|
|
Poslao: 26 Jul 2013 10:48
|
offline
- Mare Ivanović
- Ugledni građanin
- Pridružio: 30 Maj 2013
- Poruke: 425
- Gde živiš: U kući
|
Zoek.exe Version 4.0.0.4 Updated 21-07-2013
Tool run by Home on pet 26.07.2013 at 10:44:06,20.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Home\Desktop\zoek.exe [Script inserted]
==== System Restore Info ======================
26.7.2013 10:45:26 Zoek.exe System Restore Point Created Succesfully.
==== Running Processes ======================
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\PROGRA~2\MARINE~2\bar\1.bin\57barsvc.exe
C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Users\Home\Desktop\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
==== Files Recently Created / Modified ======================
====== C:\Windows ====
2013-07-05 19:43:03 A5F1CA585B977FB04129E1B4C6374403 2455886 ----a-w- C:\Windows\Sim AQUARIUM 3.scr
2013-07-05 19:42:52 86E39E9161C3D930D93822F1563C280D 1998168 ----a-w- C:\Windows\D3DX9_43.dll
====== C:\Users\Home\AppData\Local\Temp ====
====== C:\Windows\SysWOW64 =====
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2013-07-25 16:27:37 393138B07104721B1B4AF95D8F45893A 414656 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT
====== C:\Windows\Sysnative\drivers =====
2013-07-14 11:38:33 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
====== C:\Windows\Tasks ======
2013-07-25 11:51:51 90A58E6FD85E0B5958C5BFE0A9C5959B 2708 ----a-w- C:\Windows\Sysnative\Tasks\schedule!3036567561
2013-07-25 11:51:50 DEEE82D9517975C88FB853259328EA3C 414 ---ha-w- C:\Windows\Tasks\schedule!3036567561.job
2013-07-01 19:17:51 5666272FF1F9F5D683972D704DC4C1AE 894 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-01 19:17:51 46A6029C54F5C1D974DF9914A7BEC4DB 3890 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineUA
2013-07-01 19:17:50 039073D6E4C93969C54D8AB19AD41FEE 890 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-01 19:17:50 03532F0783F429E1095F3985991320B0 3638 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineCore
2013-06-29 11:14:43 1CCAD292AB20218AA3D46D33C8892BAF 830 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-29 11:14:43 0E2E029782F39969FADA56D652F107FB 3768 ----a-w- C:\Windows\Sysnative\Tasks\Adobe Flash Player Updater
2013-06-29 10:57:15 D622EFB007881C595B664E2C4090DFCB 3148 ----a-w- C:\Windows\Sysnative\Tasks\{D91E0789-2B12-4F67-8B11-D7FC0A36A75F}
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\Program Files (x86) =====
2013-07-07 07:28:47 -------- d-----w- C:\Program Files (x86)\MCShield
2013-07-06 17:36:16 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2013-07-05 18:57:11 -------- d-----w- C:\Program Files (x86)\MarineAquarium3Free_57
2013-07-02 08:50:00 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-01 19:17:46 -------- d-----w- C:\Program Files (x86)\Google
2013-06-27 07:41:20 -------- d-----w- C:\Program Files (x86)\PhotoScape
======= C: =====
====== C:\Users\Home\AppData\Roaming ======
2013-07-25 15:09:07 3267661C28EEBE52A6991CF9207A3655 108840 ----a-w- C:\users\Home\AppData\Local\GDIPFONTCACHEV1.DAT
2013-07-25 14:21:03 -------- d-----w- C:\users\Home\AppData\Local\RockMelt
2013-07-15 19:19:43 -------- d-----w- C:\users\Home\AppData\Locallow\Adobe
2013-07-11 11:18:28 -------- d-----w- C:\users\Home\AppData\Roaming\DAEMON Tools Lite
2013-07-05 19:01:38 -------- d-----w- C:\users\Home\AppData\Local\MarineAquarium3Free_57
2013-07-05 18:57:15 -------- d-----w- C:\users\Home\AppData\Locallow\MarineAquarium3Free_57
2013-07-04 09:39:20 -------- d-----w- C:\users\Home\AppData\Roaming\GRETECH
2013-07-02 08:50:10 -------- d-----w- C:\users\Home\AppData\Roaming\Mozilla
2013-06-29 11:12:10 -------- d-----w- C:\users\Home\AppData\Local\Adobe
2013-06-29 10:57:06 -------- d-----w- C:\users\Home\AppData\Local\Deployment
2013-06-29 10:57:06 -------- d-----w- C:\users\Home\AppData\Local\Apps
2013-06-28 14:56:03 -------- d-----w- C:\users\Home\AppData\Roaming\Foxit Software
2013-06-27 07:41:44 -------- d-----w- C:\users\Home\AppData\Roaming\PhotoScape
2013-06-26 17:33:42 -------- d-----w- C:\users\Home\AppData\Roaming\AVG
