Wtf naked video tag

1

Wtf naked video tag

offline
  • Pridružio: 22 Mar 2014
  • Poruke: 9

Pre svega želeo bih da pozdravim ekipu koja pomaže u rešavanju ove problematike. Moj problem počinje od glupog klika na prijateljev post WTF naked video (face timeline) i od tad ga se nikako nemogu otarasiti, gde pritom moj nalog koristi tagujući, spam-ujući sve moje prijatelje. Tražeći rešenja na netu, došao sam i do sličnog slučaja koji ste vi imali, a s obzirom da face koristim i na poslu i da postoji velika verovatnoća da sam zarazio kompjuter na poslu, pa realno ne mogu zamisliti gluplji razlog otkaza.
Unapred zahvalan, srdačan pozdrav!

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Pozdrav sirzizo, dobrodosao u Ambulantu MyCity foruma. Mi u ovom delu foruma zahtevamo skup izvestaja koji ce nam reci sta se sve pokrece sa tvojim sistemom. Ako je infekcija prisutna, ovi alati ce nam to i pokazati.





Arrow
Preuzmi Farbar-ov Farbar Recovery Scan Tool () sa ove adrese na Desktop:
Postoji 32bit. i 64bit.-na verzija. Potrebno je preuzeti verziju koja je kompatibilna sa tvojim sistemom.
Ako nisi siguran koja verzija se odnosi na tvoj sistem, preuzmi ih obe i pokreni. Samo jedan od njih će raditi na tvom sistemu, to će biti prava verzija.


dvoklikom pokreni program, kada se alat pokrene klikni Yes na disclaimer prozor;
pričekati koji trenutak dok alat proverava postoji li novija verzija;
klikni na dugme Scan;
po završetku skeniranja, alat će formirati izveštaj (FRST.txt) u isti direktorijum gde je FRST alat sačuvan;
iskopiraj sadržaj FRST.txt izveštaja u poruku;
po prvom pokretanju, alat bi trebao formirati i dodatni izveštaj (Addition.txt);
okači Addition.txt izveštaj uz poruku koristeći opciju Prikači fajl






Arrow
Preuzmi program GMER, RootKit Detektor i sačuvati ga na Desktop:
Napomena: alat nosi nasumice generisan naziv. Na samoj ikonici će jasno pisati GMER.


Dvoklikom pokreni GMER.
Sačekaj da se završi uvodno skeniranje - ukoliko se pojavi bilo kakav upit, klikni No;
klikni dugme [Scan] i sačekaj da skeniranje bude završeno;
klikni dugme [Save ...] - izveštaj sačuvaj na Desktop pod nazivom ARK;

kliknite taster >>> i odaberite Autostart karticu;
klikni dugme [Scan];
po završetku kratkotrajnog skeniranja, klikni [Copy];
otvori Notepad i u njega postavi kopirani tekst - izveštaj sačuvaj na Desktop pod nazivom autostart;



Priloži oba GMER izveštaja uz poruku korišćenjem opcije Prikači fajl.

offline
  • Pridružio: 22 Mar 2014
  • Poruke: 9

mycity.rs/must-login.png




[edit by magna86: uklonjen iskopirani Addition.txt log iz poruke, isti je prikacen uz poruku]

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

sirzizo, oba loga koja si postavio (iskopiran i okacen uz poruku) su zapravo isti, tacnije Addition.txt izvestaj, dodatni logfile koji je formirao FRST. Potrebno je da mi iskopiras u poruku primarni FRST.txt izvestaj. Wink

I naravno, oba GMER loga okaci uz poruku, bas kao sto se navodi u instrukcijama.

offline
  • Pridružio: 22 Mar 2014
  • Poruke: 9

Napisano: 22 Mar 2014 18:21

mycity.rs/must-login.png

mycity.rs/must-login.png

trebam li i dds?
Pozdrav

Dopuna: 22 Mar 2014 18:23

mycity.rs/must-login.png
sorry!








Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by korisnik (administrator) on KORISNIK-PC on 22-03-2014 17:29:32
Running from C:\Users\korisnik\Downloads
Microsoft Windows 7 Home Basic Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
(HP) C:\Windows\system32\HPSIsvc.exe
(Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\Windows\system32\IoctlSvc.exe
(VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\scalc.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HDAudDeck] - C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [1681408 2009-09-21] (VIA)
HKLM\...\Run: [HPUsageTrackingLEDM] - C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe [30264 2009-08-04] (Hewlett-Packard Company)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-1829802654-943873472-2443089448-1000\...\CurrentVersion\Windows: [Load] C:\Users\korisnik\LOCALS~1\Temp\msqwuo.cmd <===== ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.babylon.com/?affID=119294&babsrc.....2522E50316
HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = search.certified-toolbar.com?si=41460&home=true&tid=2937
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = search.babylon.com/?affID=119294&babsrc.....2522E50316
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = search.certified-toolbar.com?si=41460&home=true&tid=2937
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
URLSearchHook: HKCU - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
URLSearchHook: HKCU - (No Name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = dts.search-results.com/sr?src=ieb&gct=d.....483&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = search.babylon.com/?q={searchTerms}&affID=119294&babsrc=SP_ss_din2g&mntrId=189B002522E50316
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = search.babylon.com/?q={searchTerms}&affID=119294&babsrc=SP_ss_din2g&mntrId=189B002522E50316
SearchScopes: HKCU - {49944F31-7D64-4BF3-949A-176783B44FDE} URL = websearch.ask.com/redirect?client=ie&tb.....crm&q={searchTerms}&locale=&apn_ptnrs=^AGY&apn_dtid=^YYYYYY^YY^RS&apn_uid=8f7030f9-f4df-418e-b9bc-0f3c114f7221&apn_sauid=B0271BC3-FD5F-4EB0-82AB-1E52AC5BF48D
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = dts.search-results.com/sr?src=ieb&gct=d.....483&q={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = dts.search-results.com/sr?src=ieb&appid.....r=0&q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: DataMngr - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC)
BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
BHO: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: DownTango Launcher - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll (Simplytech Ltd.)
Toolbar: HKLM - Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
Toolbar: HKLM - DownTango Launcher - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll (Simplytech Ltd.)
Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
Toolbar: HKCU - No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} pcmcacak.zapto.org/cab/OCXChecker_8120.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage:
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Perion plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.485_0\npbrowserext.dll No File
CHR Plugin: (TorchPlugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof\1.0.0.2023_0\plugin/torchplugin.dll No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\korisnik\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_135.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.70.10) - C:\Windows\system32\npDeployJava1.dll No File
CHR Extension: (Google Drive) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-01-08]
CHR Extension: (YouTube) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-08]
CHR Extension: (Google Search) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-08]
CHR Extension: (Night Time In New York City) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnimonidkipnhnpgkhgliocfnnpgkhek [2013-01-08]
CHR Extension: (Google Wallet) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Gmail) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-08]
CHR HKLM\...\Chrome\Extension: [biffcfkpbbhalilhcjiajcpffjmfhmgp] - C:\ProgramData\Bcool\biffcfkpbbhalilhcjiajcpffjmfhmgp.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-11-19]
CHR HKLM\...\Chrome\Extension: [gladcbhcbkdeddbidiblppadjdjalidb] - C:\Program Files\DownTangoFTToolbar\chrome\DownTangoFTToolbar.crx [2012-11-19]
CHR HKLM\...\Chrome\Extension: [jifflliplgeajjdhmkcfnngfpgbjonjg] - C:\Program Files\Perion\NewTab\newTab.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\korisnik\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-01-08]
CHR HKCU\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-11-19]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2013-01-08]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

