[]
Power Zoom - Ivana - default\Extensions\jlioidldolgbmanndggdnldambdlglgj
Google Drive - Ivana - Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Ivana - Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Ivana - Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Gmail - Ivana - Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Office - Ivana - Profile 6\Extensions\ahfpbkogcgkoecgolaojpcijkabngljl
ENGLISH MEMORY - Ivana - Profile 6\Extensions\aidhibeakadjobeknimdalmhfekikmaa
Google Docs - Ivana - Profile 6\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Ivana - Profile 6\Extensions\apdfllckaahabafndbhieahigkjlhalf
Virtual Yeast Cell - Ivana - Profile 6\Extensions\bggcfkeamlabnkdllkkaeaeojiiphjhm
HeapNote Teacher - Ivana - Profile 6\Extensions\bllhchpefpppioobbgcpjffahfogcaid
YouTube - Ivana - Profile 6\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Useful Periodic Table - Ivana - Profile 6\Extensions\chachkegffmilnmdlonllkhkfkakghie
Google Search - Ivana - Profile 6\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Chemical Elements - Ivana - Profile 6\Extensions\eilhonghnelklfkaekhjibgnbfelgbho
WinWeb Online Office - Ivana - Profile 6\Extensions\fplkmnmmhodmddabbcipjijjmgokildf
Easy Essays - Ivana - Profile 6\Extensions\ippabcfpniimkomfeidkcfffmjahcgln
Zoho Writer - Ivana - Profile 6\Extensions\jgaeidloagadfcohacebhbkkapgpiddj
Little Alchemy - Ivana - Profile 6\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd
Skype for Chromium - Ivana - Profile 6\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Advanced Periodic Table - Ivana - Profile 6\Extensions\lnapfbmgfeemaakflaojcefffeobddog
Card number - Ivana - Profile 6\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Ivana - Profile 6\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
PR Checker - Ivana - Profile 6\Extensions\pneoplpmnpjoioldpodoljacigkahohc
==== Chrome Fix ======================
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_app.mam.conduit.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_app.mam.conduit.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_apps.conduit.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_apps.conduit.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_facebook.conduitapps.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_facebook.conduitapps.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_offering.hosting.distributionengine.conduit-services.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_offering.hosting.distributionengine.conduit-services.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_pricegong.conduitapps.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_search.conduit.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_search.conduit.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_ticker.conduit.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_ticker.conduit.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Local Storage\http_en.softonic.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Local Storage\http_en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Local Storage\http_jdownloader-portable.en.softonic.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Local Storage\http_jdownloader-portable.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Local Storage\http_jdownloader.en.softonic.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Local Storage\http_jdownloader.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_www2.delta-search.com_0.localstorage deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\http_www2.delta-search.com_0.localstorage-journal deleted successfully
C:\Users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\aaaaabfjnbeinlpljodiajipidiompfl deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{DECA3892-BA8F-44b8-A993-A466AD694AE4}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}] not found
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{C43829F1-5599-4CA3-8D30-6A3B84787362} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz="
==== Deleting CLSID Registry Keys ======================
HKEY_CLASSES_ROOT\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-1338069029-2438712655-2750520253-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} deleted successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\aaaaabfjnbeinlpljodiajipidiompfl deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ablnpmdakdiclnimkjfcaibpgjhapkbl deleted successfully
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\ablnpmdakdiclnimkjfcaibpgjhapkbl deleted successfully
==== Empty IE Cache ======================
C:\Users\Ivana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Ivana\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Ivana\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\users\Ivana\AppData\Local\Mozilla\Firefox\Profiles\34ss2gru.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
C:\users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Cache emptied successfully
C:\users\Ivana\AppData\Local\Google\Chrome\User Data\Profile 6\Application Cache\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Ivana\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on źet 05.09.2013 at 23:44:47,32 ======================
|