2013-06-26 14:06:17 -------- d-----w- C:\users\Home\AppData\Roaming\DownLite
2013-06-26 14:03:49 -------- d-----w- C:\users\Home\AppData\Local\Google
====== C:\Users\Home ======
2013-07-25 11:51:50 -------- d-----w- C:\ProgramData\BetterSoft
2013-07-25 11:50:48 -------- d-----w- C:\ProgramData\InstallMate
2013-07-11 11:17:26 -------- d-----w- C:\ProgramData\DAEMON Tools Lite
2013-07-09 08:17:44 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2013-07-07 07:28:49 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MCShield
2013-07-07 07:28:47 -------- d-----w- C:\ProgramData\MCShield
2013-07-06 17:36:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2013-07-05 19:42:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sim AQUARIUM 3
2013-07-05 19:42:52 -------- d-----w- C:\ProgramData\SA3
2013-07-04 13:28:27 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\Home\ntuser.ini
2013-07-04 09:38:32 -------- d-----w- C:\Users\Home\Nova fascikla
2013-07-01 19:21:44 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-06-29 14:16:48 -------- d-----w- C:\ProgramData\Simply Super Software
2013-06-29 13:01:16 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-06-28 19:09:00 -------- d-----w- C:\ProgramData\StarApp
2013-06-28 19:09:00 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSearchh-NeWWTab
2013-06-28 19:07:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSafe savvee
2013-06-27 07:41:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2013-06-26 19:08:15 -------- d-----w- C:\ProgramData\TEMP
2013-06-26 18:58:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab
2013-06-26 18:57:26 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ssaFe! save
2013-06-26 17:33:04 -------- d-----w- C:\ProgramData\AVG
2013-06-26 17:32:51 -------- d-sh--w- C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-06-26 14:09:25 -------- d-----w- C:\ProgramData\Real
====== C: exe-files ==
2013-07-25 11:52:07 E717F6CE3A7429BFA6D7F3CF66737A4B 15968 --s-a-r- C:\ProgramData\InstallMate\{A18F91AE-C21D-4A38-A8D3-8A3F7A6CB358}\Setup.exe
2013-07-25 11:51:50 98B03BEF5A2808C5EFA2A0D2430144DE 15968 --s-a-r- C:\ProgramData\InstallMate\OptimizerPro\Setup.exe
2013-07-25 11:51:50 2960400094498DAE47B36173286D76A0 348160 ------w- C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe
=== C: other files ==
2013-07-25 15:07:12 25B26E1D9D179E4F0F9762B911463595 634 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave26.zip
2013-07-25 15:07:11 D91B6CFDA90E0375B0E5CF2132D679C3 348691 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave23.zip
2013-07-25 15:07:11 1D33E88320A669EBC989698383CD422D 16413 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave25.zip
2013-07-25 15:07:11 09BB28518A1A14EE66D182FBAC3041DD 348682 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave24.zip
2013-07-25 15:07:09 6EB3A1B1A86F3DD52DB19A9A7C961A57 348616 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave22.zip
2013-07-25 14:52:56 4075459DD814B6269EDC70158CC8B733 652867 ----a-w- C:\ProgramData\AVG2013\IDS\quarantine\94da88d1-2b48-47d3-89de-e1ccefac356f.zip
2013-07-25 14:29:21 6A2BD3B434BCED0A8C7CCD3927A75C05 1171317 ----a-w- C:\ProgramData\AVG2013\IDS\quarantine\45e76c82-2b25-47d3-8a24-e1ccefac356f.zip
2013-07-19 14:06:56 6F3AAC92A4F83948B47CECB8DC1E744F 3960 ----a-w- C:\ProgramData\AVG2013\IDS\quarantine\ef21813c-268e-47d3-867e-e1ccefac356f.zip
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_UI"="C:\Program Files (x86)\AVG\AVG2013\avgui.exe /TRAYONLY"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s"
==== Startup Registry Disabled ======================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]
"SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\""
==== Startup Registry Disabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BCSSync]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BCSSync"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Microsoft Office\\Office14\\BCSSync.exe\" /DelayServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MCShield Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MCShield Monitor"