========================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP)
S4 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2012-09-03] ()
S4 WebOptimizer; C:\Windows\system32\dmwu.exe [1006448 2012-09-13] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-19] (Avira GmbH)
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1086976 2009-09-17] (VIA Technologies, Inc.)
S3 AsrCDDrv; \??\C:\Windows\system32\Drivers\AsrCDDrv.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-22 17:22 - 2014-03-22 17:29 - 00015409 _____ () C:\Users\korisnik\Downloads\FRST.txt
2014-03-22 17:22 - 2014-03-22 17:29 - 00000000 ____D () C:\FRST
2014-03-22 17:21 - 2014-03-22 17:21 - 01145856 _____ (Farbar) C:\Users\korisnik\Downloads\FRST.exe
2014-03-22 14:29 - 2014-03-22 14:29 - 00000110 ____H () C:\Users\korisnik\Desktop\.~lock.30% AVANSNO.xls#
2014-03-21 19:09 - 2014-03-21 19:09 - 00029184 _____ () C:\Users\korisnik\Downloads\35-14 Kosanović Ljiljana.xls
2014-03-20 14:58 - 2014-03-20 14:58 - 00008634 _____ () C:\Users\korisnik\AppData\Local\recently-used.xbel
2014-03-17 10:18 - 2014-03-17 10:18 - 00025600 _____ () C:\Users\korisnik\Downloads\Arilje_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1.xls
2014-03-13 09:44 - 2014-03-13 09:44 - 00032738 _____ () C:\Users\korisnik\Downloads\8 kljucnih prioriteta privrede - Dveri.xlsx
2014-03-13 09:13 - 2014-03-13 09:13 - 00000000 ____D () C:\Users\korisnik\AppData\Roaming\vlc
2014-03-12 09:19 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 09:19 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 09:19 - 2014-03-01 05:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 09:19 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 09:19 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 09:19 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 09:19 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 09:19 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 09:19 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 09:19 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 09:19 - 2014-03-01 04:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 09:19 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 09:19 - 2014-03-01 04:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 09:19 - 2014-03-01 04:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 09:19 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 09:19 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 09:19 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 09:19 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 09:19 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 09:19 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 09:19 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 09:19 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 09:19 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 09:16 - 2014-02-07 02:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 09:16 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 09:16 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 09:16 - 2014-01-28 03:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-06 12:28 - 2014-03-06 12:28 - 00000000 ____D () C:\Program Files\VideoLAN
2014-03-06 12:25 - 2014-03-06 12:41 - 00000000 ____D () C:\Users\korisnik\AppData\Local\Mobogenie
2014-03-06 12:25 - 2014-03-06 12:25 - 00000000 ____D () C:\Users\korisnik\Documents\Mobogenie
2014-03-06 12:25 - 2014-03-06 12:25 - 00000000 ____D () C:\Users\korisnik\AppData\Local\cache
2014-03-06 12:25 - 2014-03-06 12:25 - 00000000 ____D () C:\Users\korisnik\.android
2014-03-06 12:25 - 2014-03-06 12:25 - 00000000 _____ () C:\Users\korisnik\daemonprocess.txt
2014-03-06 12:21 - 2014-03-06 12:21 - 00108064 _____ () C:\Users\korisnik\Downloads\setup (1).exe
2014-03-04 09:25 - 2014-03-04 09:25 - 00139338 _____ () C:\Users\korisnik\Downloads\Unconfirmed 284436.crdownload
2014-03-01 18:53 - 2014-03-01 18:53 - 00108064 _____ () C:\Users\korisnik\Downloads\setup.exe
2014-02-25 19:36 - 2014-02-25 19:36 - 00000000 ___RD () C:\Program Files\Skype
2014-02-25 19:36 - 2014-02-25 19:36 - 00000000 ____D () C:\Program Files\Common Files\Skype

