|
Poslao: 26 Feb 2017 00:12
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
Nemoj. Pusticemo zver da odradi.
1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:
CreateRestorePoint:
BHO: Youtube AdBlock -> {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} -> C:\Program Files (x86)\Youtube AdBlock\IEEF\3hjhkmz.dll [2017-02-25] ()
C:\Program Files (x86)\Youtube AdBlock
BHO-x32: Youtube AdBlock -> {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} -> C:\Program Files (x86)\Youtube AdBlock\IEEF\UCUKMkQQ.dll [2017-02-25] ()
CHR Profile: C:\Users\PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-25] <==== ATTENTION
() C:\Windows\Temp\gD7C9.tmp.exe
CHR Extension: (No Name) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-02-25]
CHR Extension: (Adblocker for Youtube™) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-02-25]
CHR Extension: (Adblocker for Youtube™) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-02-25]
2017-02-25 18:27 - 2017-02-25 22:22 - 00016718 _____ C:\Windows\System32\Tasks\67R6334T5501Y865-dll
2017-02-25 18:25 - 2017-02-25 21:11 - 00002998 _____ C:\Windows\System32\Tasks\RunAtStartup
2017-02-25 18:25 - 2017-02-25 21:11 - 00000000 ____D C:\Users\PC\AppData\Roaming\Event Monitor
2017-02-25 18:24 - 2017-02-25 22:27 - 00016718 _____ C:\Windows\System32\Tasks\67R6334T5501Y865
2017-02-25 18:24 - 2017-02-25 18:24 - 00002872 _____ C:\Windows\System32\Tasks\Update Service for Youtube AdBlock2
2017-02-25 18:24 - 2017-02-25 18:24 - 00002570 _____ C:\Windows\System32\Tasks\Update Service for Youtube AdBlock
2017-02-25 18:24 - 2017-02-25 18:24 - 00000296 _____ C:\Windows\Tasks\Update Service for Youtube AdBlock2.job
2017-02-25 18:24 - 2017-02-25 18:24 - 00000296 _____ C:\Windows\Tasks\Update Service for Youtube AdBlock.job
2017-02-25 18:24 - 2017-02-25 18:24 - 00000000 ___HD C:\ProgramData\67R6334T5501Y865
2017-02-25 18:24 - 2017-02-25 18:24 - 00000000 ____D C:\Users\PC\AppData\Roaming\win-svc
2017-02-25 18:24 - 2017-02-25 18:24 - 00000000 ____D C:\Program Files (x86)\Youtube AdBlock
2017-02-25 18:23 - 2017-02-25 22:27 - 00000324 _____ C:\Windows\Tasks\Traffic Exchange v209 - 3.job
2017-02-25 18:23 - 2017-02-25 22:27 - 00000324 _____ C:\Windows\Tasks\Traffic Exchange v209 - 2.job
2017-02-25 18:23 - 2017-02-25 22:27 - 00000324 _____ C:\Windows\Tasks\Traffic Exchange v209 - 1.job
2017-02-25 18:23 - 2017-02-25 22:27 - 00000314 _____ C:\Windows\Tasks\Traffic Exchange v2 - 3.job
2017-02-25 18:23 - 2017-02-25 22:27 - 00000314 _____ C:\Windows\Tasks\Traffic Exchange v2 - 1.job
2017-02-25 18:23 - 2017-02-25 21:26 - 00000366 ____H C:\Windows\Tasks\Traffic Exchange Updater.job
2017-02-25 18:23 - 2017-02-25 18:23 - 00003580 _____ C:\Windows\System32\Tasks\Traffic Exchange Guardian
2017-02-25 18:23 - 2017-02-25 18:23 - 00003580 _____ C:\Windows\System32\Tasks\Traffic Exchange Guard
2017-02-25 18:23 - 2017-02-25 18:23 - 00003580 _____ C:\Windows\System32\Tasks\Traffic Exchange
2017-02-25 18:23 - 2017-02-25 18:23 - 00003196 _____ C:\Windows\System32\Tasks\Traffic Exchange Updater
2017-02-25 18:23 - 2017-02-25 18:23 - 00003150 _____ C:\Windows\System32\Tasks\Traffic Exchange v209 - 3
2017-02-25 18:23 - 2017-02-25 18:23 - 00003150 _____ C:\Windows\System32\Tasks\Traffic Exchange v209 - 2
2017-02-25 18:23 - 2017-02-25 18:23 - 00003150 _____ C:\Windows\System32\Tasks\Traffic Exchange v209 - 1
