racunar vrlo spor

1

racunar vrlo spor

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

treci put se obracam slicnim povodom iprethodna dva puta je bilo u redu ali posle izvesnog vremena racunar uspori i jedva otvara foldere a da otvori pretrazivac treba mu 2-3 minuta a uz to prilikom skidanja igricDDS (Ver_2012-11-20.01) - NTFS_x86 i nekih programa nakace mi se neki tolbarovi na pretrazivace koje ne znam da skinem a koji verovatno smetaju
Internet Explorer: 8.0.6001.18702
Run by digital at 18:18:58 on 2014-02-12
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.155 [GMT 1:00]
.
AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Disabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\runservice.exe
C:\Program Files\Mobogenie\MgAssist.exe
C:\Program Files\Mobogenie\DaemonProcess.exe
C:\PROGRA~1\SearchProtect\Main\bin\CltMngSvc.exe
C:\PROGRA~1\SearchProtect\SearchProtect\bin\cltmng.exe
C:\PROGRA~1\SearchProtect\UI\bin\cltmngui.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\TP-LINK\TP-LINK 54M Wireless Client Utility\TWCU.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\BitLord 2\Bitlord files\bitlord.exe
C:\Program Files\BitLord 2\Bitlord files\bitlord.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com/?ctid=CT3319597&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP69E2F616-83EF-41D2-AB8F-62323583425C&SSPV=
uSearch Bar = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=66022
uInternet Connection Wizard,ShellNext = iexplore
mSearchAssistant = hxxp://www.crawler.com/search/ie.aspx?tb_id=66022
mCustomizeSearch = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=66022
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: SiteFinder: {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - c:\program files\sitefinder\SiteFinder.dll
BHO: FastestTube: {3E532CE8-C6D9-4A10-8ACE-4348C96E8B6A} - c:\program files\fastesttube\2.1.9\WombatBHO.dll
TB: SiteFinder: {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - c:\program files\sitefinder\SiteFinder.dll
EB: SiteFinder: {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - c:\program files\sitefinder\SiteFinder.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [NextLive] c:\windows\system32\rundll32.exe "c:\documents and settings\digital\application data\newnext.me\nengine.dll",EntryPoint -m l
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: [TWCU] "c:\program files\tp-link\tp-link 54m wireless client utility\TWCU.exe" -nogui
mRun: [AVG_UI] "c:\program files\avg\avg2014\avgui.exe" /TRAYONLY
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [mobilegeni daemon] c:\program files\mobogenie\DaemonProcess.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D} - {CCC7B151-1D8C-11E3-B2AD-F3EF3D58318D} - c:\program files\sitefinder\SiteFinder.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
TCP: NameServer = 10.0.0.1 87.250.98.250 87.250.97.250
TCP: Interfaces\{05F2CDEC-E13B-4347-9AC3-5465F5FCC2C3} : DHCPNameServer = 10.0.0.1 87.250.98.250 87.250.97.250
TCP: Interfaces\{9367FD5D-2693-4233-A7CC-895777A2D734} : NameServer = 91.191.59.118 87.250.98.250
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs= c:\progra~1\searchprotect\searchprotect\bin\spvc32loader.dll c:\docume~1\alluse~1\applic~1\wincert\win32c~1.dll c:\progra~1\movies~1\datamngr\mgrldr.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 nwprovau
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\32.0.1700.107\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
IFEO: bitguard.exe - tasklist.exe
IFEO: bprotect.exe - tasklist.exe
IFEO: bpsvc.exe - tasklist.exe
IFEO: browserdefender.exe - tasklist.exe
IFEO: browserprotect.exe - tasklist.exe
.
Note: multiple IFEO entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\digital\application data\mozilla\firefox\profiles\g2zdq4un.default-1366142093421\
FF - prefs.js: browser.startup.homepage - hxxp://home.tb.ask.com/index.jhtml?ptb=745D17A3-D848-4848-8085-A3F2B7F39B1B&n=780b8595&p2=^ZR^xpt372^YYA^ba&si=installldownload
FF - prefs.js: keyword.URL - hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=745D17A3-D848-4848-8085-A3F2B7F39B1B&n=780b8595&ind=2014021013&p2=^ZR^xpt372^YYA^ba&si=installldownload&searchfor=
FF - plugin: c:\documents and settings\digital\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\games\greenwebplayer\npgreenwebplayer.dll
FF - plugin: c:\program files\google\update\1.3.22.5\npGoogleUpdate3.dll
FF - plugin: c:\program files\popularscreensavers\NPp5Stub.dll
FF - plugin: c:\program files\popularscreensavers_7i\bar\2.bin\NP7iStub.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1205146.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_12_0_0_43.dll
FF - ExtSQL: 2014-01-29 18:40; {96f454ea-9d38-474f-b504-56193e00c1a5}; c:\documents and settings\digital\application data\mozilla\firefox\profiles\g2zdq4un.default-1366142093421\extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}
FF - ExtSQL: 2014-02-01 19:58; {94cd2cc3-083f-49ba-a218-4cda4b4829fd}; c:\documents and settings\digital\application data\mozilla\firefox\profiles\g2zdq4un.default-1366142093421\extensions\{94cd2cc3-083f-49ba-a218-4cda4b4829fd}
FF - ExtSQL: 2014-02-10 13:06; 7iffxtbr@PopularScreensavers_7i.com; c:\documents and settings\digital\application data\mozilla\firefox\profiles\g2zdq4un.default-1366142093421\extensions\7iffxtbr@PopularScreensavers_7i.com
FF - ExtSQL: 2014-02-12 17:23; sitefinder@sitefinder.com; c:\documents and settings\digital\application data\mozilla\firefox\profiles\g2zdq4un.default-1366142093421\extensions\sitefinder@sitefinder.com
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2013-7-20 147768]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2013-7-20 222520]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2013-7-1 102712]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2013-7-10 27448]
R1 Avgdiskx;AVG Disk Driver;c:\windows\system32\drivers\avgdiskx.sys [2013-8-1 120600]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2013-7-20 209176]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2013-3-1 22840]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2013-7-20 176952]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2013-3-21 193848]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-9-2 37664]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2012/02/09 12:22:29];c:\program files\cyberlink\powerdvd9\000.fcl [2009-5-7 87536]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2012-2-9 1287296]
.
=============== Created Last 30 ================
.
2014-02-12 16:21:14 -------- d-----w- c:\program files\SimilarSites
2014-02-12 16:21:13 -------- d-----w- c:\documents and settings\digital\application data\SiteFinder
2014-02-12 16:20:45 -------- d-----w- c:\program files\SiteFinder
2014-02-12 16:20:32 -------- d-----w- c:\documents and settings\digital\application data\SimilarSites
2014-02-11 19:35:25 -------- d-----w- c:\documents and settings\digital\local settings\application data\CrashRpt
2014-02-11 19:34:22 -------- d-----w- c:\documents and settings\all users\application data\Allmyapps
2014-02-11 19:21:02 -------- d-----w- c:\program files\Systweak Support Dock
2014-02-10 12:15:35 39464 ----a-w- c:\windows\system32\p5PSSavr.scr
2014-02-10 12:15:34 31456 ----a-w- c:\program files\mozilla firefox\plugins\NPp5Stub.dll
2014-02-10 12:15:29 -------- d-----w- c:\program files\PopularScreensavers
2014-02-10 12:11:57 -------- d-----w- c:\program files\PopularScreensavers_7i
2014-02-01 19:19:31 -------- d-----w- c:\documents and settings\digital\application data\Python-Eggs
2014-02-01 19:17:40 -------- d-----w- c:\documents and settings\digital\application data\BitLord
2014-02-01 19:12:03 -------- d-----w- c:\program files\BitLord 2
2014-02-01 19:00:00 -------- d-----w- c:\program files\SearchProtect
2014-02-01 19:00:00 -------- d-----w- c:\documents and settings\digital\local settings\application data\SearchProtect
2014-02-01 17:41:19 -------- d-----w- c:\program files\MotoGP2 Demo
2014-02-01 17:28:53 -------- d-----w- c:\program files\GameTop.com
2014-01-31 16:57:14 -------- d-----w- c:\documents and settings\digital\application data\systweak
2014-01-31 16:57:10 -------- d-----w- c:\program files\RegClean Pro
2014-01-29 18:42:16 -------- d-----w- c:\documents and settings\digital\local settings\application data\Electronic_Arts_Inc
2014-01-26 15:52:14 -------- d-----w- c:\documents and settings\all users\application data\Electronic Arts
2014-01-26 15:42:49 -------- d-----w- c:\documents and settings\digital\application data\uTorrent
2014-01-24 17:28:02 -------- d-----w- C:\GAMMES.LIO
2014-01-19 12:27:13 -------- d-----w- c:\documents and settings\digital\SyncFolder
2014-01-16 18:03:17 -------- d-----w- c:\documents and settings\all users\application data\Wincert
2014-01-16 18:02:58 -------- d-----w- c:\documents and settings\digital\application data\speedtest4354
2014-01-16 18:02:45 -------- d-----w- c:\documents and settings\digital\application data\PerformerSoft
2014-01-16 18:02:26 18776 ----a-w- c:\windows\system32\roboot.exe
2014-01-16 18:01:02 -------- d-----w- c:\documents and settings\digital\application data\freegames111
2014-01-16 18:00:48 -------- d-----w- c:\program files\Movies Toolbar
2014-01-16 18:00:34 -------- d-----w- c:\documents and settings\all users\application data\Datamngr
2014-01-16 17:58:07 -------- d-----w- c:\documents and settings\digital\local settings\application data\iLivid
.
==================== Find3M ====================
.
2014-02-12 11:40:27 1401 --sha-w- c:\windows\system32\mmf.sys
2014-01-29 12:21:32 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-01-29 12:21:29 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-24 17:35:59 21840 ----atw- c:\windows\system32\SIntfNT.dll
2014-01-24 17:35:59 17212 ----atw- c:\windows\system32\SIntf32.dll
2014-01-24 17:35:58 12067 ----atw- c:\windows\system32\SIntf16.dll
2013-12-21 10:39:16 48640 ----a-w- c:\windows\mmfs.dll
2013-12-21 10:39:16 249856 ----a-w- c:\windows\lcmmfu.cpl
2013-12-21 10:39:16 16384 ----a-w- c:\windows\runservice.exe
2013-12-21 09:45:45 418480 ----a-w- c:\windows\system32\wrap_oal.dll
2013-12-21 09:45:45 115432 ----a-w- c:\windows\system32\OpenAL32.dll
2013-12-10 15:59:41 719238 ----a-w- c:\windows\Counter Strike 1.6 Reloaded Uninstaller.exe
2013-11-27 20:21:06 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
.
============= FINISH: 18:26:15,54 ===============a
mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pozdrav.


