|
Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.
Start
CloseProcesses:
HKLM\...\Run: [rundll32] => C:\Windows\system32\rundll32.exe "C:\Program Files\Sawmenger XP\Sawmenger XP.dll",elnXHi
HKLM\...\Run: [JServicesManager] => C:\Program Files\SystemaRev\RevServicesX\app.ex
HKLM-x32\...\Run: [JServicesManager] => C:\Program Files\SystemaRev\RevServicesX\app.ex
HKLM\...\RunOnce: [OMEWPRODUCT_] => C:\Program Files\Windows NT\GOCSX9XWZ6THIUBDEP3J87646MS191I\Z0GJf-FNo5.exe [233984 2018-06-11] ()
HKLM\...\RunOnce: [unqq2itjeju] => C:\Program Files (x86)\lsJZU\497969.exe [670720 2018-06-10] ()
HKLM\...\RunOnce: [OMEWPRODUCT_77QM1] => C:\Users\win7\AppData\Local\Temp\is-THBTD.tmp\up.exe [52224 2018-06-11] (CXBN) <==== ATTENTION
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [Blogger] => C:\ProgramData\Blogger\Blogger.exe [536576 2018-06-09] ()
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [WMwB6Phku4.exe] => C:\Program Files\Windows NT\GOCSX9XWZ6THIUBDEP3J87646MS191I\WMwB6Phku4.exe [394240 2018-06-11] ()
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [JI9Q9AMH5GK07W5] => C:\Program Files\BM2VJ9ZVZ4\BM2VJ9ZVZ.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [5007769] => C:\Users\win7\AppData\Roaming\d1pbfumpr2x\fhfxnlq4zka.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [5497325] => C:\Users\win7\AppData\Roaming\a3uaoh4mopl\5rckcgxrjkz.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [4306173] => C:\Users\win7\AppData\Roaming\d0krbp3szxx\0iai535qldo.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [3EOL3XGMBWI8ZNP] => C:\Program Files\8ABNBWXL7R\LZI2JV3M7.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [7450318] => C:\Users\win7\AppData\Roaming\gbsr4hbzs4e\vha5tyaqlo1.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [OK04001PFFQH8XF] => C:\Program Files\UFVTZJYYNY\UFVTZJYYN.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [8515487] => C:\Users\win7\AppData\Roaming\hsnnhmewhxw\tfjzhfnjqty.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [7560465] => C:\Users\win7\AppData\Roaming\vvubncijqd2\hiqnm1t2iis.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [6342919] => C:\Users\win7\AppData\Roaming\4omugn1awyo\3uvnio1jgds.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [WHYFWFGNCLXLG3Y] => C:\Program Files\DIR07Q8Y42\DIR07Q8Y4.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [3U4L2G3CRBXAO5Z] => C:\Program Files\ZM6R1CLMCI\ZM6R1CLMC.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [3941173] => C:\Users\win7\AppData\Roaming\fmzgmxjqrl4\5xrkph1j51r.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [6OKKO5CXS1C7N0I] => C:\Program Files\R6X0PAND02\R6X0PAND0.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [3255819] => C:\Users\win7\AppData\Roaming\cjxmrpa20sf\tmzvfpzxdeu.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [3282095] => C:\Users\win7\AppData\Roaming\120i322id44\yb4yp0jqhqs.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [1762593] => C:\Users\win7\AppData\Roaming\jojub30kxnb\bqh45rnuudb.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [LVO3YWL0I21R3C8] => C:\Program Files\MQK555TIFV\MQK555TIF.