"hkey"="HKCU"
"command"="C:\\Program Files (x86)\\MCShield\\MCShieldRTM.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WinampAgent"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Winamp\\winampa.exe\""
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task]
C:\Windows\tasks\schedule\Undetermined Task.exe []
==== Firefox Extensions ======================
==== Firefox Plugins ======================
Profilepath: C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\94yugiu7.default
3D76B5C0E02ECC19C1F5756E8FD97F72 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll - Shockwave Flash
AE7B288233C212C62CD544BF768C45E6 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll - Shockwave for Director / Shockwave for Director
2EE9DCAE1D70ABF4D058688DE35F8221 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.16
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
dhfcbmlocifngpbjdpgnkbjmgkadkjpp - C:\Program Files (x86)\Industriya\privitize\1.8.21.6\privitize.crx[]
nbmafkdmkkckhggblphicnnhlgljnoje - C:\Program Files (x86)\TornTV.com\torn2_10.crx[]
Google Docs - Home - default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Home - default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Home - default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Home - default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Slagalica fer igra - Ludara.com - Home - default\Extensions\ejpifakoabdhigpeebhalfkjkoidenba
Gmail - Home - default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== IE Start and Search Settings ======================
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{18401191-9920-4692-8096-1EA7F09EA828} Yahoo//search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=512435&p={searchTerms}"
==== EOF on pet 26.07.2013 at 10:47:22,29 ======================
|
|
|
|
|
Poslao: 26 Jul 2013 14:19
|
offline
- Mare Ivanović
- Ugledni građanin
- Pridružio: 30 Maj 2013
- Poruke: 425
- Gde živiš: U kući
|
Napisano: 26 Jul 2013 14:04
Zoek.exe Version 4.0.0.4 Updated 21-07-2013
Tool run by Home on pet 26.07.2013 at 10:44:06,20.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Home\Desktop\zoek.exe [Script inserted]
==== System Restore Info ======================
26.7.2013 10:45:26 Zoek.exe System Restore Point Created Succesfully.
==== Running Processes ======================
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\PROGRA~2\MARINE~2\bar\1.bin\57barsvc.exe
C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Users\Home\Desktop\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
==== Files Recently Created / Modified ======================
====== C:\Windows ====
2013-07-05 19:43:03 A5F1CA585B977FB04129E1B4C6374403 2455886 ----a-w- C:\Windows\Sim AQUARIUM 3.scr
2013-07-05 19:42:52 86E39E9161C3D930D93822F1563C280D 1998168 ----a-w- C:\Windows\D3DX9_43.dll
====== C:\Users\Home\AppData\Local\Temp ====
====== C:\Windows\SysWOW64 =====
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2013-07-25 16:27:37 393138B07104721B1B4AF95D8F45893A 414656 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT
====== C:\Windows\Sysnative\drivers =====
2013-07-14 11:38:33 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
====== C:\Windows\Tasks ======
2013-07-25 11:51:51 90A58E6FD85E0B5958C5BFE0A9C5959B 2708 ----a-w- C:\Windows\Sysnative\Tasks\schedule!3036567561
2013-07-25 11:51:50 DEEE82D9517975C88FB853259328EA3C 414 ---ha-w- C:\Windows\Tasks\schedule!3036567561.job
2013-07-01 19:17:51 5666272FF1F9F5D683972D704DC4C1AE 894 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-01 19:17:51 46A6029C54F5C1D974DF9914A7BEC4DB 3890 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineUA
2013-07-01 19:17:50 039073D6E4C93969C54D8AB19AD41FEE 890 ----a-w- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-01 19:17:50 03532F0783F429E1095F3985991320B0 3638 ----a-w- C:\Windows\Sysnative\Tasks\GoogleUpdateTaskMachineCore
2013-06-29 11:14:43 1CCAD292AB20218AA3D46D33C8892BAF 830 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-29 11:14:43 0E2E029782F39969FADA56D652F107FB 3768 ----a-w- C:\Windows\Sysnative\Tasks\Adobe Flash Player Updater