2017-02-25 18:23 - 2017-02-25 18:23 - 00003140 _____ C:\Windows\System32\Tasks\Traffic Exchange v2 - 3
2017-02-25 18:23 - 2017-02-25 18:23 - 00003140 _____ C:\Windows\System32\Tasks\Traffic Exchange v2 - 2
2017-02-25 18:23 - 2017-02-25 18:23 - 00003140 _____ C:\Windows\System32\Tasks\Traffic Exchange v2 - 1
2017-02-25 18:23 - 2017-02-25 18:23 - 00000314 _____ C:\Windows\Tasks\Traffic Exchange v2 - 2.job
Folder:C:\Windows\SysWOW64\%APPDATA%
2017-02-25 18:23 - 2017-02-25 18:23 - 00000000 ____D C:\Users\Default\AppData\Local\AdvinstAnalytics
2017-02-25 18:23 - 2017-02-25 18:23 - 00000000 ____D C:\Users\Default User\AppData\Local\AdvinstAnalytics
2017-02-25 18:23 - 2017-02-25 18:23 - 00000000 ____D C:\Program Files (x86)\Microleaves
2017-02-25 18:22 - 2017-02-25 18:23 - 00000000 ____D C:\Users\PC\AppData\Roaming\Microleaves
C:\Users\PC\AppData\Local\Temp\{b78-2d-04-91498-84afd-c52a-5d3d2}\eN2HAOrIdI.exe
Task: {16F29693-6E6E-45F1-9EFF-626B0DD061D3} - System32\Tasks\Traffic Exchange Updater => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe [2017-02-15] (Microleaves) <==== ATTENTION
Task: {1CE4BE94-ED68-4439-A1CB-27F93302DF1F} - \PC Clean Plus_DEFAULT -> No File <==== ATTENTION
Task: {3C8C4283-FCB6-44DD-BC64-AEA1AF82E22C} - System32\Tasks\Traffic Exchange Guardian => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {40ABE244-FBD8-4057-9DB3-AB777E293529} - System32\Tasks\Update Service for Youtube AdBlock2 => Rundll32.exe "C:\Program Files (x86)\Youtube AdBlock\XkJIxR5.dll",#1
Task: {65198D28-AF03-40BF-BBA2-474AF212633E} - \PC Clean Plus_UPDATES -> No File <==== ATTENTION
Task: {75FDAE17-21FC-4B47-8C6E-65E33C0E85D4} - System32\Tasks\Traffic Exchange v2 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {95BB29EE-51A1-4756-9E4E-1171566B56B4} - System32\Tasks\Traffic Exchange v2 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {ABEAD6F4-9F85-4889-915D-65BC059CD7C9} - \PC Clean Plus -> No File <==== ATTENTION
Task: {AFA8895C-CCBF-44FA-8789-CCE73D5F3BC8} - System32\Tasks\Update Service for Youtube AdBlock => Rundll32.exe "C:\Program Files (x86)\Youtube AdBlock\XkJIxR5.dll",#1
Task: {B576D749-6990-4DE6-B9F2-094883CF9B13} - System32\Tasks\RunAtStartup => C:\Users\PC\AppData\Roaming\Event Monitor\em.exe [2017-01-05] () <==== ATTENTION
Task: {B8417CA0-54EB-4287-8B80-C37382EBA381} - System32\Tasks\67R6334T5501Y865 => Rundll32.exe "C:\ProgramData\67R6334T5501Y865\67R6334T5501Y865.dll",RTYacjItd <==== ATTENTION
Task: {BC842011-1D26-4D50-9F2E-CF645DAA3698} - System32\Tasks\Traffic Exchange => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {BE08C826-2DDE-47ED-8FD2-C7EEDEBC5155} - System32\Tasks\Traffic Exchange v209 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {E6453297-16FA-42D6-AF2D-EFB591E8F201} - System32\Tasks\Traffic Exchange v2 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {F1B35EA2-E021-43F2-AB03-2ACDBCFB226E} - System32\Tasks\Traffic Exchange v209 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {F280543C-F150-4B7F-A3D0-AA38E4A6A5D0} - System32\Tasks\Traffic Exchange Guard => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {F5F6B7B3-56D8-48CD-8E15-EF9166D93000} - System32\Tasks\Traffic Exchange v209 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {FFAAF59A-7C6F-4BA2-BFBE-0E99F6FDEA07} - System32\Tasks\67R6334T5501Y865-dll => Rundll32.exe "C:\ProgramData\67R6334T5501Y865\67R6334T5501Y865.dll",RTYacjItd
