offline
- Pridružio: 16 Avg 2007
- Poruke: 315
- Gde živiš: Srbija
|
Napisano: 07 Okt 2014 23:41
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.1 (10.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by Boban on Tue 10/07/2014 at 23:28:44.42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1582240820-2018686280-1996047769-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] "hkey_current_user\software\microsoft\internet explorer\low rights\elevationpolicy\{a5aa24ea-11b8-4113-95ae-9ed71deaf12a}"
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{52db1893-8a90-4192-aede-08e00b8f8473}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}
~~~ Files
Successfully deleted: [File] C:\Windows\System32\Tasks\Driver Booster SkipUAC (SYSTEM)
Successfully deleted: [File] "C:\Windows\launcher.exe"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Boban\AppData\Roaming\cleanmypc software"
Successfully deleted: [Folder] "C:\Users\Boban\AppData\Roaming\thinstall"
Successfully deleted: [Folder] "C:\Users\Boban\Local Settings\Application Data\thinstall"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Boban\AppData\Roaming\mozilla\firefox\profiles\rtc8ea7a.default-1381584217073\extensions\staged
Successfully deleted: [Folder] C:\Users\Boban\AppData\Roaming\mozilla\firefox\profiles\rtc8ea7a.default-1381584217073\extensions\{cc6cc772-f121-49e0-b1f0-c26583cb0c5e}
Successfully deleted the following from C:\Users\Boban\AppData\Roaming\mozilla\firefox\profiles\rtc8ea7a.default-1381584217073\prefs.js
user_pref("browser.search.useDBForOrder", false);
user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-
user_pref("extensions.aa338c5448f724f94af2f11cc4cdd6788a64e7ca7d83cb2cdcom63311.63311.cookie.testingGaq.value", "%22hxxp%3A//extclickmedia-maynemyltf.netdna-ssl.com/Extensions
user_pref("extensions.aa338c5448f724f94af2f11cc4cdd6788a64e7ca7d83cb2cdcom63311.63311.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A
user_pref("valueApps.autoDisableScopes", 0);
user_pref("valueApps.storage./9B+7E+x305", "2423");
user_pref("valueApps.storage./9B+7E,x305", "2423");
user_pref("valueApps.storage./9B+7E-x305", "2423");
user_pref("valueApps.storage./9B+7E.:2z527", "2423");
user_pref("valueApps.storage./9B+7E.x305", "2423");
user_pref("valueApps.storage./9B+7E/x305", "2423");
user_pref("valueApps.storage./9B+7E06CG5EL8:", "6E6D696A6F6B75767475");
user_pref("valueApps.storage./9B+7E06CG5EL;8I:K", "247E2D2F226A74736F7075717B7C7A7B242F4B49474F42357D5D5C3D");
user_pref("valueApps.storage./9B+7E0x305", "2423");
user_pref("valueApps.storage./9B+7E1x305", "2423");
user_pref("valueApps.storage./9B+7E2x305", "2423");
user_pref("valueApps.storage./9B+7E3x305", "2423");
user_pref("valueApps.storage./9B+7E4x305", "2423");
user_pref("valueApps.storage./9B+7E5x305", "2423");
user_pref("valueApps.storage./9B+7E6x305", "2423");
user_pref("valueApps.storage./9B+7E7x305", "2423");
user_pref("valueApps.storage./9B+7E8x305", "2423");
user_pref("valueApps.storage./9B+7E9x305", "2423");
user_pref("valueApps.storage./9B+7E:x305", "2423");
user_pref("valueApps.storage./9B+7E;x305", "2423");
user_pref("valueApps.storage./9B+7E<x305", "2423");
user_pref("valueApps.storage./9B+7E=x305", "2423");
user_pref("valueApps.storage./9B+7E>x305", "2423");
user_pref("valueApps.storage./9B+7E?x305", "2423");
user_pref("valueApps.storage./9B+7E@x305", "2423");
user_pref("valueApps.storage./9B+7EAx305", "2423");
user_pref("valueApps.storage./9B+7EBE3G=;D9N9=D", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D337D56545138505C");
user_pref("valueApps.storage./9B+7EBx305", "2423");
user_pref("valueApps.storage./9B+7ECx305", "2423");
user_pref("valueApps.storage./9B+7EDx305", "2423");
user_pref("valueApps.storage./9B+7Etx305", "2423");