2013-06-29 10:57:15 D622EFB007881C595B664E2C4090DFCB 3148 ----a-w- C:\Windows\Sysnative\Tasks\{D91E0789-2B12-4F67-8B11-D7FC0A36A75F}
====== C:\Windows\Temp ======
======= C:\Program Files =====
======= C:\Program Files (x86) =====
2013-07-07 07:28:47 -------- d-----w- C:\Program Files (x86)\MCShield
2013-07-06 17:36:16 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2013-07-05 18:57:11 -------- d-----w- C:\Program Files (x86)\MarineAquarium3Free_57
2013-07-02 08:50:00 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-01 19:17:46 -------- d-----w- C:\Program Files (x86)\Google
2013-06-27 07:41:20 -------- d-----w- C:\Program Files (x86)\PhotoScape
======= C: =====
====== C:\Users\Home\AppData\Roaming ======
2013-07-25 15:09:07 3267661C28EEBE52A6991CF9207A3655 108840 ----a-w- C:\users\Home\AppData\Local\GDIPFONTCACHEV1.DAT
2013-07-25 14:21:03 -------- d-----w- C:\users\Home\AppData\Local\RockMelt
2013-07-15 19:19:43 -------- d-----w- C:\users\Home\AppData\Locallow\Adobe
2013-07-11 11:18:28 -------- d-----w- C:\users\Home\AppData\Roaming\DAEMON Tools Lite
2013-07-05 19:01:38 -------- d-----w- C:\users\Home\AppData\Local\MarineAquarium3Free_57
2013-07-05 18:57:15 -------- d-----w- C:\users\Home\AppData\Locallow\MarineAquarium3Free_57
2013-07-04 09:39:20 -------- d-----w- C:\users\Home\AppData\Roaming\GRETECH
2013-07-02 08:50:10 -------- d-----w- C:\users\Home\AppData\Roaming\Mozilla
2013-06-29 11:12:10 -------- d-----w- C:\users\Home\AppData\Local\Adobe
2013-06-29 10:57:06 -------- d-----w- C:\users\Home\AppData\Local\Deployment
2013-06-29 10:57:06 -------- d-----w- C:\users\Home\AppData\Local\Apps
2013-06-28 14:56:03 -------- d-----w- C:\users\Home\AppData\Roaming\Foxit Software
2013-06-27 07:41:44 -------- d-----w- C:\users\Home\AppData\Roaming\PhotoScape
2013-06-26 17:33:42 -------- d-----w- C:\users\Home\AppData\Roaming\AVG
2013-06-26 14:06:17 -------- d-----w- C:\users\Home\AppData\Roaming\DownLite
2013-06-26 14:03:49 -------- d-----w- C:\users\Home\AppData\Local\Google
====== C:\Users\Home ======
2013-07-25 11:51:50 -------- d-----w- C:\ProgramData\BetterSoft
2013-07-25 11:50:48 -------- d-----w- C:\ProgramData\InstallMate
2013-07-11 11:17:26 -------- d-----w- C:\ProgramData\DAEMON Tools Lite
2013-07-09 08:17:44 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2013-07-07 07:28:49 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MCShield
2013-07-07 07:28:47 -------- d-----w- C:\ProgramData\MCShield
2013-07-06 17:36:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
2013-07-05 19:42:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sim AQUARIUM 3
2013-07-05 19:42:52 -------- d-----w- C:\ProgramData\SA3
2013-07-04 13:28:27 6FC234AD3752E1267B34FB12BCD6718B 20 --sh--w- C:\Users\Home\ntuser.ini
2013-07-04 09:38:32 -------- d-----w- C:\Users\Home\Nova fascikla
2013-07-01 19:21:44 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-06-29 14:16:48 -------- d-----w- C:\ProgramData\Simply Super Software
2013-06-29 13:01:16 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2013-06-28 19:09:00 -------- d-----w- C:\ProgramData\StarApp
2013-06-28 19:09:00 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSearchh-NeWWTab
2013-06-28 19:07:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSafe savvee
2013-06-27 07:41:28 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2013-06-26 19:08:15 -------- d-----w- C:\ProgramData\TEMP
2013-06-26 18:58:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab
2013-06-26 18:57:26 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ssaFe! save
2013-06-26 17:33:04 -------- d-----w- C:\ProgramData\AVG
2013-06-26 17:32:51 -------- d-sh--w- C:\ProgramData\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-06-26 14:09:25 -------- d-----w- C:\ProgramData\Real
====== C: exe-files ==
2013-07-25 11:52:07 E717F6CE3A7429BFA6D7F3CF66737A4B 15968 --s-a-r- C:\ProgramData\InstallMate\{A18F91AE-C21D-4A38-A8D3-8A3F7A6CB358}\Setup.exe