Preuzmi "Xplode"-ov AdwCleaner () i sacuvaj ga na Desktop

Dvoklikom pokreni program.
Klikni na dugme [Scan] i pricekaj da program zavrsi.
Klikni na dugme [Clean]
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok


Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S0].txt






************ Sledece ***************







Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog ili ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...


U beli okvir prozora iskopiraj sledeći tekst:


filesrcm;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;


Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

Napisano: 12 Feb 2014 21:06

# AdwCleaner v3.018 - Report created 12/02/2014 at 20:08:47
# Updated 28/01/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : digital - DIGITAL-1765423
# Running from : C:\Documents and Settings\digital\My Documents\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : CltMngSvc

***** [ Files / Folders ] *****

[!] Folder Deleted : C:\Program Files\BitLord 2
Folder Deleted : C:\Program Files\Movies Toolbar
Folder Deleted : C:\Program Files\MyPC Backup
Folder Deleted : C:\Program Files\PopularScreensavers
Folder Deleted : C:\Program Files\RegClean Pro
Folder Deleted : C:\Program Files\Searchprotect
Folder Deleted : C:\Program Files\SimilarSites
Folder Deleted : C:\Documents and Settings\LocalService\Local Settings\Application Data\Searchprotect
Folder Deleted : C:\Documents and Settings\digital\Local Settings\Application Data\Ilivid
Folder Deleted : C:\Documents and Settings\digital\Local Settings\Application Data\Searchprotect
Folder Deleted : C:\DOCUME~1\digital\LOCALS~1\Temp\CT3289075
Folder Deleted : C:\Documents and Settings\digital\Application Data\BitLord
Folder Deleted : C:\Documents and Settings\digital\Application Data\OpenCandy
Folder Deleted : C:\Documents and Settings\digital\Application Data\PerformerSoft
Folder Deleted : C:\Documents and Settings\digital\Application Data\SimilarSites
Folder Deleted : C:\Documents and Settings\digital\Application Data\Systweak
Folder Deleted : C:\Documents and Settings\digital\Start Menu\Programs\BitLord
Folder Deleted : C:\Documents and Settings\digital\My Documents\BitLord
Folder Deleted : C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421\CT3289075
Folder Deleted : C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421\Extensions\{94CD2CC3-083F-49BA-A218-4CDA4B4829FD}
Folder Deleted : C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421\Extensions\7iffxtbr@PopularScreensavers_7i.com
Folder Deleted : C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421\Extensions\{96f454ea-9d38-474f-b504-56193e00c1a5}
File Deleted : C:\END
File Deleted : C:\Documents and Settings\All Users\Desktop\iLivid.lnk
File Deleted : C:\WINDOWS\system32\p5PSSavr.scr
File Deleted : C:\WINDOWS\system32\roboot.exe
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\Ask.xml
File Deleted : C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421\searchplugins\ask-web-search.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6FB5B50A-863D-4C0D-8E84-92A59565D087}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C39937A0-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C39937A9-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD55C1D4-CE89-4E93-866E-3F4A4962BD68}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A73204A3-4E2A-4924-95DA-D5DF58717368}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B5DB5A94-1E55-4E2E-AA50-49C8C8215D56}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C39937A7-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B2E5F9A4-0587-4525-8602-E08E32510243}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C39937A5-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C39937A9-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD55C1D4-CE89-4E93-866E-3F4A4962BD68}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8798BBE7-DDF6-448B-AE0E-83C9E28A5598}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F37BCE7B-6055-418C-A301-E715F36F1E79}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files\BitLord 2\Bitlord files\bitlord.exe]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\smartbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\PopularScreensavers
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RegClean Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Wincert\WIN32C~1.DLL
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~1\MOVIES~1\Datamngr\mgrldr.dll

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [CustomizeSearch]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]

-\\ Mozilla Firefox v

[ File : C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421\prefs.js ]

Line Deleted : user_pref("CT3289075.FF19Solved", "true");
Line Deleted : user_pref("CT3289075.UserID", "UN33237022741450931");
Line Deleted : user_pref("CT3289075.fullUserID", "UN33237022741450931.IN.20140126165249");
Line Deleted : user_pref("CT3289075.installDate", "26/01/2014 16:53:09");
Line Deleted : user_pref("CT3289075.installSessionId", "{251EFBA4-BDEA-4F70-8D1B-921104F1CD45}");
Line Deleted : user_pref("CT3289075.installSp", "false");
Line Deleted : user_pref("CT3289075.installUsage", "29/01/2014 18:40:27");
Line Deleted : user_pref("CT3289075.installUsageEarly", "29/01/2014 18:40:27");
Line Deleted : user_pref("CT3289075.installerVersion", "1.8.1.4");
Line Deleted : user_pref("CT3289075.searchRevert", "false");
Line Deleted : user_pref("CT3289075.searchUninstallUserMode", "1");
Line Deleted : user_pref("CT3289075.searchUserMode", "1");
Line Deleted : user_pref("CT3289075.toolbarInstallDate", "26-01-2014 16:52:50");
Line Deleted : user_pref("CT3289075.versionFromInstaller", "10.23.0.722");
Line Deleted : user_pref("CT3289075.xpeMode", "1");
Line Deleted : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3319597&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP69E2F616-83EF-41D2-AB8F-62323583425C");
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=745D17A3-D848-4848-8085-A3F2B7F39B1B&n=780b8595&p2=^ZR^xpt372^YYA^ba&si=installldownload");
Line Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Deleted : user_pref("extensions.mywebsearch.prevKwdURL", "hxxp://dts.search.ask.com/sr?src=ffb&gct=ds&appid=420&systemid=406&v=n11099-229&apn_dtid=BND406&apn_ptnrs=AG6&apn_uid=0501233951654031&o=APN10645&q=");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.BUTTON_STRUCTURE", "[{\"b\":220453304,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":220453305,\"c\":\"mindspark.entersearchterms\",\"p\":\"L.0.0[...]
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.browser.startup.homepage.prev", "hxxp://www.search.ask.com/?o=APN10645A&gct=hp&d=406-420&v=n11099-229&t=4");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.browser.startup.homepage.savedPrev", "true");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.browser.startup.homepage.tb", "hxxp://home.tb.ask.com/index.jhtml?ptb=745D17A3-D848-4848-8085-A3F2B7F39B1B&n=780b8595&p2=^ZR^xpt372^YYA^ba&si=instal[...]
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.browser.startup.page.savedPrev", 1);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.browser.startup.page.tb", 1);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.firstKnownVersion", "5.75.3.8667");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=745D17A3-D848-4848-8085-A3F2B7F39B1B&n=780b8595&p2=^ZR^xpt372^YYA^ba&si=installldownload");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.hp.lastGuardTime", 657618716);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.hp.numGuards", 1);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.initialized", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installKeysSource", "File");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.contextKey", "");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.installDate", "2014021013");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.partnerId", "^ZR^xpt372^YYA^ba");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.partnerSubId", "installldownload");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.success", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.toolbarId", "745D17A3-D848-4848-8085-A3F2B7F39B1B");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.isCompliantUninstallImplementation", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.lastActivePing", "1392222256262");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.lastKnownVersion", "5.75.3.8667");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.options.defaultSearch", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.options.homePageEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.options.keywordEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.options.tabEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.toolbarCollapsed", false);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.weather.location", "10001");
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "popularscreensavers@mindspark.com");
Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "popularscreensavers@mindspark.com");
Line Deleted : user_pref("keyword.URL", "hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=745D17A3-D848-4848-8085-A3F2B7F39B1B&n=780b8595&ind=2014021013&p2=^ZR^xpt372^YYA^ba&si=installldownload&searchfor=");
Line Deleted : user_pref("smartbar.machineId", "0OPSDP1P0VMMK1UX6SNCRECVD7R/L8XSRG/FOBMU6WUJMLAO3CCCVN8F+WP/TZ7IUEC5D6CH6VRECLPWFNU5LA");

-\\ Google Chrome v32.0.1700.107

[ File : C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Documents and Settings\digital\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : search_url
Deleted : keyword

*************************

AdwCleaner[R0].txt - [13989 octets] - [12/02/2014 20:05:10]
AdwCleaner[S0].txt - [13651 octets] - [12/02/2014 20:08:47]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13712 octets] ##########

Dopuna: 12 Feb 2014 21:25

Zoek.exe v5.0.0.0 Updated 10-February-2014
Tool run by digital on sre 12.02.2014 at 21:10:15,85.
Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\DOCUME~1\digital\LOCALS~1\Temp\Rar$DIa0.147\zoek.com [Scan all users] [Script inserted]

==== System Restore Info ======================

12.2.2014 21:14:39 Zoek.exe System Restore Point Created Succesfully.