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [P2O6WKWA1SW7AT0] => C:\Program Files\DM3SDBRN2N\DM3SDBRN2.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [4667683] => C:\Users\win7\AppData\Roaming\wi2qpuxupxd\pghyjgysjlw.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [1346401] => C:\Users\win7\AppData\Roaming\ctub1wobjvs\cjmgl40jyem.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [2347416] => C:\Users\win7\AppData\Roaming\ccc0n12gqok\scgafir1ufo.exe [554589 2018-06-11] ( )
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [UCSTXK9GKTMV665] => C:\Program Files\6W1IJ1HNXP\6W1IJ1HNX.exe [666624 2018-06-11] (CXBN)
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\...\Run: [03P7INIL7E1TY90] => C:\Program Files\ZWJ39965AD\ZWJ39965A.exe [666624 2018-06-11] (CXBN)
AppInit_DLLs: C:\ProgramData\Quoteex\Stocknix.dll => C:\ProgramData\Quoteex\Stocknix.dll [342528 2018-06-09] ()
AppInit_DLLs-x32: C:\ProgramData\Quoteex\Alpha-Top.dll => C:\ProgramData\Quoteex\Alpha-Top.dll [460800 2018-06-09] ()
ShellExecuteHooks: No Name - {BFD98515-CD74-48A4-98E2-13D209E3EE4F} - C:\Windows\System32\mcicda64.dll [2990080 2018-03-24] () <==== ATTENTION
Startup: C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AdobeUpdater.vbs [2018-06-09] ()
Startup: C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\adsviejd.lnk [2018-06-09]
ShortcutTarget: adsviejd.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Startup: C:\Users\win7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\zoiut.exe.vbs [2018-03-11] ()
GroupPolicy: Restriction ? <==== ATTENTION
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGtoMUuydOpuy8em5IIgt414t115vhNf6jfDlX4NMd7UohVL7oXgcmyBx-v4CQ9FrAtA8sh305gfKJ1fwiyQ2pFke-9IaU4RrqwsU2hQox5YpkQxkr2GCCdWPSpLZU1B70uULZAZF6bOC_B6A0AQSBxIm0H5FwV6FKzHQQ,,&q={searchTerms}
HKU\S-1-5-21-506494789-1706831849-2708248724-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGtoMUuydOpuy8em5IIgt414t115vhNf6jfDlX4NMd7UohVL7oXgcmyBx-v4CQ9FrAtA8sh305gfKJ1TXSlcp7hKxNemzvkE3xXLUREXxJjmCOJKSMvMErimMx-hwXjIzH_y9GXbTeILTJBwJI7bnBfG4YybPLCsAcN-UA,,
HKU\S-1-5-21-506494789-1706831849-2708248724-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGtoMUuydOpuy8em5IIgt414t115vhNf6jfDlX4NMd7UohVL7oXgcmyBx-v4CQ9FrAtA8sh305gfKJ1TXSlcp7hKxNemzvkE3xXLUREXxJjmCOJKSMvMErimMx-hwXjIzH_y9GXbTeILTJBwJI7bnBfG4YybPLCsAcN-UA,,
HKU\S-1-5-21-506494789-1706831849-2708248724-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGtoMUuydOpuy8em5IIgt414t115vhNf6jfDlX4NMd7UohVL7oXgcmyBx-v4CQ9FrAtA8sh305gfKJ1fwiyQ2pFke-9IaU4RrqwsU2hQox5YpkQxkr2GCCdWPSpLZU1B70uULZAZF6bOC_B6A0AQSBxIm0H5FwV6FKzHQQ,,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGtoMUuydOpuy8em5IIgt414t115vhNf6jfDlX4NMd7UohVL7oXgcmyBx-v4CQ9FrAtA8sh305gfKJ1fwiyQ2pFke-9IaU4RrqwsU2hQox5YpkQxkr2GCCdWPSpLZU1B70uULZAZF6bOC_B6A0AQSBxIm0H5FwV6FKzHQQ,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506494789-1706831849-2708248724-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10405__170627__yaie&p={searchTerms}