2013-07-25 11:51:50 98B03BEF5A2808C5EFA2A0D2430144DE 15968 --s-a-r- C:\ProgramData\InstallMate\OptimizerPro\Setup.exe
2013-07-25 11:51:50 2960400094498DAE47B36173286D76A0 348160 ------w- C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe
=== C: other files ==
2013-07-25 15:07:12 25B26E1D9D179E4F0F9762B911463595 634 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave26.zip
2013-07-25 15:07:11 D91B6CFDA90E0375B0E5CF2132D679C3 348691 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave23.zip
2013-07-25 15:07:11 1D33E88320A669EBC989698383CD422D 16413 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave25.zip
2013-07-25 15:07:11 09BB28518A1A14EE66D182FBAC3041DD 348682 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave24.zip
2013-07-25 15:07:09 6EB3A1B1A86F3DD52DB19A9A7C961A57 348616 ----a-w- C:\ProgramData\Spybot - Search & Destroy\Recovery\BarowwsoeSave22.zip
2013-07-25 14:52:56 4075459DD814B6269EDC70158CC8B733 652867 ----a-w- C:\ProgramData\AVG2013\IDS\quarantine\94da88d1-2b48-47d3-89de-e1ccefac356f.zip
2013-07-25 14:29:21 6A2BD3B434BCED0A8C7CCD3927A75C05 1171317 ----a-w- C:\ProgramData\AVG2013\IDS\quarantine\45e76c82-2b25-47d3-8a24-e1ccefac356f.zip
2013-07-19 14:06:56 6F3AAC92A4F83948B47CECB8DC1E744F 3960 ----a-w- C:\ProgramData\AVG2013\IDS\quarantine\ef21813c-268e-47d3-867e-e1ccefac356f.zip
==== Startup Registry Enabled ======================
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_UI"="C:\Program Files (x86)\AVG\AVG2013\avgui.exe /TRAYONLY"
==== Startup Registry Enabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s"
==== Startup Registry Disabled ======================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]
"SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\""
==== Startup Registry Disabled x64 ======================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BCSSync]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BCSSync"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Microsoft Office\\Office14\\BCSSync.exe\" /DelayServices"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MCShield Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MCShield Monitor"
"hkey"="HKCU"
"command"="C:\\Program Files (x86)\\MCShield\\MCShieldRTM.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WinampAgent"
"hkey"="HKLM"
"command"="\"C:\\Program Files (x86)\\Winamp\\winampa.exe\""
==== Task Scheduler Jobs ======================
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task]
C:\Windows\tasks\schedule\Undetermined Task.exe []
==== Firefox Extensions ======================
==== Firefox Plugins ======================
Profilepath: C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\94yugiu7.default
3D76B5C0E02ECC19C1F5756E8FD97F72 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll - Shockwave Flash
AE7B288233C212C62CD544BF768C45E6 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll - Shockwave for Director / Shockwave for Director
2EE9DCAE1D70ABF4D058688DE35F8221 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.16
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
dhfcbmlocifngpbjdpgnkbjmgkadkjpp - C:\Program Files (x86)\Industriya\privitize\1.8.21.6\privitize.crx[]
nbmafkdmkkckhggblphicnnhlgljnoje - C:\Program Files (x86)\TornTV.com\torn2_10.crx[]
Google Docs - Home - default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Home - default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Home - default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Home - default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Slagalica fer igra - Ludara.com - Home - default\Extensions\ejpifakoabdhigpeebhalfkjkoidenba
Gmail - Home - default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== IE Start and Search Settings ======================
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{18401191-9920-4692-8096-1EA7F09EA828} Yahoo//search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=512435&p={searchTerms}"
==== EOF on pet 26.07.2013 at 10:47:22,29 ======================
Dopuna: 26 Jul 2013 14:07
Greška ovo je isti sadržaj sad ću vam dati pravi.