==================== One Month Modified Files and Folders =======

2014-03-22 17:29 - 2014-03-22 17:22 - 00015409 _____ () C:\Users\korisnik\Downloads\FRST.txt
2014-03-22 17:29 - 2014-03-22 17:22 - 00000000 ____D () C:\FRST
2014-03-22 17:28 - 2009-07-14 05:39 - 01087017 _____ () C:\Windows\setupact.log
2014-03-22 17:21 - 2014-03-22 17:21 - 01145856 _____ (Farbar) C:\Users\korisnik\Downloads\FRST.exe
2014-03-22 16:32 - 2012-07-07 11:37 - 01770142 _____ () C:\Windows\WindowsUpdate.log
2014-03-22 14:29 - 2014-03-22 14:29 - 00000110 ____H () C:\Users\korisnik\Desktop\.~lock.30% AVANSNO.xls#
2014-03-22 14:14 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing
2014-03-22 10:43 - 2009-07-14 05:34 - 00021648 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-22 10:43 - 2009-07-14 05:34 - 00021648 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-22 10:40 - 2010-11-20 22:01 - 00778834 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-21 19:09 - 2014-03-21 19:09 - 00029184 _____ () C:\Users\korisnik\Downloads\35-14 Kosanović Ljiljana.xls
2014-03-21 11:32 - 2012-07-28 08:42 - 00000000 ____D () C:\Users\korisnik\Desktop\Ankica
2014-03-20 14:58 - 2014-03-20 14:58 - 00008634 _____ () C:\Users\korisnik\AppData\Local\recently-used.xbel
2014-03-20 14:58 - 2014-02-03 10:37 - 00000000 ____D () C:\Users\korisnik\AppData\Local\gtk-2.0
2014-03-20 14:58 - 2014-02-03 10:33 - 00000000 ____D () C:\Users\korisnik\.gimp-2.8
2014-03-20 14:15 - 2013-11-07 16:08 - 00000000 ____D () C:\Users\korisnik\Desktop\Nagradna igra sajam
2014-03-19 13:27 - 2013-04-10 13:37 - 00000000 ____D () C:\Users\korisnik\Desktop\SREDITI
2014-03-19 13:26 - 2013-07-03 15:07 - 00000000 ____D () C:\Users\korisnik\Desktop\srediti proizvodnja
2014-03-17 10:18 - 2014-03-17 10:18 - 00025600 _____ () C:\Users\korisnik\Downloads\Arilje_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1_1.xls
2014-03-13 09:44 - 2014-03-13 09:44 - 00032738 _____ () C:\Users\korisnik\Downloads\8 kljucnih prioriteta privrede - Dveri.xlsx
2014-03-13 09:13 - 2014-03-13 09:13 - 00000000 ____D () C:\Users\korisnik\AppData\Roaming\vlc
2014-03-13 09:10 - 2009-07-14 05:33 - 03821312 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-10 13:54 - 2012-11-26 14:59 - 00000000 ____D () C:\Users\korisnik\Desktop\CENOVNIK NOVO
2014-03-10 12:48 - 2014-01-15 17:57 - 00026711 _____ () C:\Users\korisnik\Desktop\upiti.odt
2014-03-07 15:40 - 2013-11-08 19:11 - 00000000 ____D () C:\Users\korisnik\Desktop\Posrednički ugovor
2014-03-06 15:36 - 2012-09-08 11:26 - 00013205 _____ () C:\Users\korisnik\Desktop\Dnevni izveštaj.ods
2014-03-06 12:41 - 2014-03-06 12:25 - 00000000 ____D () C:\Users\korisnik\AppData\Local\Mobogenie
2014-03-06 12:28 - 2014-03-06 12:28 - 00000000 ____D () C:\Program Files\VideoLAN
2014-03-06 12:25 - 2014-03-06 12:25 - 00000000 ____D () C:\Users\korisnik\Documents\Mobogenie
2014-03-06 12:25 - 2014-03-06 12:25 - 00000000 ____D () C:\Users\korisnik\AppData\Local\cache
2014-03-06 12:25 - 2014-03-06 12:25 - 00000000 ____D () C:\Users\korisnik\.android
2014-03-06 12:25 - 2014-03-06 12:25 - 00000000 _____ () C:\Users\korisnik\daemonprocess.txt
2014-03-06 12:25 - 2012-07-07 11:37 - 00000000 ____D () C:\Users\korisnik
2014-03-06 12:21 - 2014-03-06 12:21 - 00108064 _____ () C:\Users\korisnik\Downloads\setup (1).exe
2014-03-04 19:18 - 2014-02-13 10:37 - 00029184 _____ () C:\Users\korisnik\Desktop\100% AVANSNO.xls
2014-03-04 12:36 - 2013-08-02 17:49 - 00025515 _____ () C:\Users\korisnik\Desktop\šifre kase.ods
2014-03-04 09:25 - 2014-03-04 09:25 - 00139338 _____ () C:\Users\korisnik\Downloads\Unconfirmed 284436.crdownload
2014-03-01 18:53 - 2014-03-01 18:53 - 00108064 _____ () C:\Users\korisnik\Downloads\setup.exe
2014-03-01 05:30 - 2014-03-12 09:19 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 05:11 - 2014-03-12 09:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 05:10 - 2014-03-12 09:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 04:52 - 2014-03-12 09:19 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 04:51 - 2014-03-12 09:19 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 04:47 - 2014-03-12 09:19 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 04:43 - 2014-03-12 09:19 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 04:43 - 2014-03-12 09:19 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 04:40 - 2014-03-12 09:19 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 04:38 - 2014-03-12 09:19 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 04:38 - 2014-03-12 09:19 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 04:37 - 2014-03-12 09:19 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 04:31 - 2014-03-12 09:19 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 04:25 - 2014-03-12 09:19 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 04:16 - 2014-03-12 09:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 04:14 - 2014-03-12 09:19 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 04:03 - 2014-03-12 09:19 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 04:00 - 2014-03-12 09:19 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 03:57 - 2014-03-12 09:19 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 03:32 - 2014-03-12 09:19 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 03:27 - 2014-03-12 09:19 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 03:25 - 2014-03-12 09:19 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-28 17:33 - 2012-10-16 18:24 - 00000000 ____D () C:\Users\korisnik\Desktop\reklamacija
2014-02-25 19:36 - 2014-02-25 19:36 - 00000000 ___RD () C:\Program Files\Skype
2014-02-25 19:36 - 2014-02-25 19:36 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-25 19:36 - 2012-07-07 22:48 - 00002685 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-25 19:36 - 2012-07-07 22:48 - 00000000 ____D () C:\ProgramData\Skype
2014-02-24 15:37 - 2013-05-16 13:54 - 00000000 ____D () C:\Users\korisnik\Desktop\Bojan

Some content of TEMP:
====================
C:\Users\korisnik\AppData\Local\Temp\6_Offer_2.exe
C:\Users\korisnik\AppData\Local\Temp\AskSLib.dll
C:\Users\korisnik\AppData\Local\Temp\avgnt.exe
C:\Users\korisnik\AppData\Local\Temp\BearShare_setup.exe
C:\Users\korisnik\AppData\Local\Temp\crtBFC5.tmp.exe
C:\Users\korisnik\AppData\Local\Temp\DM1394104558.exe
C:\Users\korisnik\AppData\Local\Temp\GoogleToolbarInstaller_en32_signed.exe
C:\Users\korisnik\AppData\Local\Temp\htmlayout.dll
C:\Users\korisnik\AppData\Local\Temp\iMesh_setup.exe
C:\Users\korisnik\AppData\Local\Temp\Installhelper.dll
C:\Users\korisnik\AppData\Local\Temp\install_helper.exe
C:\Users\korisnik\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\korisnik\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\korisnik\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
C:\Users\korisnik\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
C:\Users\korisnik\AppData\Local\Temp\Mobogenie_INT.exe
C:\Users\korisnik\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\korisnik\AppData\Local\Temp\tbDVDV.dll
C:\Users\korisnik\AppData\Local\Temp\tbedrs.dll
C:\Users\korisnik\AppData\Local\Temp\tbuTor.dll
C:\Users\korisnik\AppData\Local\Temp\toolbar7630453.exe
C:\Users\korisnik\AppData\Local\Temp\toolbar7631312.exe
C:\Users\korisnik\AppData\Local\Temp\TorchSetupFull.exe
C:\Users\korisnik\AppData\Local\Temp\uninstall7689281.exe
C:\Users\korisnik\AppData\Local\Temp\uninstall7716734.exe
C:\Users\korisnik\AppData\Local\Temp\uninstall7716750.exe
C:\Users\korisnik\AppData\Local\Temp\uttD98C.tmp.exe
C:\Users\korisnik\AppData\Local\Temp\wmpfirefoxplugin.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-09-02 12:51