Task: C:\Windows\Tasks\Traffic Exchange Updater.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v2 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v2 - 2.job => <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v2 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v209 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v209 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v209 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\Windows\Tasks\Update Service for Youtube AdBlock.job =>
Task: C:\Windows\Tasks\Update Service for Youtube AdBlock2.job =>
C:\Users\PC\AppData\Local\Temp\{b78-2d-04-91498-84afd-c52a-5d3d2}\eN2HAOrIdI.exe
C:\Users\PC\AppData\Roaming\Event Monitor\em.exe
EmptyTemp:
2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.
3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.
Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.
|
|
|
|
Poslao: 26 Feb 2017 00:21
|
offline
- maha
- Super građanin
- Pridružio: 06 Dec 2006
- Poruke: 1152
|
Fix result of Farbar Recovery Scan Tool (x64) Version: 25-02-2017
Ran by PC (26-02-2017 00:15:37) Run:2
Running from C:\Users\PC\Desktop
Loaded Profiles: PC (Available Profiles: PC)
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
BHO: Youtube AdBlock -> {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} -> C:\Program Files (x86)\Youtube AdBlock\IEEF\3hjhkmz.dll [2017-02-25] ()
C:\Program Files (x86)\Youtube AdBlock
BHO-x32: Youtube AdBlock -> {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} -> C:\Program Files (x86)\Youtube AdBlock\IEEF\UCUKMkQQ.dll [2017-02-25] ()
CHR Profile: C:\Users\PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-02-25] <==== ATTENTION
() C:\Windows\Temp\gD7C9.tmp.exe
CHR Extension: (No Name) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-02-25]
CHR Extension: (Adblocker for Youtube™) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-02-25]
CHR Extension: (Adblocker for Youtube™) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk [2017-02-25]
2017-02-25 18:27 - 2017-02-25 22:22 - 00016718 _____ C:\Windows\System32\Tasks\67R6334T5501Y865-dll
2017-02-25 18:25 - 2017-02-25 21:11 - 00002998 _____ C:\Windows\System32\Tasks\RunAtStartup
2017-02-25 18:25 - 2017-02-25 21:11 - 00000000 ____D C:\Users\PC\AppData\Roaming\Event Monitor
2017-02-25 18:24 - 2017-02-25 22:27 - 00016718 _____ C:\Windows\System32\Tasks\67R6334T5501Y865
2017-02-25 18:24 - 2017-02-25 18:24 - 00002872 _____ C:\Windows\System32\Tasks\Update Service for Youtube AdBlock2
2017-02-25 18:24 - 2017-02-25 18:24 - 00002570 _____ C:\Windows\System32\Tasks\Update Service for Youtube AdBlock
2017-02-25 18:24 - 2017-02-25 18:24 - 00000296 _____ C:\Windows\Tasks\Update Service for Youtube AdBlock2.job
2017-02-25 18:24 - 2017-02-25 18:24 - 00000296 _____ C:\Windows\Tasks\Update Service for Youtube AdBlock.job
2017-02-25 18:24 - 2017-02-25 18:24 - 00000000 ___HD C:\ProgramData\67R6334T5501Y865
2017-02-25 18:24 - 2017-02-25 18:24 - 00000000 ____D C:\Users\PC\AppData\Roaming\win-svc
2017-02-25 18:24 - 2017-02-25 18:24 - 00000000 ____D C:\Program Files (x86)\Youtube AdBlock
2017-02-25 18:23 - 2017-02-25 22:27 - 00000324 _____ C:\Windows\Tasks\Traffic Exchange v209 - 3.job
2017-02-25 18:23 - 2017-02-25 22:27 - 00000324 _____ C:\Windows\Tasks\Traffic Exchange v209 - 2.job