==== Files Recently Created / Modified ======================

====== C:\WINDOWS ====
====== C:\DOCUME~1\digital\LOCALS~1\Temp ====
2014-02-05 17:40:01 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Documents and Settings\digital\Local Settings\Temp\{6565A986-CBDD-477B-AF4A-4EEAD24DEA93}\GoogleUpdate.exe
2014-02-03 11:36:28 630AD1674149A392A97A7B10945960CD 5987944 ----a-w- C:\Documents and Settings\digital\Local Settings\Temp\SPSetup.exe
2014-02-01 18:57:15 E9D0C6C9D87DC330BCCACCD0158E52C7 1535264 ----a-w- C:\Documents and Settings\digital\Local Settings\Temp\mam-ct3317212\mam_ie.exe
2014-02-01 18:55:43 9B25BE61BEB0E8867768150D88BAC0E6 81864 ----a-w- C:\Documents and Settings\digital\Local Settings\Temp\mam-ct3317212\ctbe.exe
2014-02-01 18:55:35 FF01A15A4F4C0A7D260041F478CC4992 5960608 ----a-w- C:\Documents and Settings\digital\Local Settings\Temp\nsw147\SpSetup.exe
2014-02-01 18:55:18 83BE9E0A3599148FE5095430B269DD2D 260416 ----a-w- C:\Documents and Settings\digital\Local Settings\Temp\mam-ct3317212\mamstub.exe
====== Java Cache =====
====== C:\WINDOWS\system32 =====
====== C:\WINDOWS\system32\drivers =====
====== C:\WINDOWS\Tasks ======
====== C:\WINDOWS\Temp ======
======= C:\Program Files =====
2014-02-12 16:20:45 -------- d-----w- C:\Program Files\SiteFinder
2014-02-11 19:21:02 -------- d-----w- C:\Program Files\Systweak Support Dock
2014-02-10 12:11:57 -------- d-----w- C:\Program Files\PopularScreensavers_7i
2014-02-01 17:41:19 -------- d-----w- C:\Program Files\MotoGP2 Demo
2014-02-01 17:28:53 -------- d-----w- C:\Program Files\GameTop.com
======= C: =====
====== C:\Documents and Settings\digital\Application Data ======
2014-02-12 19:17:27 -------- d-----w- C:\Documents and Settings\digital\Start Menu\Programs\CyberLink PowerDVD 9
2014-02-12 16:21:13 -------- d-----w- C:\Documents and Settings\digital\Application Data\SiteFinder
2014-02-11 19:35:25 -------- d-----w- C:\Documents and Settings\digital\Local Settings\Application Data\CrashRpt
2014-02-08 14:02:55 -------- d-----w- C:\Documents and Settings\digital\Start Menu\Programs\Aplikacije sustava Chrome
2014-02-05 17:52:23 -------- d-----w- C:\Documents and Settings\digital\Start Menu\Programs\Google Chrome
2014-02-02 12:25:28 -------- d-----w- C:\Documents and Settings\digital\Start Menu\Programs\WinRAR
2014-02-01 19:19:31 -------- d-----w- C:\Documents and Settings\digital\Application Data\Python-Eggs
2014-01-29 18:42:16 -------- d-----w- C:\Documents and Settings\digital\Local Settings\Application Data\Electronic_Arts_Inc
2014-01-26 15:42:49 -------- d-----w- C:\Documents and Settings\digital\Application Data\uTorrent
2014-01-26 12:30:57 -------- d--h--r- C:\Documents and Settings\digital\Application Data\SecuROM
2014-01-19 12:27:51 81532730D118DB3D8BA4702E28342BFF 14048 ----a-w- C:\Documents and Settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2014-01-16 18:02:58 -------- d-----w- C:\Documents and Settings\digital\Application Data\speedtest4354
2014-01-16 18:01:02 -------- d-----w- C:\Documents and Settings\digital\Application Data\freegames111
====== C:\Documents and Settings\digital ======
2014-02-12 16:22:17 -------- d--h--r- C:\Documents and Settings\digital\Recent
2014-01-19 12:27:13 -------- d-----w- C:\Documents and Settings\digital\SyncFolder