==================== End Of Log ============================

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Ne treba DDS, imamo FRST logove. Smile

Ti sada napravi pauzu, a ja ili neko od mojih kolega ce preuzeti slucaj uskoro i proslediti ti dalje instrukcije. Wink

offline
  • Pridružio: 22 Mar 2014
  • Poruke: 9

Napisano: 22 Mar 2014 18:34

Ok, moje ne znanje seže do toga da ne znam ni smile-i napisati u želji da iskažem postiđenost zbog pitanja koja proizilaze zbog istog, tako da hvala na razumevanju

Dopuna: 22 Mar 2014 18:54

I da iskoristim pauzu pitanjem, naravno kad budete imali vremena odgovorićete mi. Nadao sam se da tim mrežnim spy, mal, ili nem pojma kojim ware om nisam zarazio komp, a ukoliko jesam onda nisam jedan nego 3-4, još uvek nisam primetio neke promene u radu sistema, sem u jednom onom slučaju kada sam prvi put došao u vezu (bio tagovan) sa ovim wtf, nisam mogao da odem na youtube gde mi se uvek otvarao natpis (na engeskom) grupa dobro obučenih majmuna je krenula da se pozabavi ovim problemom ako ih vidite prenesite im ovu poruku, ispod te rečenice je išla cela tekstura slova,brojeva itd kao neki kod. Avira mi je nakon scaniranja otklonila taj problem (barem tako mislim).

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Hehe, opusteno, sve je to dobro. Wink


'Vako. Ciscenje se sastoji iz dva koraka.

* Prvi korak obuhvata intervenciju sa tvoje strane, tacnije deinstalacija nezeljenih/zlonamernih programa.
* Drugi korak obuhvata ciljanje i nasilno uklanjanje svih malicioznih unosa koristeci FixList script za FRST.





--- --- --- --- ---
Arrow Deinstalacija/Uklanjanje:
--- ---


Potrebno je da pristupis Programs and Features alatu koji se nalazi u Control Panel-u
( Start > Control Panel > Programs and Feauter)

Tu ces videti sta je sve od programa instalirano na sistemu. Potrebno je da pokusas da uklonis sledece programe:

BitGuard
BrowseToSave 1.66
Delta Chrome Toolbar
Delta toolbar
OptimizerPro Updater
Torch
Web Assistant
Wincore MediaBar


Ukoliko neki program ne mozes da pronadjes, ili iz nekog razloga odbija deinstalaciju, preskoci ga i predji na sledeci program sa date liste. Po zavrsenoj deinstalaciji, restartuj racunar.
Ukoliko je postojao neki program koji je odbio deinstalaciju i uklanjanje, pokusaj jos jednom sad po restartu racunara za svaki slucaj. Ako i dalje odbija, nema veze...ostavi ga/ih.







--- --- --- --- ---
Arrow FRST i FixList.txt
--- ---





1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:
START
File: C:\Users\korisnik\Downloads\setup.exe
File: C:\Users\korisnik\Downloads\setup (1).exe
Folder: C:\Users\korisnik\AppData\Local\cache
Folder: C:\Users\korisnik\.android
C:\Program Files\Mobogenie
C:\Users\korisnik\LOCALS~1\Temp\*.cmd
C:\Users\korisnik\LOCALS~1\Temp\*.dll
C:\Users\korisnik\LOCALS~1\Temp\*.exe
C:\Program Files\Web Assistant
C:\Program Files\BearShare Applications
C:\Program Files\Delta
C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
C:\ProgramData\Bcool
C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx
C:\Program Files\Perion
C:\Users\korisnik\AppData\Local\Torch
C:\Windows\system32\dmwu.exe
C:\Users\korisnik\AppData\Local\Mobogenie
C:\Users\korisnik\Documents\Mobogenie
C:\Program Files\GoforFiles
C:\ProgramData\OptimizerPro
C:\Users\korisnik\AppData\Roaming\BabSolution
CMD: IPConfig /FlushDNS
HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-1829802654-943873472-2443089448-1000\...\CurrentVersion\Windows: [Load] C:\Users\korisnik\LOCALS~1\Temp\msqwuo.cmd <===== ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=119294&babsrc.....2522E50316
HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=2937
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://search.babylon.com/?affID=119294&babsrc.....2522E50316
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=2937
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
URLSearchHook: HKCU - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
URLSearchHook: HKCU - (No Name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = http://dts.search-results.com/sr?src=ieb&gct=d.....483&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=119294&babsrc=SP_ss_din2g&mntrId=189B002522E50316
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://search.babylon.com/?q={searchTerms}&affID=119294&babsrc=SP_ss_din2g&mntrId=189B002522E50316
SearchScopes: HKCU - {49944F31-7D64-4BF3-949A-176783B44FDE} URL = http://websearch.ask.com/redirect?client=ie&tb.....crm&q={searchTerms}&locale=&apn_ptnrs=^AGY&apn_dtid=^YYYYYY^YY^RS&apn_uid=8f7030f9-f4df-418e-b9bc-0f3c114f7221&apn_sauid=B0271BC3-FD5F-4EB0-82AB-1E52AC5BF48D
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = http://dts.search-results.com/sr?src=ieb&gct=d.....483&q={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = http://dts.search-results.com/sr?src=ieb&appid.....r=0&q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms}
BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
BHO: DataMngr - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC)
BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
BHO: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
BHO: DownTango Launcher - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll (Simplytech Ltd.)
Toolbar: HKLM - Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
Toolbar: HKLM - DownTango Launcher - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll (Simplytech Ltd.)
Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
Toolbar: HKCU - No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
CHR Plugin: (Perion plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.485_0\npbrowserext.dll No File
CHR Plugin: (TorchPlugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof\1.0.0.2023_0\plugin/torchplugin.dll No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll No File
CHR HKLM\...\Chrome\Extension: [biffcfkpbbhalilhcjiajcpffjmfhmgp] - C:\ProgramData\Bcool\biffcfkpbbhalilhcjiajcpffjmfhmgp.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-11-19]
CHR HKLM\...\Chrome\Extension: [gladcbhcbkdeddbidiblppadjdjalidb] - C:\Program Files\DownTangoFTToolbar\chrome\DownTangoFTToolbar.crx [2012-11-19]
CHR HKLM\...\Chrome\Extension: [jifflliplgeajjdhmkcfnngfpgbjonjg] - C:\Program Files\Perion\NewTab\newTab.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\korisnik\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-01-08]
CHR HKCU\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-11-19]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S4 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2012-09-03] ()
S4 WebOptimizer; C:\Windows\system32\dmwu.exe [1006448 2012-09-13] ()
Task: {5D7B40DD-7825-4A4B-9117-5FE50DFCF561} - System32\Tasks\GoforFilesUpdate => C:\Program Files\GoforFiles\GFFUpdater.exe <==== ATTENTION
Task: {8E26F31F-4D20-46BD-BFF3-E9FC9363BA04} - System32\Tasks\OptimizerProUpdaterTask{4057793E-7B8D-4A3B-AC85-22994000FC32} => C:\ProgramData\OptimizerPro\ix_updater.exe [2012-10-29] () <==== ATTENTION
Task: {B2FE6D17-ED08-4FA5-BC95-5399C93048DB} - System32\Tasks\EPUpdater => C:\Users\korisnik\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION
Task: C:\Windows\Tasks\OptimizerProUpdaterTask{4057793E-7B8D-4A3B-AC85-22994000FC32}.job => C:\ProgramData\OptimizerPro\ix_updater.exe <==== ATTENTION
REBOOT:
END

