Skocz do zawartości

Problem z app_loader i Windows


Rekomendowane odpowiedzi

Witam znajomy zostawił u mnie komputer i próbuje coś z nim zrobić. Instalował jakieś programy do łamania haseł i efekt jest taki, że system wygląda jakby chodził w trybie awaryjnym, ale nie jest to tryb awaryjny(jak wygląda w załączniku) oraz wirus/wirusy, app_loader którego mogę wyłączyć procesach ale nie mogę usunąć z Program files/ systema rev. Ręcznie pousuwałem to co się doinstalowało do przeglądarki, i ADWCleaner też usunął parę rzeczy i wpisów z rejestru.

post-18417-0-25174700-1531053316_thumb.png

post-18417-0-35383800-1531053635_thumb.png

post-18417-0-01961400-1531053649_thumb.png

Addition.txt

FRST.txt

Shortcut.txt

Odnośnik do komentarza
Pomoc jest darmowa, ale proszę rozważ przekazanie dotacji na utrzymanie serwisu: klik.

Uruchom FRST. NA klawiaturze naciśnij jednocześnie CTRL+Y.

Otworzy się Notatnik - wklej do niego:

Task: {20C9DDF7-4B00-490E-8A24-DA980389D90D} - System32\Tasks\{A7274E71-EEF0-4A45-8FC8-E4CE1B4067A8} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\tkJZqDYhWuUn\bsNLFgtNHd.exe" -c /raun
Task: {2AC3AB43-C746-4B29-9DF4-B151B0C9F6F0} - System32\Tasks\MgpeKOGXlCeKqpkYxSV2 => rundll32 "C:\Program Files (x86)\zfLNassuzpDxC\upWFfNi.dll",#1
Task: {5505B30D-A069-43FC-96F7-0CCBE2663C1E} - System32\Tasks\PPejCupzujabRKM2 => rundll32 "C:\Program Files (x86)\CJkSCRmZU\GbHPIR.dll",#1
Task: {5FF4B3B8-1DC0-4BD2-A3EF-899C3256ED01} - System32\Tasks\kxand => C:\Users\Yama72\AppData\Roaming\yqltg\kxand.vbs [2018-07-06] ()
Task: {639167C9-4FC3-43BC-8A9A-C3EE55043470} - System32\Tasks\Bid-i-War => C:\Windows\system32\rundll32.exe "C:\Program Files\Bid-i-War\Bid-i-War.dll",AgzPkPQYjnm <==== UWAGA
Task: {9A9683C4-28A7-42A4-B624-F1EE297DC23B} - System32\Tasks\EqpFSOLlowVuQ2 => C:\Windows\system32\wscript.exe "C:\ProgramData\qddGHEDCBPKSMPVB\alSZnlU.wsf"
Task: {AFDCEAAB-E096-4395-B8DC-945DB05A89B0} - System32\Tasks\RestoreRevTask => C:\Program Files\Common Files\restore_rev.bat [2018-06-24] () <==== UWAGA
Task: {B0DD32D8-2E63-4114-96B6-2A97077FBD94} - System32\Tasks\Fundoli Fission XBP3100 Series => C:\Windows\system32\rundll32.exe "C:\Program Files\Fundoli Fission XBP3100 Series\Fundoli Fission XBP3100 Series.dll",ytjqwIL <==== UWAGA
Task: {B593311B-AB16-4004-92A7-5FBFE6ED9835} - System32\Tasks\Update_5.0.6 => C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe [2018-07-02] (SystemaRev)
Task: {C0460791-8AC2-4106-A6D6-3E9B35AEEE7F} - System32\Tasks\heCowIfQqSuzYJ => rundll32 "C:\Program Files (x86)\yaolwXGxxrAU2\HGObPHBPFIvRK.dll",#1
Task: {CC09BF15-963A-43EE-88B5-C0918F6F8C33} - System32\Tasks\Bid-i-War-dll => C:\Windows\system32\rundll32.exe "C:\Program Files\Bid-i-War\Bid-i-War.dll",AgzPkPQYjnm
Task: {DCAD7867-8795-4CD7-9282-892E35665422} - System32\Tasks\AppLoaderPM => C:\Program Files\SystemaRev\RevServicesX\app_loader.exe [2018-07-02] ()
Task: {E73CBA8F-EAD1-494B-AC35-4E386416EAAD} - System32\Tasks\dqUvxAMLDajqkAKky2 => rundll32 "C:\Program Files (x86)\ggyoEsstymMAtvJtmyR\MQhOeyy.dll",#1
RemoveDirectory: C:\Program Files (x86)\zfLNassuzpDxC
RemoveDirectory: C:\Program Files (x86)\tkJZqDYhWuUn
RemoveDirectory: C:\Program Files (x86)\CJkSCRmZU
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\yqltg
RemoveDirectory: C:\Program Files\Bid-i-War
RemoveDirectory: C:\ProgramData\qddGHEDCBPKSMPVB
RemoveDirectory: C:\Program Files\Fundoli Fission XBP3100 Series
RemoveDirectory: C:\Program Files (x86)\ggyoEsstymMAtvJtmyR
RemoveDirectory: C:\Program Files\SystemaRev
RemoveDirectory: C:\Program Files (x86)\yaolwXGxxrAU2
