Ciscenje kompjutera od Adware

2

Ciscenje kompjutera od Adware

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

aha nasla sam i taj..Smile
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16428 BrowserJavaVersion: 10.45.2
Run by zora at 1:48:29 on 2013-11-14
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.46.1033.18.7862.4743 [GMT 1:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\SysWOW64\IoctlSvc.exe
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\SysWOW64\vmnat.exe
C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
C:\Windows\SysWOW64\vmnetdhcp.exe
C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\zora\AppData\Local\MediaFire Express\mf_systray.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Personal\bin\Personal.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\zora\AppData\Local\MediaFire Express\mf_daemon.exe
C:\Users\zora\AppData\Local\MediaFire Express\mf_status.exe
C:\Users\zora\AppData\Local\MediaFire Express\mf_services.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Users\zora\AppData\Local\Temp\tmpB615.exe
C:\Users\zora\AppData\Local\Temp\is-5L1PA.tmp\tmpB615.tmp
C:\Users\zora\AppData\Local\Temp\tmpB615.exe
C:\Users\zora\AppData\Local\Temp\is-855SM.tmp\tmpB615.tmp
C:\Windows\system32\prevhost.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\explorer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\AUDIODG.EXE
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Windows\system32\prevhost.exe
C:\Program Files\Tracker Software\PDF Viewer\PDFXCview.exe
C:\Windows\explorer.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
mWinlogon: Userinit = userinit.exe,
BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [MediaFire Tray] "C:\Users\zora\AppData\Local\MediaFire Express\mf_systray.exe" --boot-start
uRun: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
uRun: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
mRun: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
mRun: [EaseUS EPM tray] C:\Program Files (x86)\EaseUS\EaseUS Partition Master 9.2.2\bin\EpmNews.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BANKID~1.LNK - C:\Program Files (x86)\Personal\bin\Personal.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{0F74F4BA-550C-4BF7-9A46-7B7BBF04557D} : DHCPNameServer = 208.67.222.222 208.67.220.220
TCP: Interfaces\{B7B5A375-CE40-4677-93BB-45BD2ADEF0A6} : DHCPNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
AppInit_DLLs= c:\progra~2\sk-enh~1\psupport.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll
x64-BHO: YoutubeAdblocker: {50AEE663-1D30-B772-3D43-DADA24F0AE72} -
x64-BHO: SSurf and keep: {5FCDC77B-A242-98A6-2314-2B02787795C7} -
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\3ptp0kek.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Personal\bin\np_prsnl.dll
FF - plugin: C:\Program Files (x86)\Personal\bin\np_prsnl64.dll
FF - plugin: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll
FF - plugin: C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
FF - plugin: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
FF - ExtSQL: 2013-10-25 00:41; jid1-vW9nopuIAJiRHw@jetpack; C:\Users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\3ptp0kek.default\extensions\jid1-vW9nopuIAJiRHw@jetpack.xpi
FF - ExtSQL: 2013-11-01 19:56; helper@savefrom.net; C:\Users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\3ptp0kek.default\extensions\helper@savefrom.net.xpi
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-7 65336]
R0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-3-7 204880]
R0 vsock;vSockets Driver;C:\Windows\System32\drivers\vsock.sys [2013-11-7 73296]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-2-18 1030952]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-2-18 378944]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-2-18 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-2-18 80816]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-9-29 46808]
R2 Freemake Improver;Freemake Improver;C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2013-11-1 101888]