====== C: exe-files ==
2014-02-12 19:02:22 54DB2B8C60F04C5ADE6D711D47EABA75 1166132 ----a-w- C:\Documents and Settings\digital\My Documents\Downloads\AdwCleaner.exe
2014-02-12 18:17:01 5BCBC1323A131510A0429BECD0D5CBEC 282960 ----a-w- C:\Documents and Settings\digital\My Documents\Downloads\Firefox Setup Stub 27.0 (1).exe
2014-02-12 17:55:24 0E14B1EB617D25AD2985B5C5CED0CC0B 283072 ----a-w- C:\Documents and Settings\digital\My Documents\Downloads\Firefox Setup Stub 27.0.exe
2014-02-12 16:21:09 04B26BADB735C3B9AEB9A14260EDC7E4 48532 ----a-w- C:\Program Files\SiteFinder\sitefinder_uninstaller.exe
2014-02-10 12:42:31 CBABC92AAADCF47A0D08FF4256156A13 401760 ----a-w- C:\Documents and Settings\digital\My Documents\??????????\SoftonicDownloader_for_gta-san-andreas-car-pack.exe
2014-02-10 12:35:16 A345218C89812148C411978A2ED38919 401744 ----a-w- C:\Documents and Settings\digital\My Documents\??????????\SoftonicDownloader_for_grand-theft-auto.exe
2014-02-10 12:20:33 6223C702BA8B1F0A3E95DFECC07B5DD4 55368 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\7iSrchMn.exe
2014-02-10 12:20:32 6410E580737018F0EE3D6C484849C1C7 55880 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\7iskplay.exe
2014-02-10 12:20:31 59B38CCFD561682A7EE32D97656FA8FB 12872 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\7imedint.exe
2014-02-10 12:20:30 4F3EC39CED1D1DB84BF453F87364F4CE 12872 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\7ihighin.exe
2014-02-10 12:20:28 565575C26D63FFAD0B81BC4EEC13A145 71752 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\7ibrmon64.exe
2014-02-10 12:20:28 4C6BAE7DBB9C97A51C65F2CB55069526 61512 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\7ibrmon.exe
2014-02-10 12:20:22 27D73232C6171DD137621982724F3406 1384520 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\CrExtP7i.exe
2014-02-10 12:20:19 41DDFB8D89ACEDC3BCE9D0C779A5BF09 485448 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\AppIntegrator64.exe
2014-02-10 12:20:17 42B9D6E7B18F7AD09CF47323E592D421 88648 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\2.bin\7ibarsvc.exe
2014-02-10 12:13:43 9EFC460E66125576CAAED7E1A2A190D7 5396880 ----a-w- C:\Documents and Settings\digital\My Documents\??????????\PopularScreensaversSetup2.5.14.73.^ZR^fox000^YYA^.exe
2014-02-10 12:12:05 4C6BAE7DBB9C97A51C65F2CB55069526 61512 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibrmon.exe
2014-02-10 12:11:57 42B9D6E7B18F7AD09CF47323E592D421 88648 ----a-w- C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibarsvc.exe
2014-02-10 12:06:44 FF3FD6B78A82624C7B319EEA7F7EB8F6 51080 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateOnDemand.exe
2014-02-10 12:06:43 6D24CD9918A11CD8AB9AE678CB2CC3C7 51080 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateBroker.exe
2014-02-10 12:06:41 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdateSetup.exe
2014-02-10 12:05:59 EA8B5B41163A06FFA8930F5316473035 273800 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler64.exe
2014-02-10 12:05:58 C98ACDE22458C8F46FD0503CB9E2D01F 223112 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler.exe
2014-02-10 12:05:56 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files\Google\Update\1.3.22.5\GoogleUpdate.exe
2014-02-10 12:03:42 BA5C08130D2EFBD4E546912646DC4461 847640 ----a-w- C:\Program Files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.22.5\GoogleUpdateSetup.exe
=== C: other files ==
2014-02-11 19:43:13 6894257C050EBE7F09CB071306C46AE0 228 ----a-w- C:\Documents and Settings\All Users\Application Data\Allmyapps\ama_uninstall.bat
2014-02-08 14:11:44 6558F4F26A9373D2F38476A5B0497C9F 2323795 ----a-w- C:\Documents and Settings\digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\njkkjobcechefaoknodniidfjapgfoco\2.2.7_1\images\weather_icons.zip

==== Startup Registry Enabled ======================

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"

[HKEY_USERS\S-1-5-21-1757981266-562591055-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe /background"
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
"NextLive"="C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\digital\Application Data\newnext.me\nengine.dll,EntryPoint -m l"

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TWCU"="C:\Program Files\TP-LINK\TP-LINK 54M Wireless Client Utility\TWCU.exe -nogui"
"AVG_UI"="C:\Program Files\AVG\AVG2014\avgui.exe /TRAYONLY"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"RemoteControl9"="C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"
"PDVD9LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe"
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe"
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe"
"mobilegeni daemon"="C:\Program Files\Mobogenie\DaemonProcess.exe"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe /background"
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
"NextLive"="C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\digital\Application Data\newnext.me\nengine.dll,EntryPoint -m l"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

==== Startup Registry Disabled ======================

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Skype\\\\Phone\\Skype.exe\" /nosplash /minimized"


==== Task Scheduler Jobs ======================

C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a------ C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [29.01.2014 13:21]
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [24.06.2013 13:06]
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [24.06.2013 13:06]

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [19.04.2013 12:35]

==== Firefox Extensions ======================

ProfilePath: C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421
- Site Finder - %ProfilePath%\extensions\sitefinder@sitefinder.com
- New tab - %ProfilePath%\extensions\{6F977649-B06D-7809-9725-1FCFD3AC8308}

==== Firefox Plugins ======================

Profilepath: C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421
C623BD29E66052B94E6535FC6A7058E0 - C:\Program Files\PopularScreensavers_7i\bar\2.bin\NP7iStub.dll - Mindspark Toolbar Platform Plugin Stub
A9C86900D2A61728C8326FE7147617C5 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll - Google Update
2557FBC582910A71CDEB0F22886D118D - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll - Shockwave Flash
C2321043FA2CA4C32FF449DE6116B5D9 - C:\WINDOWS\system32\Adobe\Director\np32dsw_1205146.dll - Shockwave for Director / Shockwave for Director
F0DBF31A1C23D334A02FDF524701D390 - C:\Documents and Settings\digital\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
B50F45C9DCE776FCA64A3A8BD3D6A6F7 - C:\Games\GreenWebPlayer\npgreenwebplayer.dll - GreenWebPlayer
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
28000D7EEB2FD95A36E1A7539F599C3B - C:\Program Files\Windows Media Player\npdrmv2.dll - Microsoft® DRM
5D41BCD19A3D90E4EBB58A6BFB79E4F7 - C:\Program Files\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
8B6884E3E1E5F8ABA5FA0C6A2B13181D - C:\Program Files\Windows Media Player\npwmsdrm.dll - Microsoft® DRM


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
jljheddigenhleadfofeccneimcmlefp - C:\Documents and Settings\digital\Application Data\speedtest4354\speedtest4354.crx[19.12.2013 22:52]