RemoveDirectory: C:\Program Files\DAEMON Tools Lite\8LX7TQ6F61J
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\orsfv2vsqxv
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\cxyp1qtbrjp
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\hqxff2hgs4j
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\n02thuwrske
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\e1nt14a0u15
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\mukipk3patl
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\wiqpntdu4p3
RemoveDirectory: C:\Program Files\I95KF1FMK2
RemoveDirectory: C:\Users\Yama72\AppData\LocalLow\cnOgaNtVaNULS
RemoveDirectory: C:\Program Files (x86)\yaolwXGxxrAU2
RemoveDirectory: C:\Program Files (x86)\szukwmZlgIE
RemoveDirectory: C:\ProgramData\qddGHEDCBPKSMPVB
RemoveDirectory: C:\Program Files (x86)\CJkSCRmZU
RemoveDirectory: C:\Program Files\YA3Y70BVMP
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\mukipk3patl
RemoveDirectory: C:\Program Files\S74MZQXZWG
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\bmjswq4utmf
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\zgycmuhyyxi
RemoveDirectory: C:\Program Files\4JMORKMC0X
RemoveDirectory: C:\ProgramData\dec5f87f-7c1a-45d2-bbb0-52d9d01ae1ab
RemoveDirectory: C:\Program Files\L16BTVLRMM
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\e1nt14a0u15
RemoveDirectory: C:\ProgramData\cdf5afe3-52c4-4927-897b-86969a4c8d48
RemoveDirectory: C:\Program Files\DUFG3LEOS5
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\x31pl2054vf
RemoveDirectory: C:\Program Files\ANJZQWKKFH
RemoveDirectory: C:\Program Files\ZF9QEFIAL7
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\hqxff2hgs4j
RemoveDirectory: C:\Program Files\2G9OZGSPRK
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\cxyp1qtbrjp
RemoveDirectory: C:\Program Files\X6D26B9R7J
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\orsfv2vsqxv
RemoveDirectory: C:\Users\Yama72\AppData\Roaming\xtwaiyeh2y4
RemoveDirectory: C:\Program Files\0IIQKBM8CU
RemoveDirectory: C:\Program Files (x86)\Kbira
RemoveDirectory: C:\Program Files (x86)\Multitimer
RemoveDirectory: C:\Program Files (x86)\foldershare
RemoveDirectory: C:\Users\Public\Documents\XMUpdate
C:\Users\Yama72\AppData\Local\sham.db
C:\Users\Yama72\AppData\Local\installer.dat
C:\Program Files\Common Files\restore_rev.bat
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\StartupApproved\Run: => "2989931"
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\StartupApproved\Run: => "4427524"
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\StartupApproved\Run: => "5247568"
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\StartupApproved\Run: => "5567072"
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\StartupApproved\Run: => "799133"
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\StartupApproved\Run: => "9575678"
FirewallRules: [{432001F1-1BFD-4502-A9ED-CC0C1DBA32BD}] => (Allow) C:\Windows\system32\rundll32.exe
FirewallRules: [{540F2DB2-CE4D-4D40-A37B-A6BB2FEF6681}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{D0DE611F-C817-4581-881D-66ACF5DBF620}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{03007955-8BCD-4D85-8C0E-8DF209EE0DBB}] => (Allow) C:\Program Files\SystemaRev\RevServicesX\app_loader.exe
FirewallRules: [{278FD2B2-9872-47A8-AB71-6FF930E90BB6}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{DDC7A800-6E18-4F60-893D-60230CA56D0E}] => (Allow) C:\Windows\System32\rundll32.exe
HKLM\...\Run: [rundll32] => C:\Windows\system32\rundll32.exe "C:\Program Files\Fundoli Fission XBP3100 Series\Fundoli Fission XBP3100 Series.dll",ytjqwIL