R2 IDMWFP;IDMWFP;C:\Windows\System32\drivers\idmwfp.sys [2011-11-14 145008]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-4-16 39056]
R2 VMUSBArbService;VMware USB Arbitration Service;C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2013-10-9 905272]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-2-17 676968]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2013-6-4 103448]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2013-11-8 111616]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 pwdrvio;pwdrvio;C:\Windows\System32\pwdrvio.sys [2013-10-25 19032]
S3 pwdspio;pwdspio;C:\Windows\System32\pwdspio.sys [2013-10-25 12384]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2013-2-20 31800]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2013-6-4 203672]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\System32\drivers\Synth3dVsc.sys [2010-11-21 88960]
S3 Tdsshbecr;Handelsbanken card reader;C:\Windows\System32\drivers\shbecr.sys [2008-9-23 50176]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\System32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;tsusbhub;C:\Windows\System32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-2-17 1255736]
S3 VBoxUSB;VirtualBox USB;C:\Windows\System32\drivers\VBoxUSB.sys [2012-12-19 106408]
.
=============== Created Last 30 ================
.
2013-11-13 12:19:29 75888 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8ED88597-478C-4B8F-B0BE-F83E1024C726}\offreg.dll
2013-11-13 11:32:44 -------- d-----w- C:\ProgramData\boost_interprocess
2013-11-13 11:32:19 -------- d-sh--w- C:\$RECYCLE.BIN
2013-11-13 11:23:38 24064 ----a-w- C:\Windows\zoek-delete.exe
2013-11-13 11:23:38 -------- d-----w- C:\Users\zora\AppData\Local\Temp
2013-11-12 15:49:33 10280728 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8ED88597-478C-4B8F-B0BE-F83E1024C726}\mpengine.dll
2013-11-11 19:03:51 127488 ----a-w- C:\Windows\System32\ff_vfw.dll
2013-11-11 19:03:50 -------- d-----w- C:\Program Files\ffdshow
2013-11-11 18:56:14 696832 ----a-w- C:\Windows\System32\xvidcore.dll
2013-11-11 18:56:14 645632 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2013-11-11 18:56:14 255488 ----a-w- C:\Windows\System32\xvidvfw.dll
2013-11-11 18:56:14 240640 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2013-11-11 18:56:14 173568 ----a-w- C:\Windows\System32\xvid.ax
2013-11-11 18:56:14 153088 ----a-w- C:\Windows\SysWow64\xvid.ax
2013-11-11 18:56:14 -------- d-----w- C:\Program Files (x86)\Xvid
2013-11-11 18:02:29 -------- d-----w- C:\zoek_backup
2013-11-09 10:50:55 -------- d-----w- C:\boilsoft_tmp
2013-11-08 16:40:40 86016 ----a-w- C:\Windows\unvise32.exe
2013-11-08 16:40:39 -------- d-----w- C:\Program Files (x86)\DivXLand
2013-11-07 15:19:30 -------- d-----w- C:\Users\zora\AppData\Local\VMware
2013-11-07 15:18:33 73296 ----a-w- C:\Windows\System32\drivers\vsock.sys
2013-11-07 15:18:33 67664 ----a-w- C:\Windows\System32\vsocklib.dll
2013-11-07 15:18:33 63568 ----a-w- C:\Windows\SysWow64\vsocklib.dll
2013-11-07 15:18:31 64080 ----a-w- C:\Windows\System32\drivers\vmx86.sys
2013-11-07 15:18:30 32848 ----a-w- C:\Windows\System32\drivers\VMkbd.sys
2013-11-07 15:18:29 31824 ----a-w- C:\Windows\System32\drivers\VMparport.sys
2013-11-07 15:17:56 358480 ----a-w- C:\Windows\SysWow64\vmnetdhcp.exe
2013-11-07 15:17:54 437328 ----a-w- C:\Windows\SysWow64\vmnat.exe
2013-11-07 15:17:52 30800 ----a-w- C:\Windows\System32\drivers\vmnetuserif.sys
2013-11-07 15:17:45 930384 ----a-w- C:\Windows\System32\vnetlib64.dll
2013-11-07 15:17:41 53816 ----a-w- C:\Windows\System32\drivers\hcmon.sys
2013-11-07 15:17:35 -------- d-----w- C:\Program Files\Common Files\VMware
2013-11-07 15:17:25 -------- d-----w- C:\Program Files (x86)\VMware
2013-11-07 15:17:25 -------- d-----w- C:\Program Files (x86)\Common Files\VMware
2013-11-07 15:09:34 -------- d-----w- C:\ProgramData\VMware
2013-11-04 22:22:31 -------- d-----w- C:\AdwCleaner
2013-11-01 19:06:14 -------- d-----w- C:\Users\zora\AppData\Local\FreemakeVideoConverter
2013-10-31 13:41:07 -------- d-----w- C:\Program Files (x86)\Britannica 11.0
2013-10-31 12:42:33 -------- d--h--w- C:\Program Files (x86)\Zero G Registry
2013-10-31 12:42:33 -------- d-----w- C:\Program Files (x86)\Britannica 9.0