2017-02-25 18:23 - 2017-02-25 22:27 - 00000324 _____ C:\Windows\Tasks\Traffic Exchange v209 - 1.job
2017-02-25 18:23 - 2017-02-25 22:27 - 00000314 _____ C:\Windows\Tasks\Traffic Exchange v2 - 3.job
2017-02-25 18:23 - 2017-02-25 22:27 - 00000314 _____ C:\Windows\Tasks\Traffic Exchange v2 - 1.job
2017-02-25 18:23 - 2017-02-25 21:26 - 00000366 ____H C:\Windows\Tasks\Traffic Exchange Updater.job
2017-02-25 18:23 - 2017-02-25 18:23 - 00003580 _____ C:\Windows\System32\Tasks\Traffic Exchange Guardian
2017-02-25 18:23 - 2017-02-25 18:23 - 00003580 _____ C:\Windows\System32\Tasks\Traffic Exchange Guard
2017-02-25 18:23 - 2017-02-25 18:23 - 00003580 _____ C:\Windows\System32\Tasks\Traffic Exchange
2017-02-25 18:23 - 2017-02-25 18:23 - 00003196 _____ C:\Windows\System32\Tasks\Traffic Exchange Updater
2017-02-25 18:23 - 2017-02-25 18:23 - 00003150 _____ C:\Windows\System32\Tasks\Traffic Exchange v209 - 3
2017-02-25 18:23 - 2017-02-25 18:23 - 00003150 _____ C:\Windows\System32\Tasks\Traffic Exchange v209 - 2
2017-02-25 18:23 - 2017-02-25 18:23 - 00003150 _____ C:\Windows\System32\Tasks\Traffic Exchange v209 - 1
2017-02-25 18:23 - 2017-02-25 18:23 - 00003140 _____ C:\Windows\System32\Tasks\Traffic Exchange v2 - 3
2017-02-25 18:23 - 2017-02-25 18:23 - 00003140 _____ C:\Windows\System32\Tasks\Traffic Exchange v2 - 2
2017-02-25 18:23 - 2017-02-25 18:23 - 00003140 _____ C:\Windows\System32\Tasks\Traffic Exchange v2 - 1
2017-02-25 18:23 - 2017-02-25 18:23 - 00000314 _____ C:\Windows\Tasks\Traffic Exchange v2 - 2.job
Folder:C:\Windows\SysWOW64\%APPDATA%
2017-02-25 18:23 - 2017-02-25 18:23 - 00000000 ____D C:\Users\Default\AppData\Local\AdvinstAnalytics
2017-02-25 18:23 - 2017-02-25 18:23 - 00000000 ____D C:\Users\Default User\AppData\Local\AdvinstAnalytics
2017-02-25 18:23 - 2017-02-25 18:23 - 00000000 ____D C:\Program Files (x86)\Microleaves
2017-02-25 18:22 - 2017-02-25 18:23 - 00000000 ____D C:\Users\PC\AppData\Roaming\Microleaves
C:\Users\PC\AppData\Local\Temp\{b78-2d-04-91498-84afd-c52a-5d3d2}\eN2HAOrIdI.exe
Task: {16F29693-6E6E-45F1-9EFF-626B0DD061D3} - System32\Tasks\Traffic Exchange Updater => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe [2017-02-15] (Microleaves) <==== ATTENTION
Task: {1CE4BE94-ED68-4439-A1CB-27F93302DF1F} - \PC Clean Plus_DEFAULT -> No File <==== ATTENTION
Task: {3C8C4283-FCB6-44DD-BC64-AEA1AF82E22C} - System32\Tasks\Traffic Exchange Guardian => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {40ABE244-FBD8-4057-9DB3-AB777E293529} - System32\Tasks\Update Service for Youtube AdBlock2 => Rundll32.exe "C:\Program Files (x86)\Youtube AdBlock\XkJIxR5.dll",#1
Task: {65198D28-AF03-40BF-BBA2-474AF212633E} - \PC Clean Plus_UPDATES -> No File <==== ATTENTION
Task: {75FDAE17-21FC-4B47-8C6E-65E33C0E85D4} - System32\Tasks\Traffic Exchange v2 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {95BB29EE-51A1-4756-9E4E-1171566B56B4} - System32\Tasks\Traffic Exchange v2 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {ABEAD6F4-9F85-4889-915D-65BC059CD7C9} - \PC Clean Plus -> No File <==== ATTENTION
Task: {AFA8895C-CCBF-44FA-8789-CCE73D5F3BC8} - System32\Tasks\Update Service for Youtube AdBlock => Rundll32.exe "C:\Program Files (x86)\Youtube AdBlock\XkJIxR5.dll",#1
Task: {B576D749-6990-4DE6-B9F2-094883CF9B13} - System32\Tasks\RunAtStartup => C:\Users\PC\AppData\Roaming\Event Monitor\em.exe [2017-01-05] () <==== ATTENTION