Google Docs - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
TV - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh
YouTube - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Street Racers - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cohkjfondhjjfehnehlpmjpljpihfhfc
Google Search - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
WGT Golf Challenge - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dcilimldmomiaihcfkmaldanopfejefg
PiXditor - Photo Effects - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ddfflkeppghppjmfikeachhdbmpjiacj
8 Ball Pool Multiplayer - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ddfplgpeamcbpecnihfpikllkfojgkai
Qualys BrowserCheck for Windows - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejhnkognlohdkpjkjongioociddgoibk
Digital Clock - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gdkjifoifglkpcdffkenpinlbjgephlo
Run Pixie Run - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gfkmokjholoinfcnlolbjfaokmoegeoh
MotorAuthority in Pictures - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\iejnbmehnhkijljppacclfbmkncnaekh
Anatomy Games - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kbplkkegndhkgnendpdhcffamoplajga
Autodesk Homestyler - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb
MusiXhunt - Free Music Search - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kioickjjacfgafgihoghdilimjlbofnk
Viber - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lakmihnejgenmnokmckaemfmailphjpl
Value apps - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon
Google Maps - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh
Planner 5D - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcafejemebbngbglfoinpoaannbihjna
English vocabulary - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mgmklfohhllfpjjmjejencmaodgiknmj
Clock - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mjocghlclkpgheifflemilcnblodjohg
Need for Speed World is a FREE to play online racing game where you can compete with millions of players around the World. - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mnnelgnkomjdakpkjpkfehdipjifjmbk
WGT Golf Game - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mpedbpkelbhcbkdaglillalioeeekbpb
PixFiltre - Photo Editor - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nebhanlkihgdilmhiaiaclanodcalglc
WeatherBug - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\njkkjobcechefaoknodniidfjapgfoco
Google Wallet - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Foto Rulez - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\odahhdimpaeigjcdbgcnhemlkejclmmk
Allin1Convert - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pfkanglmmnniiolknlhaajllgmlgcdkj
Gmail - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Docs - NetworkService\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - NetworkService\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - NetworkService\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - NetworkService\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Gmail - NetworkService\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== IE Start and Search Settings ======================

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"SearchAssistant"="http://www.google.com"
"CustomizeSearch"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
"CustomizeSearch"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url="http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== C:\zoek_backup content ======================

C:\zoek_backup (files=752 folders=309 31909926 bytes)

==== EOF on sre 12.02.2014 at 21:23:13,28 ======================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Ponovo pokreni zoek ;


zatvori browser i ostale pokrenute programe;
deaktiviraj zaštitni softver ( po potrebi ) Uputstvo ;


U beli okvir prozora iskopiraj sledeći tekst:


C:\Program Files\PopularScreensavers_7i\bar\2.bin;fs
C:\Documents and Settings\digital\My Documents\??????????\PopularScreensaversSetup2.5.14.73.^ZR^fox000^YYA^.exe;f
C:\Program Files\PopularScreensavers_7i\bar\1.bin;fs
C:\Program Files\Mobogenie;fs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run];r
"mobilegeni daemon"=-;r
C:\Documents and Settings\digital\Application Data\newnext.me;fs
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run];r
"NextLive"="C:\WINDOWS\system32\rundll32.exe";r
[HKEY_USERS\S-1-5-21-1757981266-562591055-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Run];r
"NextLive"="C:\WINDOWS\system32\rundll32.exe";r
TV;ff
emptyalltemp;
autoclean;
emptyclsid;
ipconfig /flushdns >> %temp%\log.txt;b




Klikni na dugme i pričekaj da se skeniranje završi.


zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)


Arrow Kopiraj sadrzaj tog loga u poruku.

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

Zoek.exe v5.0.0.0 Updated 10-February-2014
Tool run by digital on sre 12.02.2014 at 22:10:13,15.
Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\digital\My Documents\Downloads\zoek.scr [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-02-12-202313.log 19140 bytes

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MgAssistService deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MgAssistService deleted successfully

