Poslao: 15 Mar 2014 22:51
|
offline
- boki199777
- Elitni građanin
- Pridružio: 26 Sep 2012
- Poruke: 1869
- Gde živiš: Ček' da vidim...
|
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01
Ran by G31M at 2014-03-15 22:49:45 Run:2
Running from C:\Users\G31M\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
File: C:\Program Files\Mobogenie\DaemonProcess.exe
Task: {41F44F6C-798B-4EAA-9C4A-206B68458A23} - System32\Tasks\PCRemote Startup Task => C:\Users\G31M\AppData\Local\Temp\Rar$EXa0.318\PCRemoteServer\PCRemoteServer.exe
Folder: C:\Users\G31M\AppData\Local\Temp\Rar$EXa0.318
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully.
========================= File: C:\Program Files\Mobogenie\DaemonProcess.exe ========================
"C:\Program Files\Mobogenie\DaemonProcess.exe" not found.
====== End Of File: ======
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{41F44F6C-798B-4EAA-9C4A-206B68458A23} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41F44F6C-798B-4EAA-9C4A-206B68458A23} => Key deleted successfully.
C:\Windows\System32\Tasks\PCRemote Startup Task => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCRemote Startup Task => Key deleted successfully.
========================= Folder: C:\Users\G31M\AppData\Local\Temp\Rar$EXa0.318 ========================
Directory Not Found
==== End of Fixlog ====
|
|
|
|
Poslao: 15 Mar 2014 23:47
|
offline
- NIx Car
- Legendarni građanin
- Més que un club
- Glavni vokal @ Harpun
- Pridružio: 27 Feb 2009
- Poruke: 3898
- Gde živiš: Novi Sad,Klisa
|
Kakvo je stanje?
|
|
|
|
Poslao: 16 Mar 2014 11:59
|
offline
- boki199777
- Elitni građanin
- Pridružio: 26 Sep 2012
- Poruke: 1869
- Gde živiš: Ček' da vidim...
|
Napisano: 16 Mar 2014 11:33
Podizanje sistema se nesto malo ubrzalo, ali za razliku od pre nego sto se pojavio problem i dalje je sporije. CMD se za sada ne prikazuje
Dopuna: 16 Mar 2014 11:59
I posle svakog podizanja pokazuje mi se greska kao na prvoj slici koju sam okacio.
|
|
|
|
Poslao: 16 Mar 2014 12:14
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Boki da ne cekamo Nix-a pokreni FRST sa ovom skriptom i javi kakvo je stanje posle toga.
HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
HKU\S-1-5-21-2180428478-2044508922-3083944251-1000\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\G31M\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
Task: {41F44F6C-798B-4EAA-9C4A-206B68458A23} - System32\Tasks\PCRemote Startup Task => C:\Users\G31M\AppData\Local\Temp\Rar$EXa0.318\PCRemoteServer\PCRemoteServer.exe <==== ATTENTION
Znaci skriptu nazovi Fixlist i sacuvaj je na istom mestu gde se nalazi FRST.
|
|
|
|
|
|
Poslao: 16 Mar 2014 12:40
|
offline
- boki199777
- Elitni građanin
- Pridružio: 26 Sep 2012
- Poruke: 1869
- Gde živiš: Ček' da vidim...
|
Sta je to stvaralo problem ovde? Vidim da se oko nekog [mobilegeni daemon] vrtelo?
|
|
|
|
|
|
Poslao: 16 Mar 2014 12:45
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Adware ili PUP.
Vodi racuna kod instalacije programa, ako postoji mogucnost uvek idi na custom install i rascekiraj sve nepotrebno sto dolazi sa instalacijom, ako ne, opet vodi racuna jer se oni ogranice pitanjem "da li zelite ovo da instalirate" i naravno ti kliknes na next i to je to a imas mogucnost da rascekiras.
|
|
|
|