HKLM\...\Run: [JServicesManager] => C:\Program Files\SystemaRev\RevServicesX\App_loader.ex
HKLM-x32\...\Run: [JServicesManager] => C:\Program Files\SystemaRev\RevServicesX\App_loader.ex
HKLM\ DisallowedCertificates: 03D22C9C66915D58C88912B64C1F984B8344EF09 (Comodo Security Solutions) <==== UWAGA
HKLM\ DisallowedCertificates: 0F684EC1163281085C6AF20528878103ACEFCAAB (F-Secure Corporation) <==== UWAGA
HKLM\ DisallowedCertificates: 1667908C9E22EFBD0590E088715CC74BE4C60884 (FRISK Software International/F-Prot) <==== UWAGA
HKLM\ DisallowedCertificates: 18DEA4EFA93B06AE997D234411F3FD72A677EECE (Bitdefender SRL) <==== UWAGA
HKLM\ DisallowedCertificates: 2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF (G DATA Software AG) <==== UWAGA
HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== UWAGA
HKLM\ DisallowedCertificates: 31AC96A6C17C425222C46D55C3CCA6BA12E54DAF (Symantec Corporation) <==== UWAGA
HKLM\ DisallowedCertificates: 331E2046A1CCA7BFEF766724394BE6112B4CA3F7 (Trend Micro) <==== UWAGA
HKLM\ DisallowedCertificates: 3353EA609334A9F23A701B9159E30CB6C22D4C59 (Webroot Inc.) <==== UWAGA
HKLM\ DisallowedCertificates: 373C33726722D3A5D1EDD1F1585D5D25B39BEA1A (SUPERAntiSpyware.com) <==== UWAGA
HKLM\ DisallowedCertificates: 3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F (Kaspersky Lab) <==== UWAGA
HKLM\ DisallowedCertificates: 3D496FA682E65FC122351EC29B55AB94F3BB03FC (AVG Technologies CZ) <==== UWAGA
HKLM\ DisallowedCertificates: 4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 (PC Tools) <==== UWAGA
HKLM\ DisallowedCertificates: 42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 (K7 Computing Pvt Ltd) <==== UWAGA
HKLM\ DisallowedCertificates: 4420C99742DF11DD0795BC15B7B0ABF090DC84DF (Doctor Web Ltd.) <==== UWAGA
HKLM\ DisallowedCertificates: 4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF (Emsisoft Ltd) <==== UWAGA
HKLM\ DisallowedCertificates: 5240AB5B05D11B37900AC7712A3C6AE42F377C8C (Check Point Software Technologies Ltd.) <==== UWAGA
HKLM\ DisallowedCertificates: 5DD3D41810F28B2A13E9A004E6412061E28FA48D (Emsisoft Ltd) <==== UWAGA
HKLM\ DisallowedCertificates: 7457A3793086DBB58B3858D6476889E3311E550E (K7 Computing Pvt Ltd) <==== UWAGA
HKLM\ DisallowedCertificates: 76A9295EF4343E12DFC5FE05DC57227C1AB00D29 (BullGuard Ltd) <==== UWAGA
HKLM\ DisallowedCertificates: 775B373B33B9D15B58BC02B184704332B97C3CAF (McAfee) <==== UWAGA
HKLM\ DisallowedCertificates: 872CD334B7E7B3C3D1C6114CD6B221026D505EAB (Comodo Security Solutions) <==== UWAGA
HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== UWAGA
HKLM\ DisallowedCertificates: 9132E8B079D080E01D52631690BE18EBC2347C1E (Adaware Software) <==== UWAGA
HKLM\ DisallowedCertificates: 982D98951CF3C0CA2A02814D474A976CBFF6BDB1 (Safer Networking Ltd.) <==== UWAGA
HKLM\ DisallowedCertificates: 9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 (Webroot Inc.) <==== UWAGA
HKLM\ DisallowedCertificates: 9C43F665E690AB4D486D4717B456C5554D4BCEB5 (ThreatTrack Security) <==== UWAGA
HKLM\ DisallowedCertificates: 9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 (CURIOLAB S.M.B.A.) <==== UWAGA
HKLM\ DisallowedCertificates: A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 (Avira Operations GmbH & Co. KG) <==== UWAGA
HKLM\ DisallowedCertificates: A5341949ABE1407DD7BF7DFE75460D9608FBC309 (BullGuard Ltd) <==== UWAGA
HKLM\ DisallowedCertificates: A59CC32724DD07A6FC33F7806945481A2D13CA2F (ESET) <==== UWAGA
HKLM\ DisallowedCertificates: AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 (AVG Technologies CZ) <==== UWAGA