Task: {B8417CA0-54EB-4287-8B80-C37382EBA381} - System32\Tasks\67R6334T5501Y865 => Rundll32.exe "C:\ProgramData\67R6334T5501Y865\67R6334T5501Y865.dll",RTYacjItd <==== ATTENTION
Task: {BC842011-1D26-4D50-9F2E-CF645DAA3698} - System32\Tasks\Traffic Exchange => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {BE08C826-2DDE-47ED-8FD2-C7EEDEBC5155} - System32\Tasks\Traffic Exchange v209 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {E6453297-16FA-42D6-AF2D-EFB591E8F201} - System32\Tasks\Traffic Exchange v2 - 1 => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe [2016-11-22] (Microleaves LTD) <==== ATTENTION
Task: {F1B35EA2-E021-43F2-AB03-2ACDBCFB226E} - System32\Tasks\Traffic Exchange v209 - 3 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {F280543C-F150-4B7F-A3D0-AA38E4A6A5D0} - System32\Tasks\Traffic Exchange Guard => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian.exe [2016-08-17] (Microleaves LTD) <==== ATTENTION
Task: {F5F6B7B3-56D8-48CD-8E15-EF9166D93000} - System32\Tasks\Traffic Exchange v209 - 2 => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe [2017-02-07] (Microleaves LTD) <==== ATTENTION
Task: {FFAAF59A-7C6F-4BA2-BFBE-0E99F6FDEA07} - System32\Tasks\67R6334T5501Y865-dll => Rundll32.exe "C:\ProgramData\67R6334T5501Y865\67R6334T5501Y865.dll",RTYacjItd
Task: C:\Windows\Tasks\Traffic Exchange Updater.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Traffic Exchange Updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v2 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v2 - 2.job => <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v2 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v209 - 1.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v209 - 2.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\Windows\Tasks\Traffic Exchange v209 - 3.job => C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe <==== ATTENTION
Task: C:\Windows\Tasks\Update Service for Youtube AdBlock.job =>
Task: C:\Windows\Tasks\Update Service for Youtube AdBlock2.job =>
C:\Users\PC\AppData\Local\Temp\{b78-2d-04-91498-84afd-c52a-5d3d2}\eN2HAOrIdI.exe
C:\Users\PC\AppData\Roaming\Event Monitor\em.exe
EmptyTemp:
*****************
Restore point was successfully created.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} => key not found.
HKCR\CLSID\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} => key not found.
"C:\Program Files (x86)\Youtube AdBlock" => not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} => key not found.
HKCR\Wow6432Node\CLSID\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} => key not found.
C:\Users\PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData => moved successfully
[2244] C:\Windows\Temp\gD7C9.tmp.exe => process closed successfully.
C:\Users\PC\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk => not found
C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk => not found
C:\Users\PC\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gndgngmogcnpkcbknmcgpnooljecgadk => not found
C:\Windows\System32\Tasks\67R6334T5501Y865-dll => moved successfully
C:\Windows\System32\Tasks\RunAtStartup => moved successfully
"C:\Users\PC\AppData\Roaming\Event Monitor" folder move:
Could not move "C:\Users\PC\AppData\Roaming\Event Monitor" => Scheduled to move on reboot.