2013-10-31 12:29:03 -------- d--h--w- C:\Users\zora\InstallAnywhere
2013-10-25 20:30:59 -------- d-----w- C:\Program Files (x86)\MiniTool Partition Wizard Professional Edition 7.5
2013-10-25 14:45:00 2966720 ----a-w- C:\Windows\System32\pwNative.exe
2013-10-25 14:44:59 19032 ------w- C:\Windows\System32\pwdrvio.sys
2013-10-25 14:44:59 12384 ------w- C:\Windows\System32\pwdspio.sys
2013-10-25 12:08:32 -------- d-----w- C:\ProgramData\Oracle
2013-10-25 12:08:18 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-24 20:16:56 -------- d-----w- C:\Program Files (x86)\EaseUS
2013-10-24 09:12:53 -------- d-----w- C:\Program Files (x86)\GlobFX
2013-10-23 14:48:00 -------- d-----w- C:\Users\zora\AppData\Local\DriverTuner
2013-10-19 10:25:26 -------- d-----w- C:\Users\zora\AppData\Local\Microsoft Games
2013-10-18 11:44:58 80464 ----a-w- C:\Windows\System32\vmnetbridge.dll
2013-10-18 11:44:58 49232 ----a-w- C:\Windows\System32\vnetinst.dll
2013-10-18 11:44:58 46160 ----a-w- C:\Windows\System32\drivers\vmnetbridge.sys
2013-10-18 11:44:58 24656 ----a-w- C:\Windows\System32\drivers\vmnet.sys
2013-10-18 11:44:58 20560 ----a-w- C:\Windows\System32\drivers\vmnetadapter.sys
2013-10-17 02:30:30 -------- d-----w- C:\Windows\System32\appmgmt
.
==================== Find3M ====================
.
2013-10-08 23:10:06 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-08 23:10:06 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-10-08 17:21:06 85584 ----a-w- C:\Windows\System32\drivers\vmci.sys
2013-09-14 01:10:19 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2013-09-08 02:30:37 1903552 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-09-08 02:27:14 327168 ----a-w- C:\Windows\System32\mswsock.dll
2013-09-08 02:03:58 231424 ----a-w- C:\Windows\SysWow64\mswsock.dll
2013-09-04 12:12:11 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2013-09-04 12:11:51 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2013-09-04 12:11:49 99840 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2013-09-04 12:11:43 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2013-09-04 12:11:43 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2013-09-04 12:11:42 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2013-09-04 12:11:40 7808 ----a-w- C:\Windows\System32\drivers\usbd.sys
2013-09-03 12:35:10 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-08-30 07:48:10 72016 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-08-30 07:48:10 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-08-30 07:48:10 204880 ----a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-08-30 07:48:10 1030952 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-08-30 07:48:09 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-08-30 07:47:40 41664 ----a-w- C:\Windows\avastSS.scr
2013-08-29 02:17:48 5549504 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-08-29 02:16:35 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-08-29 02:16:28 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-08-29 02:16:14 859648 ----a-w- C:\Windows\System32\tdh.dll
2013-08-29 02:13:28 878080 ----a-w- C:\Windows\System32\advapi32.dll
2013-08-29 01:51:45 3969472 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-08-29 01:51:45 3914176 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-08-29 01:50:31 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-08-29 01:50:30 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-08-29 01:50:16 619520 ----a-w- C:\Windows\SysWow64\tdh.dll
2013-08-29 01:48:17 640512 ----a-w- C:\Windows\SysWow64\advapi32.dll
2013-08-29 01:48:15 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2013-08-29 00:49:53 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-08-29 00:49:52 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-08-29 00:49:52 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-08-29 00:49:49 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-08-28 01:21:06 3155968 ----a-w- C:\Windows\System32\win32k.sys
2013-08-28 01:12:33 461312 ----a-w- C:\Windows\System32\scavengeui.dll
.
============= FINISH: 1:48:54,46 ===============