SearchScopes: HKU\S-1-5-21-506494789-1706831849-2708248724-1000 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGtoMUuydOpuy8em5IIgt414t115vhNf6jfDlX4NMd7UohVL7oXgcmyBx-v4CQ9FrAtA8sh305gfKJ1fwiyQ2pFke-9IaU4RrqwsU2hQox5YpkQxkr2GCCdWPSpLZU1B70uULZAZF6bOC_B6A0AQSBxIm0H5FwV6FKzHQQ,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506494789-1706831849-2708248724-1001 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGtoMUuydOpuy8em5IIgt414t115vhNf6jfDlX4NMd7UohVL7oXgcmyBx-v4CQ9FrAtA8sh305gfKJ1fwiyQ2pFke-9IaU4RrqwsU2hQox5YpkQxkr2GCCdWPSpLZU1B70uULZAZF6bOC_B6A0AQSBxIm0H5FwV6FKzHQQ,,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-506494789-1706831849-2708248724-1001 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGtoMUuydOpuy8em5IIgt414t115vhNf6jfDlX4NMd7UohVL7oXgcmyBx-v4CQ9FrAtA8sh305gfKJ1fwiyQ2pFke-9IaU4RrqwsU2hQox5YpkQxkr2GCCdWPSpLZU1B70uULZAZF6bOC_B6A0AQSBxIm0H5FwV6FKzHQQ,,&q={searchTerms}
FF user.js: detected! => C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\qig4ehrc.default\user.js [2017-06-30]
FF Homepage: Mozilla\Firefox\Profiles\qig4ehrc.default -> file:///C:/ProgramData/Quoteexs/ff.HP
FF NewTab: Mozilla\Firefox\Profiles\qig4ehrc.default -> file:///C:/ProgramData/Quoteexs/ff.NT
FF Extension: (System Table) - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\qig4ehrc.default\Extensions\143734@modext.tech.xpi [2018-03-01]
FF Extension: (System Table) - C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\qig4ehrc.default\Extensions\214028@modext.tech.xpi [2018-02-28]
FF SearchPlugin: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\qig4ehrc.default\searchplugins\yahoo-lavasoft.xml [2017-08-19]
R2 backlh; C:\ProgramData\Logic Cramble\set.exe [3780096 2018-06-09] () [File not signed] <==== ATTENTION
S3 SystemUpdate64; C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe [593920 2018-06-08] (SystemaRev) [File not signed] <==== ATTENTION
S2 Quoteex; C:\ProgramData\\Quoteex\\Quoteex.exe shuz -f "C:\ProgramData\\Quoteex\\Quoteex.dat" -l -a <==== ATTENTION
2018-06-11 03:38 - 2018-06-11 03:55 - 000093696 _____ (jatnsxdnhhvbyxucxt) C:\Users\win7\AppData\Roaming\command.dll
2017-06-22 12:27 - 2017-06-22 12:27 - 000370070 _____ () C:\Users\win7\AppData\Roaming\logo_empire_desktop.ico
2018-06-11 03:38 - 2018-06-11 03:05 - 000623616 _____ (zloidyahgrwhmvqhwz) C:\Users\win7\AppData\Roaming\product.dll
2018-06-09 18:11 - 2018-06-09 18:11 - 007627776 _____ () C:\Users\win7\AppData\Local\agent.dat
2018-06-09 18:11 - 2018-06-09 18:11 - 001988902 _____ () C:\Users\win7\AppData\Local\Alphait.tst
2018-06-09 18:11 - 2018-06-09 18:11 - 001895382 _____ () C:\Users\win7\AppData\Local\Aping.bin
2018-06-09 18:11 - 2018-06-09 18:11 - 000070896 _____ () C:\Users\win7\AppData\Local\Config.xml
2018-01-29 21:38 - 2018-01-29 21:38 - 000003584 _____ () C:\Users\win7\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-06-09 18:11 - 2018-06-09 18:11 - 000016416 _____ () C:\Users\win7\AppData\Local\InstallationConfiguration.xml
2018-06-09 18:11 - 2018-06-09 18:11 - 000140800 _____ () C:\Users\win7\AppData\Local\installer.dat
2018-06-09 18:11 - 2018-06-09 18:11 - 000018432 _____ () C:\Users\win7\AppData\Local\Main.dat
2018-06-09 18:11 - 2018-06-09 18:11 - 000005568 _____ () C:\Users\win7\AppData\Local\md.xml