C:\Windows\System32\Tasks\67R6334T5501Y865 => moved successfully
"C:\Windows\System32\Tasks\Update Service for Youtube AdBlock2" => not found.
"C:\Windows\System32\Tasks\Update Service for Youtube AdBlock" => not found.
"C:\Windows\Tasks\Update Service for Youtube AdBlock2.job" => not found.
"C:\Windows\Tasks\Update Service for Youtube AdBlock.job" => not found.
C:\ProgramData\67R6334T5501Y865 => moved successfully
C:\Users\PC\AppData\Roaming\win-svc => moved successfully
"C:\Program Files (x86)\Youtube AdBlock" => not found.
C:\Windows\Tasks\Traffic Exchange v209 - 3.job => moved successfully
C:\Windows\Tasks\Traffic Exchange v209 - 2.job => moved successfully
C:\Windows\Tasks\Traffic Exchange v209 - 1.job => moved successfully
C:\Windows\Tasks\Traffic Exchange v2 - 3.job => moved successfully
C:\Windows\Tasks\Traffic Exchange v2 - 1.job => moved successfully
C:\Windows\Tasks\Traffic Exchange Updater.job => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange Guardian => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange Guard => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange Updater => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange v209 - 3 => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange v209 - 2 => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange v209 - 1 => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange v2 - 3 => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange v2 - 2 => moved successfully
C:\Windows\System32\Tasks\Traffic Exchange v2 - 1 => moved successfully
C:\Windows\Tasks\Traffic Exchange v2 - 2.job => moved successfully
========================= Folder:C:\Windows\SysWOW64\%APPDATA% ========================
not found.
====== End of Folder: ======
C:\Users\Default\AppData\Local\AdvinstAnalytics => moved successfully
"C:\Users\Default User\AppData\Local\AdvinstAnalytics" => not found.
C:\Program Files (x86)\Microleaves => moved successfully
C:\Users\PC\AppData\Roaming\Microleaves => moved successfully
C:\Users\PC\AppData\Local\Temp\{b78-2d-04-91498-84afd-c52a-5d3d2}\eN2HAOrIdI.exe => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{16F29693-6E6E-45F1-9EFF-626B0DD061D3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{16F29693-6E6E-45F1-9EFF-626B0DD061D3} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange Updater => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange Updater => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1CE4BE94-ED68-4439-A1CB-27F93302DF1F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1CE4BE94-ED68-4439-A1CB-27F93302DF1F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Clean Plus_DEFAULT => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3C8C4283-FCB6-44DD-BC64-AEA1AF82E22C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C8C4283-FCB6-44DD-BC64-AEA1AF82E22C} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange Guardian => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange Guardian => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40ABE244-FBD8-4057-9DB3-AB777E293529} => key not found.
C:\Windows\System32\Tasks\Update Service for Youtube AdBlock2 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Service for Youtube AdBlock2 => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65198D28-AF03-40BF-BBA2-474AF212633E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65198D28-AF03-40BF-BBA2-474AF212633E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Clean Plus_UPDATES => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{75FDAE17-21FC-4B47-8C6E-65E33C0E85D4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75FDAE17-21FC-4B47-8C6E-65E33C0E85D4} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange v2 - 2 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange v2 - 2 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{95BB29EE-51A1-4756-9E4E-1171566B56B4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95BB29EE-51A1-4756-9E4E-1171566B56B4} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange v2 - 3 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange v2 - 3 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ABEAD6F4-9F85-4889-915D-65BC059CD7C9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ABEAD6F4-9F85-4889-915D-65BC059CD7C9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PC Clean Plus => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AFA8895C-CCBF-44FA-8789-CCE73D5F3BC8} => key not found.
C:\Windows\System32\Tasks\Update Service for Youtube AdBlock => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update Service for Youtube AdBlock => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B576D749-6990-4DE6-B9F2-094883CF9B13} => key not found.
C:\Windows\System32\Tasks\RunAtStartup => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAtStartup => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B8417CA0-54EB-4287-8B80-C37382EBA381} => key not found.