offline
  • Pridružio: 04 Jul 2011
  • Poruke: 5424

Arrow Ponovo pokreni zoek ;


zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;


U beli okvir prozora iskopiraj sledeći tekst:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows];r
"AppInit_DLLs"="";r
{50AEE663-1D30-B772-3D43-DADA24F0AE72};c
{5FCDC77B-A242-98A6-2314-2B02787795C7};c
autoclean;




Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

Napisano: 15 Nov 2013 1:30

Zoek.exe Version 4.0.0.5 Updated 14-November-2013
Tool run by zora on 2013-11-15 at 1:13:30,72.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\zora\Desktop\zoek.com [Script inserted]

==== Older Logs ======================

C:\zoek-results2013-11-11-180511.log 40563 bytes
C:\zoek-results2013-11-13-113214.log 17042 bytes

==== Deleting CLSID Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{50AEE663-1D30-B772-3D43-DADA24F0AE72} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{50AEE663-1D30-B772-3D43-DADA24F0AE72} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50AEE663-1D30-B772-3D43-DADA24F0AE72} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5FCDC77B-A242-98A6-2314-2B02787795C7} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{5FCDC77B-A242-98A6-2314-2B02787795C7} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5FCDC77B-A242-98A6-2314-2B02787795C7} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

==== Deleting Files \ Folders ======================

C:\ProgramData\boost_interprocess deleted
C:\Users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\3ptp0kek.default\extensions\staged deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"fmconverter@gmail.com"="C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox" [2013-11-01 19:56]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"mozilla_cc@internetdownloadmanager.com"="C:\Users\zora\AppData\Roaming\IDM\idmmzcc5" [2013-02-19 02:49]

==== Firefox Extensions ======================

ProfilePath: C:\Users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\3ptp0kek.default
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- LastPass - %ProfilePath%\extensions\support@lastpass.com
- SaveFrom.net asistan - %ProfilePath%\extensions\helper@savefrom.net.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\3ptp0kek.default
4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash
A64F2C388DC26BE3E469EDC3657B14F4 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit)
C45F7E59F2A0A6D3C4E90117F4752414 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit)
F7AEAD4303A056F2D1685B43024776CA - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit)
FA0A3008589567CB7196620B05C9F28D - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin
ACE30EDECDF6B258DB3609F10DB7882C - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll - PDF-XChange Viewer


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[2013-04-16 02:11]
jbolfgndggfhhpbnkgnpjkfhinclbigj - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx[2013-10-24 10:37]

LastPass - zora - Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd
RealDownloader - zora - Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
Freemake Video Converter - zora - Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\zora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\zora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0S8BERS6 will be deleted at reboot
C:\Users\zora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\264JAXTD will be deleted at reboot
C:\Users\zora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NM59ZHG3 will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\zora\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\zora\AppData\Local\Google\Chrome\User Data\Default\Application Cache\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\zora\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\zora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0S8BERS6" not found
"C:\Users\zora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\264JAXTD" not found
"C:\Users\zora\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NM59ZHG3" not found

==== EOF on 2013-11-15 at 1:22:59,75 ======================
evo opet , sve sam isto uradila ali sada prije reboota pojavila mi se poruka da zoek nije kompatibilan i da mozda nije dobro instaliran..
a odradio je posao i ne razumem zasto sad ta poruka a nije pre 2 dana a isti program sam pokrenula..
svaka vam cast i hvala s ovim se muciti..

Dopuna: 15 Nov 2013 1:32

da, obrisala sam stare logove od 11 i 13.
a sta cu s onim zoek bkp-om na CConfused

offline
  • Pridružio: 04 Jul 2011
  • Poruke: 5424

Arrow To bi bilo to, završili smo sa čišćenjem.



Arrow Preuzmi "Xplode"-ov DelFix i sačuvaj ga na Desktop

Dvoklikom pokreni program.

Štikliraj sledeće opcije:
Remove disinfection tools
Purge System Restore
Reset system settings


Klikni na dugme "Run" i pričekaj da program završi rad.
Alat ce ukloniti sve koriscene alate u ovoj temi...
Kada alat završi, otvoriće izvestaj u notepadu.
Napomena: Izvestaj ce takodje biti sacuvan na C:\DelFix.txt

Nije potrebno dostavljati izvestaj.




Idea Preporučujem ti da koristiš program MCShield za zaštitu USB memorijskih uređaja.

Program možeš preuzeti sa OVOG linka. Nakon instalacije programa, priključi USB memorijske uređaje, i oni će biti skenirani. Na kraju skeniranja ćeš dobiti izveštaj da je uređaj čist ili obaveštenje o uklonjenom malware-u.


Idea Takođe, poseti ovu temu da vidiš da li ti je pretraživač ranjiv i instaliraš ažurirane komponente
http://www.mycity.rs/Propusti-i-azuriranja/Testira.....anjiv.html




Ivance95 (AMF Tim)

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

Napisano: 15 Nov 2013 16:51

hvala Ivance, uradicu kako si rekao ako uspem otvoriti windows..
jutros u 1.30 uradila sam kako ste rekli sa zoekom, i poslala log zatvorila komp. ali microsoft je nesto azurirao i ja otisla na spavanje..kad sam ustala trebalo mi je brzo neki info o redu voznje..bila sam na putu za stockholm..windows se nije otvorio..prekidacem sam ugasila komp.jer nisam mogla vise cekati..
sada cu uskoro kuci..
pa cu opet videti sta se desava..
zadnje sto sam uradila dakle bio je zoek i poslala vam izvestaj..
javljam se za 3 sata..
pozdrav