2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

sirzizo ::
I da iskoristim pauzu pitanjem, naravno kad budete imali vremena odgovorićete mi. Nadao sam se da tim mrežnim spy, mal, ili nem pojma kojim ware om nisam zarazio komp, a ukoliko jesam onda nisam jedan nego 3-4, još uvek nisam primetio neke promene u radu sistema, sem u jednom onom slučaju kada sam prvi put došao u vezu (bio tagovan) sa ovim wtf, nisam mogao da odem na youtube gde mi se uvek otvarao natpis (na engeskom) grupa dobro obučenih majmuna je krenula da se pozabavi ovim problemom ako ih vidite prenesite im ovu poruku, ispod te rečenice je išla cela tekstura slova,brojeva itd kao neki kod. Avira mi je nakon scaniranja otklonila taj problem (barem tako mislim).



Znas kako, postavljeni logovi su izlistali ucitan ne samo malware kao takav vec i razne ucitane PUP programe. Ti ces pokusati deo toga ukloniti rucno (korak1) a drugi deo ima zadatak da kaze FRST alatu da cilja i ukloni (koristeci silu ako treba) sve maliciozne i PUP unose koje imas na sistemu. Sve sto su AntiVirus/AntiMalware programi propustili, ja ih iz generickih logova vidim i ciljam.


A ovo za 'grupa dobro obučenih majmuna' ( Laughing ) nisam najbolje razumeo, plasim se.

offline
  • Pridružio: 22 Mar 2014
  • Poruke: 9

Napisano: 22 Mar 2014 20:06

Da, tek posle kada sam to objavio skapirah da se može skapirati ironično i izvinjavam se na tome, ali mi je stalno tako izlazilo umesto otvaranja youtuba, tako da sve ovo što postujem- postujem bez ikakve ironije, pa će ovo rešavanje mog problema biti put ka rešavanju nečijeg, jer isto tako čitajući neki od problema mojih prethodnika dodjoh do vas, a nisam imao veze ni da postojite.

Uradjeno je sve od traženog. Koji je sledeći korak?

Dopuna: 22 Mar 2014 20:11

nisam obrisao tourch za čije brisanje mi je potreban pasword, i Optimizer pro-updater
mycity.rs/must-login.png

Dopuna: 22 Mar 2014 20:16

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01
Ran by korisnik at 2014-03-22 19:58:36 Run:1
Running from C:\Users\korisnik\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
START
File: C:\Users\korisnik\Downloads\setup.exe
File: C:\Users\korisnik\Downloads\setup (1).exe
Folder: C:\Users\korisnik\AppData\Local\cache
Folder: C:\Users\korisnik\.android
C:\Program Files\Mobogenie
C:\Users\korisnik\LOCALS~1\Temp\*.cmd
C:\Users\korisnik\LOCALS~1\Temp\*.dll
C:\Users\korisnik\LOCALS~1\Temp\*.exe
C:\Program Files\Web Assistant
C:\Program Files\BearShare Applications
C:\Program Files\Delta
C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
C:\ProgramData\Bcool
C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx
C:\Program Files\Perion
C:\Users\korisnik\AppData\Local\Torch
C:\Windows\system32\dmwu.exe
C:\Users\korisnik\AppData\Local\Mobogenie
C:\Users\korisnik\Documents\Mobogenie
C:\Program Files\GoforFiles
C:\ProgramData\OptimizerPro
C:\Users\korisnik\AppData\Roaming\BabSolution
CMD: IPConfig /FlushDNS
HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-1829802654-943873472-2443089448-1000\...\CurrentVersion\Windows: [Load] C:\Users\korisnik\LOCALS~1\Temp\msqwuo.cmd <===== ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.babylon.com/?affID=119294&babsrc.....2522E50316
HKCU\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = search.certified-toolbar.com?si=41460&home=true&tid=2937
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = search.babylon.com/?affID=119294&babsrc.....2522E50316
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
HKLM\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = search.certified-toolbar.com?si=41460&home=true&tid=2937
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = search.certified-toolbar.com?si=41460&tid=2937&bs=true&q=
URLSearchHook: HKCU - (No Name) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No File
URLSearchHook: HKCU - (No Name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = dts.search-results.com/sr?src=ieb&gct=d.....483&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms}
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = search.babylon.com/?q={searchTerms}&affID=119294&babsrc=SP_ss_din2g&mntrId=189B002522E50316
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = search.babylon.com/?q={searchTerms}&affID=119294&babsrc=SP_ss_din2g&mntrId=189B002522E50316
SearchScopes: HKCU - {49944F31-7D64-4BF3-949A-176783B44FDE} URL = websearch.ask.com/redirect?client=ie&tb.....crm&q={searchTerms}&locale=&apn_ptnrs=^AGY&apn_dtid=^YYYYYY^YY^RS&apn_uid=8f7030f9-f4df-418e-b9bc-0f3c114f7221&apn_sauid=B0271BC3-FD5F-4EB0-82AB-1E52AC5BF48D
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = dts.search-results.com/sr?src=ieb&gct=d.....483&q={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL = dts.search-results.com/sr?src=ieb&appid.....r=0&q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2269050&SSPV=TB_IEOB27
SearchScopes: HKCU - {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = search.certified-toolbar.com?si=41460&bs=true&tid=2937&q={searchTerms}
BHO: Web Assistant - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
BHO: DataMngr - {B939CF93-F2CB-443d-956C-DC523D85C9DB} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\BrowserConnection.dll (MusicLab, LLC)
BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com)
BHO: Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
BHO: DownTango Launcher - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll (Simplytech Ltd.)
Toolbar: HKLM - Wincore Mediabar - {c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - C:\Program Files\BearShare Applications\MediaBar\Datamngr\ToolBar\wincorebsdtx.dll ()
Toolbar: HKLM - DownTango Launcher - {e327b07a-0e11-4fd4-bef2-b2c5605b59c6} - C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar\DownTangoFTToolbar.dll (Simplytech Ltd.)
Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com)
Toolbar: HKCU - No Name - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File
CHR Plugin: (Perion plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.485_0\npbrowserext.dll No File
CHR Plugin: (TorchPlugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof\1.0.0.2023_0\plugin/torchplugin.dll No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll No File
CHR HKLM\...\Chrome\Extension: [biffcfkpbbhalilhcjiajcpffjmfhmgp] - C:\ProgramData\Bcool\biffcfkpbbhalilhcjiajcpffjmfhmgp.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-11-19]
CHR HKLM\...\Chrome\Extension: [gladcbhcbkdeddbidiblppadjdjalidb] - C:\Program Files\DownTangoFTToolbar\chrome\DownTangoFTToolbar.crx [2012-11-19]
CHR HKLM\...\Chrome\Extension: [jifflliplgeajjdhmkcfnngfpgbjonjg] - C:\Program Files\Perion\NewTab\newTab.crx [2012-07-27]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\korisnik\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-01-08]
CHR HKCU\...\Chrome\Extension: [ejpbbhjlbipncjklfjjaedaieimbmdda] - C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx [2012-11-19]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S4 Web Assistant Updater; C:\Program Files\Web Assistant\ExtensionUpdaterService.exe [188760 2012-09-03] ()
S4 WebOptimizer; C:\Windows\system32\dmwu.exe [1006448 2012-09-13] ()
Task: {5D7B40DD-7825-4A4B-9117-5FE50DFCF561} - System32\Tasks\GoforFilesUpdate => C:\Program Files\GoforFiles\GFFUpdater.exe <==== ATTENTION
Task: {8E26F31F-4D20-46BD-BFF3-E9FC9363BA04} - System32\Tasks\OptimizerProUpdaterTask{4057793E-7B8D-4A3B-AC85-22994000FC32} => C:\ProgramData\OptimizerPro\ix_updater.exe [2012-10-29] () <==== ATTENTION
Task: {B2FE6D17-ED08-4FA5-BC95-5399C93048DB} - System32\Tasks\EPUpdater => C:\Users\korisnik\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION
Task: C:\Windows\Tasks\OptimizerProUpdaterTask{4057793E-7B8D-4A3B-AC85-22994000FC32}.job => C:\ProgramData\OptimizerPro\ix_updater.exe <==== ATTENTION
REBOOT:
END
*****************