C:\Windows\System32\Tasks\67R6334T5501Y865 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\67R6334T5501Y865 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC842011-1D26-4D50-9F2E-CF645DAA3698} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC842011-1D26-4D50-9F2E-CF645DAA3698} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BE08C826-2DDE-47ED-8FD2-C7EEDEBC5155} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE08C826-2DDE-47ED-8FD2-C7EEDEBC5155} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange v209 - 1 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange v209 - 1 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E6453297-16FA-42D6-AF2D-EFB591E8F201} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6453297-16FA-42D6-AF2D-EFB591E8F201} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange v2 - 1 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange v2 - 1 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F1B35EA2-E021-43F2-AB03-2ACDBCFB226E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F1B35EA2-E021-43F2-AB03-2ACDBCFB226E} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange v209 - 3 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange v209 - 3 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F280543C-F150-4B7F-A3D0-AA38E4A6A5D0} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F280543C-F150-4B7F-A3D0-AA38E4A6A5D0} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange Guard => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange Guard => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F5F6B7B3-56D8-48CD-8E15-EF9166D93000} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5F6B7B3-56D8-48CD-8E15-EF9166D93000} => key removed successfully
C:\Windows\System32\Tasks\Traffic Exchange v209 - 2 => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Traffic Exchange v209 - 2 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{FFAAF59A-7C6F-4BA2-BFBE-0E99F6FDEA07} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFAAF59A-7C6F-4BA2-BFBE-0E99F6FDEA07} => key removed successfully
C:\Windows\System32\Tasks\67R6334T5501Y865-dll => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\67R6334T5501Y865-dll => key removed successfully
C:\Windows\Tasks\Traffic Exchange Updater.job => not found.
C:\Windows\Tasks\Traffic Exchange v2 - 1.job => not found.
C:\Windows\Tasks\Traffic Exchange v2 - 2.job => not found.
C:\Windows\Tasks\Traffic Exchange v2 - 3.job => not found.
C:\Windows\Tasks\Traffic Exchange v209 - 1.job => not found.
C:\Windows\Tasks\Traffic Exchange v209 - 2.job => not found.
C:\Windows\Tasks\Traffic Exchange v209 - 3.job => not found.
C:\Windows\Tasks\Update Service for Youtube AdBlock.job => not found.
C:\Windows\Tasks\Update Service for Youtube AdBlock2.job => not found.
"C:\Users\PC\AppData\Local\Temp\{b78-2d-04-91498-84afd-c52a-5d3d2}\eN2HAOrIdI.exe" => not found.
C:\Users\PC\AppData\Roaming\Event Monitor\em.exe => moved successfully
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5099777 B
Java, Flash, Steam htmlcache => 812 B
Windows/system/drivers => 4939795 B
Edge => 0 B
Chrome => 199680 B
Firefox => 38079012 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 83222 B
Public => 0 B
ProgramData => 0 B
systemprofile => 100621 B
systemprofile32 => 82795 B
LocalService => 66708 B
NetworkService => 692 B
PC => 17032593 B
RecycleBin => 330731 B
EmptyTemp: => 71 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 26-02-2017 00:18:41)
C:\Users\PC\AppData\Roaming\Event Monitor => moved successfully
==== End of Fixlog 00:18:44 ====
|
|
|
|
Poslao: 26 Feb 2017 00:22
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
Stanje?
Probaj sad da pokrenes AdwCleaner i dostavi log, ako ne moze, onda novi FRST log i Addition.
|
|
|
|
|
Poslao: 26 Feb 2017 00:33
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
Skini ga iz nekog drugog browsera. Mozda se nece to pojavljivati.
|
|
|
|
Poslao: 26 Feb 2017 00:41
|
offline
- maha
- Super građanin
- Pridružio: 06 Dec 2006
- Poruke: 1152
|
probao iz chrome..skinuo i cim pokrenem adwc...izbaci firefox sa desetine prozora..
|
|
|
|
Poslao: 26 Feb 2017 07:38
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
Pokreni ponovo MBAM i ovog puta UKLONI ono sto bude pronadjeno. Postavi izvestaj od MBAMa i nove FRST izvestaje.
|
|
|
|
|
|