user_pref("valueApps.storage./9B-0?3G>D", "3C3D6E6E407142407A72457A762048487A21257B7C53532A5528572659292E2E592D2B32");
user_pref("valueApps.storage./9B-0?3G@6:5;", "");
user_pref("valueApps.storage./9B-0?3GFA7EF", "2B2E2C3D");
user_pref("valueApps.storage./9B-3=3ECCJA=F>", "247E333D2C452F4135276F297B7E7D21202F26313E4249357D37382F3A494D5D513F283338435D6554695B65546D57695D5D686365533C70766C66755E");
user_pref("valueApps.storage./9B/>01=9A6K6<IM;KRIE@PDAWM", "6E6A68707374757677");
user_pref("valueApps.storage./9B3=>@44I48?", "372C2D3269757633423633414847203E3D474E4D4C45474F2A554A4D2D5858585E4B554E366352564F");
user_pref("valueApps.storage./9B5BA==9CJAG", "3C686B6C70723F457A4447487476494B764F4C7D50");
user_pref("valueApps.storage./9B6B11G4C56B>F;P;ANR@P", "6E6D696A6F6B75767475797676");
user_pref("valueApps.storage./9B90E@.3C;7B=?OFB>>RHIQS", "393F352F3E");
user_pref("valueApps.storage./9B9643G3/9E", "6A");
user_pref("valueApps.storage./9B;45>:BI9I7IE", "2B2E2C3D");
user_pref("valueApps.storage./9B<:222H64<", "393F352F3E");
user_pref("valueApps.storage./9B<:222H64<L8DAJ", "6D70706F7673737974772A797A72797E757D7E");
user_pref("valueApps.storage./9B=+03EH8H8J?:", "4443");
user_pref("valueApps.storage./9B?+E2A52D8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
user_pref("valueApps.storage./9B?B0D:8AJ62<H", "6D");
user_pref("valueApps.storage./9BA@0<0BI6A7GN:6@L?", "6C");
user_pref("valueApps.storage.PG_ENABLE", "74727565");
user_pref("valueApps.storage._key_cl_active", "63653430353161372D373937652D346238632D393965642D656463336236663263633534");
user_pref("valueApps.storage.cbfirsttime", "5475652044656320333120323031332031323A34303A333320474D542B30313030202843656E7472616C204575726F7065205374616E646172642054696D6529");
user_pref("valueApps.storage.mam_gk_appStateReportTime", "31333838343930303330343935");
user_pref("valueApps.storage.mam_gk_appState_Clarity_Active", "6F6E");
user_pref("valueApps.storage.mam_gk_appsConfig", "7B2241707073436F6E66696775726174696F6E223A5B7B226964223A22436C61726974795F416374697665222C2275726C223A22687474703A2F2F73746F7
user_pref("valueApps.storage.mam_gk_appsDefaultEnabled", "74727565");
user_pref("valueApps.storage.mam_gk_calledSetupService", "31");
user_pref("valueApps.storage.mam_gk_currentVersion", "312E31322E302E35");
user_pref("valueApps.storage.mam_gk_first_time", "31");
user_pref("valueApps.storage.mam_gk_lastLoginTime", "31333838343930303330383439");
user_pref("valueApps.storage.mam_gk_localization", "7B226469616C6F674F4B223A7B2254657874223A224F4B227D2C22646D626F7831223A7B2254657874223A224465616C5C725C6E6F66207468652064617
user_pref("valueApps.storage.mam_gk_mamEnabled", "74727565");
user_pref("valueApps.storage.mam_gk_settings1.12.0.5", "7B22537461747573223A22737563636565646564222C2244617461223A7B2263757272656E7444617465223A223230313331323331222C22696E746
user_pref("valueApps.storage.mam_gk_showWelcomeGadget", "66616C7365");
user_pref("valueApps.storage.mam_gk_stamp", "35345F30");
user_pref("valueApps.storage.mam_gk_userId", "34363537303838652D316234362D346666612D393566352D306337653235653261336461");
user_pref("valueApps.storage.mam_gk_user_approval_interacted", "");
Emptied folder: C:\Users\Boban\AppData\Roaming\mozilla\firefox\profiles\rtc8ea7a.default-1381584217073\minidumps [73 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Boban\appdata\local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 10/07/2014 at 23:30:32.11
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Dopuna: 07 Okt 2014 23:44
[Link mogu videti samo ulogovani korisnici]
Dopuna: 07 Okt 2014 23:45
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
Dopuna: 07 Okt 2014 23:47
napomena
ESET Antivirus License nisam nasao u control panelu da ga reinstaliram kao ni keylogger, pa sam nesto rucno brisao,
|