Dopuna: 26 Jul 2013 14:19
Kad mi se restartovao kompjuter dobio sam dve datoteke pod imenom folders i files. Evo sadržaja
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
|
|
|
|
Poslao: 26 Jul 2013 14:21
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Pogledaj na C:\zoek-results.log
|
|
|
|
Poslao: 26 Jul 2013 14:42
|
offline
- Mare Ivanović
- Ugledni građanin
- Pridružio: 30 Maj 2013
- Poruke: 425
- Gde živiš: U kući
|
Napisano: 26 Jul 2013 14:41
Zoek.exe Version 4.0.0.4 Updated 21-07-2013
Tool run by Home on pet 26.07.2013 at 14:06:21,05.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Home\Desktop\zoek.exe [Script inserted]
==== System Restore Info ======================
26.7.2013 14:08:05 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\94yugiu7.default\prefs.js:
user_pref("browser.startup.homepage", "www.google.rs");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.useDBForOrder", "false");
Added to C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\94yugiu7.default\prefs.js:
ProfilePath: C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\94yugiu7.default
user.js not found
---- Lines toolbar removed from prefs.js ----
---- Lines toolbar modified from prefs.js ----
---- FireFox user.js and prefs.js backups ----
prefs_26.07.2013_1410_.backup
==== Deleting Files \ Folders ======================
"C:\WINDOWS\Tasks\At*.job" not found
"C:\Program Files (x86)\TornTV.com" not found
"C:\Program Files (x86)\Industriya" not found
"C:\ProgramData\InstallMate\{A18F91AE-C21D-4A38-A8D3-8A3F7A6CB358}\Setup.exe" deleted
"C:\ProgramData\InstallMate\OptimizerPro\Setup.exe" deleted
"C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe" deleted
"C:\windows\SysNative\Tasks\EPUpdater" deleted
"C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\94yugiu7.default\searchplugins\ask-web-search.xml" deleted
"C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\94yugiu7.default\searchplugins\ask-web-search.xml" deleted
"C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe" deleted
"C:\Users\Home\AppData\Roaming\DRPSu" deleted
"C:\Program Files (x86)\Vittalia" deleted
"C:\Users\Home\AppData\Roaming\DRPSu" deleted
"C:\ProgramData\StarApp" deleted
"C:\ProgramData\BetterSoft" not deleted
"C:\ProgramData\InstallMate" deleted
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab" deleted
"C:\ProgramData\BetterSoft\OptimizerPro" not deleted
==== Firefox Extensions ======================
==== Firefox Plugins ======================
Profilepath: C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\94yugiu7.default
3D76B5C0E02ECC19C1F5756E8FD97F72 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll - Shockwave Flash
AE7B288233C212C62CD544BF768C45E6 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1203133.dll - Shockwave for Director / Shockwave for Director
2EE9DCAE1D70ABF4D058688DE35F8221 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.16
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
dhfcbmlocifngpbjdpgnkbjmgkadkjpp - C:\Program Files (x86)\Industriya\privitize\1.8.21.6\privitize.crx[]
nbmafkdmkkckhggblphicnnhlgljnoje - C:\Program Files (x86)\TornTV.com\torn2_10.crx[]
Google Docs - Home - default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Home - default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Home - default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Home - default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Slagalica fer igra - Ludara.com - Home - default\Extensions\ejpifakoabdhigpeebhalfkjkoidenba
Gmail - Home - default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{18401191-9920-4692-8096-1EA7F09EA828} Yahoo//search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=512435&p={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
==== Reset Google Chrome ======================
C:\users\Home\AppData\Local\Google\Chrome\User Data\default\Preferences was reset successfully
C:\users\Home\AppData\Local\Google\Chrome\User Data\default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\dhfcbmlocifngpbjdpgnkbjmgkadkjpp deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\users\Home\AppData\Local\Mozilla\Firefox\Profiles\94yugiu7.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\users\Home\AppData\Local\Google\Chrome\User Data\default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
Dopuna: 26 Jul 2013 14:42
Našao sam samo ovo.
|
|
|
|
|
|
Poslao: 26 Jul 2013 15:33
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Uradi update SpyBot-a, pokreni ga desni klik Run as Administrator, trebalo bi da obrise taj reg unos.
|
|
|
|