2018-06-09 18:11 - 2018-06-09 18:11 - 000126464 _____ () C:\Users\win7\AppData\Local\noah.dat
2018-06-09 18:11 - 2018-06-09 18:11 - 000929792 _____ () C:\Users\win7\AppData\Local\sham.db
2018-06-09 18:11 - 2018-06-09 18:11 - 000278510 _____ () C:\Users\win7\AppData\Local\Stanwarm.tst
2018-06-09 18:11 - 2018-06-09 18:11 - 000032038 _____ () C:\Users\win7\AppData\Local\uninstall_temp.ico
Task: {24C02CF1-DFC7-4B64-8A7E-7965ACB926C2} - System32\Tasks\FastDataX Task => C:\PROGRA~2\FASTDA~1\FASTDA~1.EXE
Task: {282F35E9-F7A8-4374-84C6-4A42DD1B8C81} - System32\Tasks\PPI Update => C:\Windows\explorer.exe "hxxp://windowsdefender.club/warning/download.php?mn=5623" <==== ATTENTION
Task: {2B3CC5D0-3966-4D62-BF6F-B11A3D99C68C} - System32\Tasks\System\SystemChecks => C:\Windows\System32\wscript.exe C:\Users\Public\Libraries\Checks.vbs
Task: {2D675A19-A11D-4507-A9D7-10C55E34E977} - System32\Tasks\Opera scheduled Autoupdate 4086469641 => C:\Windows\system32\cmd.exe /c start "" "C:\Users\win7\AppData\Roaming\Microsoft\Windows\adsviejd\ctavhrbf.exe"
Task: {35493DD8-0565-45BF-A6E4-4DA40D60BAF3} - System32\Tasks\snf => C:\ProgramData\Quoteex\Quoteex.exe <==== ATTENTION
Task: {4881B963-9407-4EBD-802E-A97A813FFDF8} - System32\Tasks\Online Application V2G4 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [2017-11-02] () <==== ATTENTION
Task: {5DE9939A-52AB-4B37-84FA-A2C1AFE61A9B} - System32\Tasks\Online Application V2G3 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [2017-11-02] () <==== ATTENTION
Task: {5F6D8ECE-2A12-4EF7-97E2-98F6B315F6CE} - System32\Tasks\Update_4.0.8 => C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe [2018-06-08] (SystemaRev)
Task: {640547C8-74EE-4931-BD5D-09723CDF4351} - System32\Tasks\Sawmenger XP => C:\Windows\system32\rundll32.exe "C:\Program Files\Sawmenger XP\Sawmenger XP.dll",elnXHi <==== ATTENTION
Task: {6617C6A6-401C-444E-A36B-A64657C9B6E5} - System32\Tasks\Online Application V2G1 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [2017-11-02] () <==== ATTENTION
Task: {71C8EA82-F747-4B9D-BA46-45FC522BC6C7} - System32\Tasks\snp => C:\ProgramData\Quoteex\Quoteex.exe <==== ATTENTION
Task: {855D9CA3-BED3-45ED-8FBF-0E8210BA8A60} - System32\Tasks\Online Application V2G2 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [2017-11-02] () <==== ATTENTION
Task: {995D456F-B957-4D8B-B1F2-0B9AA3CA951A} - System32\Tasks\Online Application V2G5 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [2017-11-02] () <==== ATTENTION
Task: {EA49642B-56ED-4CC7-9068-7627E492675E} - System32\Tasks\MainPMgr => powershell -ExecutionPolicy ByPass -File pm.ps1
Task: {F397F92B-82E0-4CBC-BE3B-56EFA65BDAAB} - System32\Tasks\Updater_Online_Application => C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe [2017-11-02] (Microleaves) <==== ATTENTION
Task: {FD5E3AAA-1BC1-4EEC-94BD-75042D4E22F8} - System32\Tasks\Online Application V2G6 => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe [2017-11-02] () <==== ATTENTION
Task: C:\Windows\Tasks\iToolsDaemon.job => C:\Program Files (x86)\ThinkSky\iTools 3\iToolsDaemon.exe
Task: C:\Windows\Tasks\Online Application V2G1.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