==== FireFox Fix ======================

ProfilePath: C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421

user.js not found
---- Lines TV removed from prefs.js ----
user_pref("extensions.blocklist.pingCountVersion", -1);
user_pref("extensions.hotfix.lastVersion", "20130826.01");
user_pref("valueApps.storage.mam_gk_currentVersion", "312E31332E302E3137");
---- Lines valueApps removed from prefs.js ----
user_pref("valueApps.autoDisableScopes", -1);
user_pref("valueApps.storage./9B-0?3G@6:5;", "");
user_pref("valueApps.storage./9B-0?3G>D", "686B696E723F42417A43437A4A2077487C7B25237C23522A265653282656275C295B292E");
user_pref("valueApps.storage./9B-0?3GFA7EF", "2B2E2C3D");
user_pref("valueApps.storage./9B-3=3ECCJA=F>", "247E333D2C452F4135276F297B7E7D21202F26313E4249357D37382F3A494D5D513F283338435D6554695B65546D57695D5D68
user_pref("valueApps.storage./9B/>01=9A6K6<IM;KRIE@PDAWM", "6E6A68707374757677");
user_pref("valueApps.storage./9B;45>:BI9I7IE", "2B2E2C3D");
user_pref("valueApps.storage./9B?+E2A52D8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
user_pref("valueApps.storage./9B?B0D:8AJ62<H", "6D");
user_pref("valueApps.storage./9B+7E-x305", "2423");
user_pref("valueApps.storage./9B+7E,x305", "2423");
user_pref("valueApps.storage./9B+7E.:2z527", "2423");
user_pref("valueApps.storage./9B+7E.x305", "2423");
user_pref("valueApps.storage./9B+7E/x305", "2423");
user_pref("valueApps.storage./9B+7E:x305", "2423");
user_pref("valueApps.storage./9B+7E;x305", "2423");
user_pref("valueApps.storage./9B+7E?x305", "2423");
user_pref("valueApps.storage./9B+7E@x305", "2423");
user_pref("valueApps.storage./9B+7E+x305", "2423");
user_pref("valueApps.storage./9B+7E<x305", "2423");
user_pref("valueApps.storage./9B+7E=x305", "2423");
user_pref("valueApps.storage./9B+7E>x305", "2423");
user_pref("valueApps.storage./9B+7E06CG5EL;8I:K", "247E2D2F226A74736E7777727A7A7B78242F4B49474F42357D5D5C3D");
user_pref("valueApps.storage./9B+7E06CG5EL8:", "6E6D6871716C74747572");
user_pref("valueApps.storage./9B+7E0x305", "2423");
user_pref("valueApps.storage./9B+7E1x305", "2423");
user_pref("valueApps.storage./9B+7E2x305", "2423");
user_pref("valueApps.storage./9B+7E3x305", "2423");
user_pref("valueApps.storage./9B+7E4x305", "2423");
user_pref("valueApps.storage./9B+7E5x305", "2423");
user_pref("valueApps.storage./9B+7E6x305", "2423");
user_pref("valueApps.storage./9B+7E7x305", "2423");
user_pref("valueApps.storage./9B+7E8x305", "2423");
user_pref("valueApps.storage./9B+7E9x305", "2423");
user_pref("valueApps.storage./9B+7EAx305", "2423");
user_pref("valueApps.storage./9B+7EBE3G=;D9N9=D", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D337D56545138505C");
user_pref("valueApps.storage./9B+7EBx305", "2423");
user_pref("valueApps.storage./9B+7ECx305", "2423");
user_pref("valueApps.storage./9B+7EDx305", "2423");
user_pref("valueApps.storage./9B+7Etx305", "2423");
user_pref("valueApps.storage./9B<:222H64<", "393F352F3E");
user_pref("valueApps.storage./9B<:222H64<L8DAJ", "6D70706E7674737977772A7972727D7E757E7B");
user_pref("valueApps.storage./9B=+03EH8H8J?:", "4443");
user_pref("valueApps.storage./9B3=>@44I48?", "372C2D3269757633423633414847203E3D474E4D4C45474F2A554A4D2D5858585E4B554E366352564F");
user_pref("valueApps.storage./9B5BA==9CJAG", "3D6E69716F3E6D6F7A7045497A787B4A4C7A792022");
user_pref("valueApps.storage./9B6B11G4C56B>F;P;ANR@P", "6E6D6871716C7474766F707377");
user_pref("valueApps.storage./9B90E@.3C;7B=?OFB>>RHIQS", "393F352F3E");
user_pref("valueApps.storage./9B9643G3/9E", "6A");
user_pref("valueApps.storage./9BA@0<0BI6A7GN:6@L?", "6C");
user_pref("valueApps.storage._key_cl_active", "35373032373332612D653564312D343266662D396561352D393734303833386262303136");
user_pref("valueApps.storage.cbfirsttime", "5361742046656220303120323031342032303A30303A313820474D542B30313030202843656E7472616C204575726F7065616E2053
user_pref("valueApps.storage.mam_gk_appsDefaultEnabled", "6E756C6C");
user_pref("valueApps.storage.mam_gk_appState_Clarity_Active", "6F6E");
user_pref("valueApps.storage.mam_gk_appStateReportTime", "31333931333735303130383036");
user_pref("valueApps.storage.mam_gk_calledSetupService", "31");
user_pref("valueApps.storage.mam_gk_first_time", "31");
user_pref("valueApps.storage.mam_gk_lastLoginTime", "31333931333735303131373032");
user_pref("valueApps.storage.mam_gk_mamEnabled", "66616C7365");
user_pref("valueApps.storage.mam_gk_showWelcomeGadget", "66616C7365");
user_pref("valueApps.storage.mam_gk_stamp", "35345F30");