========================= File: C:\Users\korisnik\Downloads\setup.exe ========================

MD5: 9B8E39E792DE4FD471CF387471F8622C
Creation and modification date: 2014-03-01 18:53 - 2014-03-01 18:53
Size: 0108064
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product Name: Installer
Description: Installer
File Version:
Product Version: 3.0
Copyright: Installer

====== End Of File: ======


========================= File: C:\Users\korisnik\Downloads\setup (1).exe ========================

MD5: C3454716348D704276D26AE212DD3FD9
Creation and modification date: 2014-03-06 12:21 - 2014-03-06 12:21
Size: 0108064
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product Name: Installer
Description: Installer
File Version:
Product Version: 3.0
Copyright: Installer

====== End Of File: ======


========================= Folder: C:\Users\korisnik\AppData\Local\cache ========================

2014-03-06 12:25 - 2014-03-06 12:25 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\0
2014-03-06 12:25 - 2014-03-06 12:25 - 0009488 _____ () C:\Users\korisnik\AppData\Local\cache\data7\0\24oojbk0.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007709 _____ () C:\Users\korisnik\AppData\Local\cache\data7\0\2db7f4hp.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0035458 _____ () C:\Users\korisnik\AppData\Local\cache\data7\0\2kolj8xp.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007125 _____ () C:\Users\korisnik\AppData\Local\cache\data7\0\35o9owkp.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0042278 _____ () C:\Users\korisnik\AppData\Local\cache\data7\0\3pff9xd0.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0009291 _____ () C:\Users\korisnik\AppData\Local\cache\data7\0\3pmso4rp.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004655 _____ () C:\Users\korisnik\AppData\Local\cache\data7\0\6gkpgkgp.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0003644 _____ () C:\Users\korisnik\AppData\Local\cache\data7\0\xehflwdp.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\1
2014-03-06 12:26 - 2014-03-06 12:26 - 0008613 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\168flaba.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0003437 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\1fzoc3yq.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004018 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\26rb70ea.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0005018 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\27x6egca.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0003086 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\28cxfqoq.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0001565 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\2htydrk1.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0078155 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\2kt1bgaa.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0107326 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\2pb39jra.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0038310 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\2y15i5dq.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0005739 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\39z7j3pq.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0025311 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\3bnv6vua.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0001369 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\hdlcfcy1.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0102501 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\ka5o8f8a.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0005505 _____ () C:\Users\korisnik\AppData\Local\cache\data7\1\sciws5i1.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\2
2014-03-06 12:26 - 2014-03-06 12:26 - 0027208 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\17ob3rb2.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007499 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\1z7jiufb.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007379 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\20t318q2.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0032300 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\28imw5dr.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0008368 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\2k19pg1r.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007642 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\2olqmat2.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006859 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\37mn60zr.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004271 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\37zm53gr.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0040107 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\3bdexyb2.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007944 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\3m4cq7fr.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0055756 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\3ptrm7s2.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007744 _____ () C:\Users\korisnik\AppData\Local\cache\data7\2\3sdofzpr.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\3
2014-03-06 12:26 - 2014-03-06 12:26 - 0005046 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\1qcqfnlc.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0018526 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\1x3hpzbs.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0036396 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\2317x5kc.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004101 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\285w2qg3.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0012181 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\3ks9d9f3.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004196 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\dw94nbs3.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0005080 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\f7nrj1ps.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0028569 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\mhgoxr4c.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0035838 _____ () C:\Users\korisnik\AppData\Local\cache\data7\3\q3x5mjuc.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\4
2014-03-06 12:26 - 2014-03-06 12:26 - 0022608 _____ () C:\Users\korisnik\AppData\Local\cache\data7\4\1ohtdc64.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0011893 _____ () C:\Users\korisnik\AppData\Local\cache\data7\4\1u4imsyt.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0003268 _____ () C:\Users\korisnik\AppData\Local\cache\data7\4\2cwy0vkd.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004065 _____ () C:\Users\korisnik\AppData\Local\cache\data7\4\2o7cstld.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0122366 _____ () C:\Users\korisnik\AppData\Local\cache\data7\4\315volld.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007007 _____ () C:\Users\korisnik\AppData\Local\cache\data7\4\3bcfqqf4.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0008061 _____ () C:\Users\korisnik\AppData\Local\cache\data7\4\3qsky8ut.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0008463 _____ () C:\Users\korisnik\AppData\Local\cache\data7\4\lr7ii0r4.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\5
2014-03-06 12:25 - 2014-03-06 12:25 - 0016443 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\13ttpxq5.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0035396 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\1djsm1v5.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0005217 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\1gltjwne.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004623 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\1j44fvte.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0021749 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\1kan2dc5.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0037393 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\1sr6fv2u.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0021576 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\1wglxe85.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0033984 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\26jk49bu.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0005724 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\27id0f35.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0017548 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\31up9p35.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0023885 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\352cxu0u.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0003596 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\35oydmeu.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0022289 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\3auxirle.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0039600 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\3fz0czm5.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0060883 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\3lft60je.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0002766 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\3p4xtku5.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004239 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\5iumvkz5.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0023449 _____ () C:\Users\korisnik\AppData\Local\cache\data7\5\nvc7qz1u.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\6