Dopuna: 15 Nov 2013 21:13

ponovo sam kod kuce i u miru resavala 'ne-otvaranje' windowsa. Ponudjen mi je "Startup repair"
prihvatila sam --(jedino moguce).
nakon duze vremena zavrseno je i postojao je log.
pronasla sam tamo sledece:
Root cause found
ACLs on file Windows\system32\slui.exe are not proper
old value=oxfo1df
Neznam da li je nesto poremeceno zadnjim zahvatom zoek-a ili je Microsoft update uzrok mojih problema,
ja sam vratila na restore point prije microsoft update koji je odmah sledio nakon poslednjeg 'zoeg' zahvata i sad imam opet moj normalni ekran i w7.
Pitanje:
1.ako ne izvrsim ovaj poslednji od vas predlozeni postupak..koje su konzekvence?
(vidim da bi se izvrsio 'purge system restore' a ja jako trebam taj zadnji system restore nakon sto sam vama poslala log i prije nego je microsoft izvrsio kriticni update) Wink
2. ako iskljucim automatski update windowsa , moze li se dalje raditi svejedno..(izvinite mozda ovde nije pravo mesto da pitam...korigirati cu post ako treba).. Hvala!

offline
  • Pridružio: 04 Jul 2011
  • Poruke: 5424

Arrow Taj korak nije obavezan, samo olakšava posao, u principu možeš da obrišeš sve alate koje smo koristili, i to je to.


Arrow Nije preporučljivo isključivati Windows Update, tada će ti kompjuter biti ranjiv od strane malware-a. Da li je u pitanju legalna verzija ili ...? Ako je ova druga u pitanju tu ne mogu da ti pomognem, protiv pravila je. A ako je u pitanju legalna verzija možeš da otvoriš temu u Windows potforumu, kompjuter ti je čist što se malware-a tiče. Ako ti nešto oko procedure nije jasno pitaj slobodno, ali što se tiče tog problema obrati se u Windows potforum.




Ivance95 (AMF Tim)

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

Ziveli puno hvala na pomoci i zadnjem odgovoru.raduje me da nije obavezno.. Sve sada radi kako treba ,obrisacu rucno sve koristeno u ovoj operaciji i ubuduce cu biti jos malo vise oprezna.. Smile
inace cudne su to igre..zasto onda svi ti antimalware i antivirus programi ako trebam windows update da mi cuva komp. od ranjivosti..?
..ali ne moras mi odgovoriti na to jer ovde nije mesto tome.. Wink

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Citat:prekidacem sam ugasila komp.jer nisam mogla vise cekati..
sada cu uskoro kuci..


Zbog toga si morala da radis startup repair, to ne moj vise da radis.

Citat:zasto onda svi ti antimalware i antivirus programi ako trebam windows update da mi cuva komp. od ranjivosti..?

Kad imas vremena procitaj ovaj clanak pa ce ti biti jasnije.
http://www.mycity.rs/Zastita/Mali-recnik-zastite.html

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

'startup repair ' mi je ponudjen s komentarom..your computer couldn't start..a to je i bila istina..
naravno necu to raditi bez velike potrebe..i nisam trebala do sada..kad su se poklopili microsoft update i ciscenje kompjutera..
jos uvek mi je pomalo misticno zasto mu je trebalo tako dugo da se makne iz mracnog stanja..
sto znaci ona primedba u log-u ACLs...?
zapravo necu vise ni razmisljati o tome ali hvala na uputi da procitam ono na linku..Smile

Ko je trenutno na forumu
 

Ukupno su 1133 korisnika na forumu :: 44 registrovanih, 8 sakrivenih i 1081 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Acivi, Atomski čoban, babaroga, bojcistv, BORUTUS, BraneS, cenejac111, croato, DENIRO, Dogma21, dolinalima, DPera, Draganeli, dule10savic, Georgius, havoc995, hyla, Insan, kolle.the.kid, krkalon, Leonov, maiden6657, Mediator, Milometer, mnn2, moldway, naki011, nebkv, nenooo, nikoladim, procesor, raketaš, RJ, Romibrat, royst33, skvara, Srle993, stemark, Toper, uruk, wolf431, yrraf, YugoSlav, Zoca