user_pref("valueApps.storage.mam_gk_user_approval_interacted", "");
user_pref("valueApps.storage.mam_gk_userId", "35336163313338312D616264622D343065332D623861642D656337636565653363306163");
user_pref("valueApps.storage.PG_ENABLE", "74727565");
user_pref("valueApps.storage.url_history0001", "687474703A2F2F61736B2E666D2F4A6F76616E6152697374696339383A3A3A636C69636B68616E646C65723A3A3A3133393133
---- Lines PlusWinks removed from prefs.js ----
user_pref("extensions.pluswinks@PlusWinks.id", "\"9e6a5197-597f-65f5-954b-b8cda1883f7a\"");
user_pref("extensions.pluswinks@PlusWinks.mzID", "63");
user_pref("extensions.pluswinks@PlusWinks.uuid", "\"f5d94b01-13ed-11e3-8099-0025901ef77c\"");
---- Lines SpeedAnalysis removed from prefs.js ----
user_pref("extensions.speedanalysis02@SpeedAnalysis.com.id", "\"4345cc23-b190-c077-56b0-538e0b05611a\"");
user_pref("extensions.speedanalysis02@SpeedAnalysis.com.mzID", "75");
user_pref("extensions.speedanalysis02@SpeedAnalysis.com.uuid", "\"f5d09643-13ed-11e3-8099-0025901ef77c\"");
---- FireFox user.js and prefs.js backups ----

prefs_12.02.2014_2246_.backup

==== Registry Fix Code ======================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mobilegeni daemon"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"="C:\WINDOWS\system32\rundll32.exe"
[HKEY_USERS\S-1-5-21-1757981266-562591055-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"="C:\WINDOWS\system32\rundll32.exe"

==== Batch Command(s) Run By Tool======================



Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


==== Deleting Files \ Folders ======================

"C:\Documents and Settings\digital\My Documents\??????????\PopularScreensaversSetup2.5.14.73.^ZR^fox000^YYA^.exe" not found
C:\Program Files\PopularScreensavers_7i\bar\2.bin deleted
C:\Program Files\PopularScreensavers_7i\bar\1.bin deleted
C:\Documents and Settings\digital\Application Data\newnext.me deleted
C:\Program Files\PopularScreensavers_7i deleted
C:\Documents and Settings\digital\Local Settings\Application Data\genienext deleted
C:\Documents and Settings\digital\.android deleted
C:\Program Files\GreenTree Applications deleted
C:\Program Files\Systweak Support Dock deleted
C:\Documents and Settings\digital\Application Data\Microsoft\Internet Explorer\Quick Launch\Mobogenie.lnk deleted
C:\Documents and Settings\digital\Application Data\freegames111 deleted
C:\Documents and Settings\digital\Application Data\speedtest4354 deleted
C:\Documents and Settings\All Users\Application Data\Datamngr deleted
C:\Documents and Settings\All Users\Application Data\Wincert deleted
C:\Documents and Settings\All Users\Application Data\Allmyapps deleted
C:\Documents and Settings\All Users\Application Data\AVG January 2013 Campaign deleted
C:\Documents and Settings\digital\Local Settings\Application Data\Mobogenie deleted
C:\Documents and Settings\digital\Local Settings\Application Data\cache deleted
C:\Documents and Settings\digital\Start Menu\Programs\Mobogenie deleted
C:\WINDOWS\System32\SET8E.tmp deleted
C:\WINDOWS\System32\SET92.tmp deleted
C:\WINDOWS\System32\SET9A.tmp deleted
C:\WINDOWS\System32\SETE4.tmp deleted
C:\WINDOWS\System32\tmp11.tmp deleted
C:\WINDOWS\System32\tmp12.tmp deleted
C:\Documents and Settings\digital\My documents\Mobogenie deleted
C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xml deleted
"C:\Documents and Settings\digital\daemonprocess.txt" deleted
"C:\Program Files\Mobogenie\DaemonProcess.exe" deleted
"C:\Program Files\Mobogenie\libeay32.dll" deleted
"C:\Program Files\Mobogenie\msvcp100.dll" deleted
"C:\Program Files\Mobogenie\msvcr100.dll" deleted
"C:\Program Files\Mobogenie\QtCore4.dll" deleted
"C:\Program Files\Mobogenie\QtGui4.dll" deleted
"C:\Program Files\Mobogenie\QtNetwork4.dll" deleted
"C:\Program Files\Mobogenie\QtSql4.dll" deleted
"C:\Program Files\Mobogenie\QtWebKit4.dll" deleted
"C:\Program Files\Mobogenie\ssleay32.dll" deleted
"C:\Program Files\Mobogenie\DaemonProcess.exe" deleted
"C:\Program Files\Mobogenie\libeay32.dll" deleted
"C:\Program Files\Mobogenie\msvcp100.dll" deleted
"C:\Program Files\Mobogenie\msvcr100.dll" deleted
"C:\Program Files\Mobogenie\QtCore4.dll" deleted
"C:\Program Files\Mobogenie\QtGui4.dll" deleted
"C:\Program Files\Mobogenie\QtNetwork4.dll" deleted
"C:\Program Files\Mobogenie\QtSql4.dll" deleted
"C:\Program Files\Mobogenie\QtWebKit4.dll" deleted
"C:\Program Files\Mobogenie\ssleay32.dll" deleted
"C:\Program Files\Mobogenie" deleted
"C:\Program Files\Mobogenie" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [19.04.2013 12:35]