2014-03-06 12:26 - 2014-03-06 12:26 - 0008848 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\1ardrua6.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0099557 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\1khdo0j6.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007971 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\26sgjfdf.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007288 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\29gpatcv.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0032680 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\2v38v456.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0046928 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\33qouog6.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0037688 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\3ec1gm4v.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0005352 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\3egv15y6.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007858 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\3fhrpk5v.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007677 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\7paqzvgf.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0032379 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\c5qgqqcv.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0026349 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\nzq8i4uf.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004683 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\qcsph5r6.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0003369 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\ral1pvrv.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006286 _____ () C:\Users\korisnik\AppData\Local\cache\data7\6\t2v4a9kv.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\7
2014-03-06 12:26 - 2014-03-06 12:26 - 0027220 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\1l5u41jg.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0013953 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\217mx137.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006062 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\24e7euzw.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0000610 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\26omvijg.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0027538 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\28j2eks7.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0023725 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\2bs28gjg.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0003088 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\2c42d2hw.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0003826 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\2cy8w32w.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0040015 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\2e9sygow.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0030734 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\2ub3xqhw.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004803 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\30ts1197.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0036454 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\369vwf77.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0005514 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\36cgdeag.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006033 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\36i4ceo7.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006713 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\3gxidu2g.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004182 _____ () C:\Users\korisnik\AppData\Local\cache\data7\7\3rju97o7.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\8
2014-03-06 12:26 - 2014-03-06 12:26 - 0007566 _____ () C:\Users\korisnik\AppData\Local\cache\data7\8\1cldrvqx.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0044348 _____ () C:\Users\korisnik\AppData\Local\cache\data7\8\1nrxxith.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007339 _____ () C:\Users\korisnik\AppData\Local\cache\data7\8\1u3rukb8.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0008073 _____ () C:\Users\korisnik\AppData\Local\cache\data7\8\1zkvkbq8.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006843 _____ () C:\Users\korisnik\AppData\Local\cache\data7\8\20i45e8x.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0001675 _____ () C:\Users\korisnik\AppData\Local\cache\data7\8\2o00rkoh.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0087251 _____ () C:\Users\korisnik\AppData\Local\cache\data7\8\ll4pvn8h.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006304 _____ () C:\Users\korisnik\AppData\Local\cache\data7\8\mxsm8fbx.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\9
2014-03-06 12:26 - 2014-03-06 12:26 - 0027448 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\1026jw4y.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0043664 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\1j681wxy.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0008056 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\1uzhbex9.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0002888 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\1zzx28y9.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0001901 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\2n8kvku9.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006855 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\31osj1vy.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0008322 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\3jr7mrm9.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0009433 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\9bolvw7i.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0008240 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\dkcmnmsy.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007070 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\gjbkzzt9.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0032680 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\kj3na9ni.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0142839 _____ () C:\Users\korisnik\AppData\Local\cache\data7\9\xwqu1rn9.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\a
2014-03-06 12:26 - 2014-03-06 12:26 - 0025465 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\15yop5pz.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0013837 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\1g164e4j.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0037508 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\2aoztfjz.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0020420 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\2da25t2z.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0001663 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\2iduv9jz.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007760 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\343rm0qz.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0009777 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\35xyl2ez.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0005986 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\4tzhsucz.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0048271 _____ () C:\Users\korisnik\AppData\Local\cache\data7\a\tn96d5yz.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\b
2014-03-06 12:26 - 2014-03-06 12:26 - 0005266 _____ () C:\Users\korisnik\AppData\Local\cache\data7\b\25i4i99k.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0001223 _____ () C:\Users\korisnik\AppData\Local\cache\data7\b\2683lelk.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0090637 _____ () C:\Users\korisnik\AppData\Local\cache\data7\b\yfm0ur7k.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\c
2014-03-06 12:26 - 2014-03-06 12:26 - 0007222 _____ () C:\Users\korisnik\AppData\Local\cache\data7\c\1knohvyl.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\d
2014-03-06 12:26 - 2014-03-06 12:26 - 0138120 _____ () C:\Users\korisnik\AppData\Local\cache\data7\d\1orykpsm.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007559 _____ () C:\Users\korisnik\AppData\Local\cache\data7\d\2kgrv1xm.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007042 _____ () C:\Users\korisnik\AppData\Local\cache\data7\d\2rjwcz0m.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0008986 _____ () C:\Users\korisnik\AppData\Local\cache\data7\d\3hmmcnwm.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0026602 _____ () C:\Users\korisnik\AppData\Local\cache\data7\d\gp0j6bim.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0007163 _____ () C:\Users\korisnik\AppData\Local\cache\data7\d\wv4memmm.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\e
2014-03-06 12:26 - 2014-03-06 12:26 - 0003348 _____ () C:\Users\korisnik\AppData\Local\cache\data7\e\1rtqgzhn.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0007289 _____ () C:\Users\korisnik\AppData\Local\cache\data7\e\2d5fujln.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0006404 _____ () C:\Users\korisnik\AppData\Local\cache\data7\e\3ss3klxn.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0001663 _____ () C:\Users\korisnik\AppData\Local\cache\data7\e\9bnshwin.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\data7\f
2014-03-06 12:26 - 2014-03-06 12:26 - 0008053 _____ () C:\Users\korisnik\AppData\Local\cache\data7\f\1pzeke0o.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0005799 _____ () C:\Users\korisnik\AppData\Local\cache\data7\f\2f7qpkgo.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0004324 _____ () C:\Users\korisnik\AppData\Local\cache\data7\f\39nrp0ao.d
2014-03-06 12:26 - 2014-03-06 12:26 - 0030651 _____ () C:\Users\korisnik\AppData\Local\cache\data7\f\3j18m0po.d
2014-03-06 12:25 - 2014-03-06 12:25 - 0040459 _____ () C:\Users\korisnik\AppData\Local\cache\data7\f\fj7qiq0o.d
2014-03-06 12:25 - 2014-03-06 12:26 - 0000000 ____D () C:\Users\korisnik\AppData\Local\cache\prepared