Task: C:\Windows\Tasks\Online Application V2G2.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
Task: C:\Windows\Tasks\Online Application V2G3.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
Task: C:\Windows\Tasks\Online Application V2G4.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
Task: C:\Windows\Tasks\Online Application V2G5.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
Task: C:\Windows\Tasks\Online Application V2G6.job => C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe <==== ATTENTION
Task: C:\Windows\Tasks\Updater_Online_Application.job => C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.exe <==== ATTENTION
ShortcutWithArgument: C:\Users\win7\Desktop\Goodgame Empire.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://empire.goodgamestudios.com/?w=357274
ShortcutWithArgument: C:\Users\win7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> %SNP%
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> %SNP%
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> %SNF%
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> %SNP%
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> %SNF%
C:\Users\win7\AppData\Local\Temp\is-THBTD.tmp\up.exe
C:\ProgramData\Logic Cramble
C:\ProgramData\Dikasio
C:\Program Files\Windows NT
C:\Users\win7\AppData\Local\Temp\FVEJ1NZ1YV
C:\Program Files (x86)\lsJZU
C:\Users\win7\AppData\Roaming\d1pbfumpr2x
C:\Users\win7\AppData\Roaming\a3uaoh4mopl
C:\Users\win7\AppData\Roaming\d0krbp3szxx
C:\Users\win7\AppData\Roaming\gbsr4hbzs4e
C:\Program Files\UFVTZJYYNY
C:\Program Files\SystemaRev
C:\Users\win7\AppData\Roaming\hsnnhmewhxw
C:\Users\win7\AppData\Roaming\vvubncijqd2
C:\Users\win7\AppData\Roaming\4omugn1awyo
C:\Program Files\DIR07Q8Y42
C:\Program Files\ZM6R1CLMCI
C:\Users\win7\AppData\Local\Temp\is-THBTD.tmp\up.exe
C:\Users\win7\AppData\Roaming\fmzgmxjqrl4
C:\Program Files\R6X0PAND02
C:\Users\win7\AppData\Roaming\cjxmrpa20sf\tmzvfpzxdeu.exe
C:\Users\win7\AppData\Local\Temp\is-8HVI6.tmp\tmzvfpzxdeu.tmp
C:\Users\win7\AppData\Roaming\120i322id44\yb4yp0jqhqs.exe
C:\Users\win7\AppData\Local\Temp\is-65LPS.tmp\yb4yp0jqhqs.tmp
C:\Users\win7\AppData\Roaming\jojub30kxnb\bqh45rnuudb.exe
C:\Users\win7\AppData\Local\Temp\is-T2SFV.tmp\bqh45rnuudb.tmp
C:\Program Files\MQK555TIFV
C:\Program Files\DM3SDBRN2N
C:\Users\win7\AppData\Roaming\wi2qpuxupxd\pghyjgysjlw.exe
C:\Users\win7\AppData\Local\Temp\is-J8PC9.tmp\pghyjgysjlw.tmp
C:\Users\win7\AppData\Roaming\ctub1wobjvs\cjmgl40jyem.exe
C:\Users\win7\AppData\Local\Temp\is-JMMCK.tmp\cjmgl40jyem.tmp
(C:\Users\win7\AppData\Roaming\ccc0n12gqok\scgafir1ufo.exe
(C:\Users\win7\AppData\Local\Temp\is-F7CRU.tmp\scgafir1ufo.tmp
C:\Program Files\6W1IJ1HNXP
C:\Program Files\ZWJ39965AD
C:\Program Files\Sawmenger XP
C:\ProgramData\Quoteex
C:\Windows\System32\mcicda64.dll
C:/ProgramData/Quoteexs
C:\Users\Public\Libraries\Checks.vbs
C:\Users\win7\AppData\Roaming\Microsoft\Windows\adsviejd
C:\Program Files (x86)\Microleaves
End
U okviru Notepad-a klikni na File --> Save As
Pod Encoding izaberi UTF-8.
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).
|