==== Firefox Extensions ======================

ProfilePath: C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421
- Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
- Site Finder - %ProfilePath%\extensions\sitefinder@sitefinder.com
- New tab - %ProfilePath%\extensions\{6F977649-B06D-7809-9725-1FCFD3AC8308}

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421
A9C86900D2A61728C8326FE7147617C5 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll - Google Update
2557FBC582910A71CDEB0F22886D118D - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll - Shockwave Flash
C2321043FA2CA4C32FF449DE6116B5D9 - C:\WINDOWS\system32\Adobe\Director\np32dsw_1205146.dll - Shockwave for Director / Shockwave for Director
F0DBF31A1C23D334A02FDF524701D390 - C:\Documents and Settings\digital\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
B50F45C9DCE776FCA64A3A8BD3D6A6F7 - C:\Games\GreenWebPlayer\npgreenwebplayer.dll - GreenWebPlayer
AB87EEFFD18F2BAAFC274E7075EA6C67 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
28000D7EEB2FD95A36E1A7539F599C3B - C:\Program Files\Windows Media Player\npdrmv2.dll - Microsoft® DRM
5D41BCD19A3D90E4EBB58A6BFB79E4F7 - C:\Program Files\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
8B6884E3E1E5F8ABA5FA0C6A2B13181D - C:\Program Files\Windows Media Player\npwmsdrm.dll - Microsoft® DRM


==== Deleted Firefox Extensions ======================

C:\Documents and Settings\digital\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421\extensions\{6F977649-B06D-7809-9725-1FCFD3AC8308} deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
jljheddigenhleadfofeccneimcmlefp - C:\Documents and Settings\digital\Application Data\speedtest4354\speedtest4354.crx[]

Street Racers - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cohkjfondhjjfehnehlpmjpljpihfhfc
Qualys BrowserCheck for Windows - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ejhnkognlohdkpjkjongioociddgoibk
Run Pixie Run - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gfkmokjholoinfcnlolbjfaokmoegeoh
MotorAuthority in Pictures - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\iejnbmehnhkijljppacclfbmkncnaekh
Anatomy Games - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kbplkkegndhkgnendpdhcffamoplajga
Viber - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lakmihnejgenmnokmckaemfmailphjpl
Value apps - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon
English vocabulary - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mgmklfohhllfpjjmjejencmaodgiknmj
WeatherBug - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\njkkjobcechefaoknodniidfjapgfoco
Foto Rulez - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\odahhdimpaeigjcdbgcnhemlkejclmmk
Allin1Convert - digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pfkanglmmnniiolknlhaajllgmlgcdkj
Docs - NetworkService\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

==== Chrome Fix ======================

C:\Documents and Settings\digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lcnnhcneegeeojhgpfijnlnocjdmlaon deleted successfully
C:\Documents and Settings\digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lcnnhcneegeeojhgpfijnlnocjdmlaon_0.localstorage deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"SearchAssistant"="http://www.google.com"
"CustomizeSearch"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
"CustomizeSearch"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"SearchAssistant"="http://go.microsoft.com/fwlink/?LinkId=54896"
"CustomizeSearch"="http://go.microsoft.com/fwlink/?LinkId=54896"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jljheddigenhleadfofeccneimcmlefp deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie deleted successfully

==== Empty IE Cache ======================

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\digital\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Documents and Settings\digital\Local Settings\Application Data\Mozilla\Firefox\Profiles\g2zdq4un.default-1366142093421\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Documents and Settings\digital\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=3546 folders=560 286573841 bytes)

==== Empty Temp Folders ======================

C:\Documents and Settings\Default User\Local Settings\Temp emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temp emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp emptied successfully
C:\Documents and Settings\digital\Local Settings\Temp will be emptied at reboot
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\digital\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Documents and Settings\digital\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on sre 12.02.2014 at 23:17:13,81 ======================

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Kakvo je stanje?

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

mnogo bolje i ako moze preporuka kako najbolje da zastitim racunar od zaraze.hvala

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore


Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.






Citat:mnogo bolje i ako moze preporuka kako najbolje da zastitim racunar od zaraze.hvala

Sve ovo sto smo cistili si ti sam instalirao, ti ili neko od tvojih ko ima pristup racunaru.

offline
  • Pridružio: 27 Sep 2013
  • Poruke: 94

ne znam da li ima veze sa ovim sto ste mi ocistili komp ali sad mi uopste ne prepoznaje nijedan mobitel kad nakacim da recimo prebacim sliku ili pesmu,pre cim konektujem mobilni preko usb kabla iskoci mi tabela sa opcijama koje sad nema a nema ga ni kad udjem u my computer

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Nema veze sa ciscenjem, cistili smo samo adware-e.

Ko je trenutno na forumu
 

Ukupno su 847 korisnika na forumu :: 7 registrovanih, 1 sakriven i 839 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: comi_pfc, hyla, ILGromovnik, MB120mm, Metanoja, nenad81, opt1