====== End of Folder: ======


========================= Folder: C:\Users\korisnik\.android ========================

2014-03-06 12:25 - 2014-03-06 12:25 - 0001704 _____ () C:\Users\korisnik\.android\adbkey
2014-03-06 12:25 - 2014-03-06 12:25 - 0000716 _____ () C:\Users\korisnik\.android\adbkey.pub

====== End of Folder: ======

"C:\Program Files\Mobogenie" => File/Directory not found.
"C:\Users\korisnik\LOCALS~1\Temp\*.cmd" => File/Directory not found.
C:\Users\korisnik\LOCALS~1\Temp\*.dll => Moved successfully.
C:\Users\korisnik\LOCALS~1\Temp\*.exe => Moved successfully.
"C:\Program Files\Web Assistant" => File/Directory not found.
C:\Program Files\BearShare Applications => Moved successfully.
C:\Program Files\Delta => Moved successfully.
C:\Users\korisnik\AppData\Roaming\DownTangoFTToolbar => Moved successfully.
"C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg" => File/Directory not found.
"C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd" => File/Directory not found.
"C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof" => File/Directory not found.
"C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda" => File/Directory not found.
"C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda" => File/Directory not found.
C:\ProgramData\Bcool => Moved successfully.
C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx => Moved successfully.
C:\Program Files\Perion => Moved successfully.
C:\Users\korisnik\AppData\Local\Torch => Moved successfully.
"C:\Windows\system32\dmwu.exe" => File/Directory not found.
C:\Users\korisnik\AppData\Local\Mobogenie => Moved successfully.
C:\Users\korisnik\Documents\Mobogenie => Moved successfully.
C:\Program Files\GoforFiles => Moved successfully.
C:\ProgramData\OptimizerPro => Moved successfully.
C:\Users\korisnik\AppData\Roaming\BabSolution => Moved successfully.

========= IPConfig /FlushDNS =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully.
HKU\S-1-5-21-1829802654-943873472-2443089448-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Default_Page_URL => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\bProtector Start Page => Value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Default_Page_URL => Value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\bProtectorDefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{49944F31-7D64-4BF3-949A-176783B44FDE} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{49944F31-7D64-4BF3-949A-176783B44FDE} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087} => Key not found.
HKCR\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B939CF93-F2CB-443d-956C-DC523D85C9DB} => Key deleted successfully.
HKCR\CLSID\{B939CF93-F2CB-443d-956C-DC523D85C9DB} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully.
HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} => Key deleted successfully.
HKCR\CLSID\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6} => Key deleted successfully.
HKCR\CLSID\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} => Value deleted successfully.
HKCR\CLSID\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6} => Value deleted successfully.
HKCR\CLSID\{e327b07a-0e11-4fd4-bef2-b2c5605b59c6} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Value deleted successfully.
HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => Value deleted successfully.
HKCR\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} => Value deleted successfully.
HKCR\CLSID\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} => Key not found.
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg\1.0.0_0\Plugins/PerionNewTabChrome-32.dll not found.
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.485_0\npbrowserext.dll not found.
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof\1.0.0.2023_0\plugin/torchplugin.dll not found.
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll not found.
C:\Users\korisnik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\biffcfkpbbhalilhcjiajcpffjmfhmgp => Key deleted successfully.
"C:\ProgramData\Bcool\biffcfkpbbhalilhcjiajcpffjmfhmgp.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd => Key deleted successfully.
"C:\Program Files\Web Assistant\source.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda => Key deleted successfully.
"C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\gladcbhcbkdeddbidiblppadjdjalidb => Key deleted successfully.
"C:\Program Files\DownTangoFTToolbar\chrome\DownTangoFTToolbar.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg => Key deleted successfully.
"C:\Program Files\Perion\NewTab\newTab.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof => Key deleted successfully.
"C:\Users\korisnik\AppData\Local\Torch\Plugins\TorchPlugin.crx" => File/Directory not found.
HKCU\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda => Key deleted successfully.
"C:\Users\korisnik\AppData\Local\CRE\ejpbbhjlbipncjklfjjaedaieimbmdda.crx" => File/Directory not found.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
Web Assistant Updater => Service not found.
WebOptimizer => Service not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5D7B40DD-7825-4A4B-9117-5FE50DFCF561} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D7B40DD-7825-4A4B-9117-5FE50DFCF561} => Key deleted successfully.
C:\Windows\System32\Tasks\GoforFilesUpdate => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoforFilesUpdate => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8E26F31F-4D20-46BD-BFF3-E9FC9363BA04} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E26F31F-4D20-46BD-BFF3-E9FC9363BA04} => Key deleted successfully.
C:\Windows\System32\Tasks\OptimizerProUpdaterTask{4057793E-7B8D-4A3B-AC85-22994000FC32} => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OptimizerProUpdaterTask{4057793E-7B8D-4A3B-AC85-22994000FC32} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B2FE6D17-ED08-4FA5-BC95-5399C93048DB} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2FE6D17-ED08-4FA5-BC95-5399C93048DB} => Key deleted successfully.
C:\Windows\System32\Tasks\EPUpdater => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater => Key deleted successfully.
C:\Windows\Tasks\OptimizerProUpdaterTask{4057793E-7B8D-4A3B-AC85-22994000FC32}.job => Moved successfully.


The system needed a reboot.

==== End of Fixlog ====

Dopuna: 22 Mar 2014 20:18

greškom sam obrisao web optimizer, koliko mi je on potreban?

Ko je trenutno na forumu
 

Ukupno su 1000 korisnika na forumu :: 37 registrovanih, 3 sakrivenih i 960 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, A.R.Chafee.Jr., Albin0, asdfjklc, bolenbgd, cenejac111, crnitrn, darkangel, djboj, draganca, esx66, hyla, ivica976, jackreacher011011, Kubovac, Mercury, Milometer, milutin134, moldway, nenad81, nenaddz, operniki, Panter, panzerwaffe, Parker, Primus17, repac, skvara, sombrero, sosko, srbijaiznadsvega, Srle993, stegonosa, Tas011, Vlada78, Yellow Pinky, 79693