HKLM\ DisallowedCertificates: AD4C5429E10F4FF6C01840C20ABA344D7401209F (Avast Antivirus/Software) <==== UWAGA
HKLM\ DisallowedCertificates: AD96BB64BA36379D2E354660780C2067B81DA2E0 (Symantec Corporation) <==== UWAGA
HKLM\ DisallowedCertificates: B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 (Malwarebytes Corporation) <==== UWAGA
HKLM\ DisallowedCertificates: CDC37C22FE9272D8F2610206AD397A45040326B8 (Trend Micro) <==== UWAGA
HKLM\ DisallowedCertificates: D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 (Kaspersky Lab) <==== UWAGA
HKLM\ DisallowedCertificates: DB303C9B61282DE525DC754A535CA2D6A9BD3D87 (ThreatTrack Security) <==== UWAGA
HKLM\ DisallowedCertificates: DB77E5CFEC34459146748B667C97B185619251BA (Avast Antivirus/Software) <==== UWAGA
HKLM\ DisallowedCertificates: E22240E837B52E691C71DF248F12D27F96441C00 (Total Defense, Inc.) <==== UWAGA
HKLM\ DisallowedCertificates: E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF (AVG Technologies CZ) <==== UWAGA
HKLM\ DisallowedCertificates: ED841A61C0F76025598421BC1B00E24189E68D54 (Bitdefender SRL) <==== UWAGA
HKLM\ DisallowedCertificates: F83099622B4A9F72CB5081F742164AD1B8D048C9 (ESET) <==== UWAGA
HKLM\ DisallowedCertificates: FBB42F089AF2D570F2BF6F493D107A3255A9BB1A (Panda Security S.L) <==== UWAGA
HKLM\ DisallowedCertificates: FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 (Doctor Web Ltd.) <==== UWAGA
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Ograniczenia <==== UWAGA
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\Run: [k6nL4Dy3c2.exe] => C:\Program Files\DAEMON Tools Lite\8LX7TQ6F61J\k6nL4Dy3c2.exe
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\Run: [5247568] => "C:\Users\Yama72\AppData\Roaming\orsfv2vsqxv\hunwb0wspn3.exe" /VERYSILENT
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\Run: [2989931] => "C:\Users\Yama72\AppData\Roaming\cxyp1qtbrjp\0fkwxykz5zo.exe" /VERYSILENT
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\Run: [4427524] => "C:\Users\Yama72\AppData\Roaming\hqxff2hgs4j\4muhfad3udg.exe" /VERYSILENT
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\Run: [5567072] => "C:\Users\Yama72\AppData\Roaming\n02thuwrske\v5wcw3jpq2r.exe" /VERYSILENT
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\Run: [9575678] => "C:\Users\Yama72\AppData\Roaming\e1nt14a0u15\bbro2gkbcmc.exe" /VERYSILENT
HKU\S-1-5-21-585497507-2271305030-2490774745-1001\...\Run: [799133] => "C:\Users\Yama72\AppData\Roaming\mukipk3patl\00oyndjh2g1.exe" /VERYSILENT
GroupPolicy: Ograniczenia - Chrome <==== UWAGA
CHR HKLM\SOFTWARE\Policies\Google: Ograniczenia <==== UWAGA
FF user.js: detected! => C:\Users\Yama72\AppData\Roaming\Mozilla\Firefox\Profiles\3nhh07ui.default\user.js [2016-10-25]
CHR Extension: (Adblocker for Youtube™) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\Default\Extensions\dccefhjaifdmpkjcbiojjennojmedchc [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
CHR Extension: (Brak nazwy) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\Guest Profile\Extensions\dfkbibfnelggjiagnbapfoodmhhnedfa [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
CHR Extension: (Adblocker for Youtube™) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\dccefhjaifdmpkjcbiojjennojmedchc [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
S3 SystemUpdate64; C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe [593920 2018-07-02] (SystemaRev) [brak podpisu cyfrowego] <==== UWAGA
S1 prisafe; \SystemRoot\System32\drivers\prisafe.sys [X]
HOSTS:
EmptyTemp:


Na klawiaturze naciśnij jednocześnie CTRL+S. W FRST kliknij na Fix (NAPRAW).

 

Zrób nowe logi FRST.

 

jessi

Odnośnik do komentarza

Uruchom FRST. NA klawiaturze naciśnij jednocześnie CTRL+Y.
Otworzy się Notatnik - wklej do niego:

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NAPI-PROJEKT\Napi-projekt.lnk
DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1655C0CA-7AE7-4012-8502-970C8675E5F8
DeleteKey: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\1655C0CA-7AE7-4012-8502-970C8675E5F8
Task: {AE4144C0-4081-44CA-83DF-46AE02593890} - System32\Tasks\AppLoaderHelpers => C:\Program Files\SystemaRev\RevServicesX\app_loader.exe
RemoveDirectory: C:\Program Files\SystemaRev
Task: C:\Windows\Tasks\Bid-i-War.job => rundll32.exe  C:\Program Files\Bid-i-War\Bid-i-War.dll
RemoveDirectory: C:\Program Files\Bid-i-War
CHR Extension: (Adblocker for Youtube™) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\Default\Extensions\dccefhjaifdmpkjcbiojjennojmedchc [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
CHR Extension: (Adblocker for Youtube™) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\dccefhjaifdmpkjcbiojjennojmedchc [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
R2 winamgr; C:\ProgramData\Microsoft\Windows\Audio\winamgr.exe [10415104 2018-07-05] (Microsoft Corporation) [brak podpisu cyfrowego] <==== UWAGA
C:\ProgramData\Microsoft\Windows\Audio\winamgr.exe
EmptyTemp:


Na klawiaturze naciśnij jednocześnie CTRL+S. W FRST kliknij na Fix (NAPRAW).

 

Zrób nowe logi FRST - już bez Shortcut.

 

jessi

Odnośnik do komentarza

1) Uruchom FRST. NA klawiaturze naciśnij jednocześnie CTRL+Y.
Otworzy się Notatnik - wklej do niego:

RevServicesX (HKLM\...\{66D48499-AFBE-47BB-887D-EA964982737B}) (Version: 5.0.6 - SystemaRev) Hidden
CHR Extension: (Adblocker for Youtube™) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\Default\Extensions\dccefhjaifdmpkjcbiojjennojmedchc [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\Default\Extensions\dccefhjaifdmpkjcbiojjennojmedchc
CHR Extension: (Brak nazwy) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\Guest Profile\Extensions\dfkbibfnelggjiagnbapfoodmhhnedfa [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
CHR Extension: (Adblocker for Youtube™) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\dccefhjaifdmpkjcbiojjennojmedchc [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA
2018-07-08 16:35 - 2018-07-08 16:35 - 000000002 _____ C:\Users\Yama72\Downloads\louprnmrdzxw.txt
2018-07-08 16:18 - 2018-07-08 16:18 - 000000116 _____ C:\Users\Yama72\Desktop\asdasdas.txt
2018-07-08 16:05 - 2018-07-08 16:05 - 000013473 _____ C:\Users\Yama72\Downloads\ehuavirymcfkez.txt
EmptyTemp:


Na klawiaturze naciśnij jednocześnie CTRL+S. W FRST kliknij na Fix (NAPRAW).
 

 

2)

RevServicesX (HKLM\...\{66D48499-AFBE-47BB-887D-EA964982737B}) (Version: 5.0.6 - SystemaRev) Hidden

Ten program powinien się teraz pokazać, więc go odinstaluj.

 

3) Zrób nowe logi FRST - bez Shortcut.

 

jessi
 

Odnośnik do komentarza
RemoveDirectory: C:\ProgramData\rvlkl

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\rvlkl.lnk [2018-07-07]

ShortcutTarget: rvlkl.lnk -> C:\ProgramData\rvlkl\rvlkl.exe (Logixoft)

018-07-07 13:31 - 2018-07-07 13:32 - 000000000 ____D C:\ProgramData\rvlkl

2018-07-07 13:30 - 2018-07-07 13:30 - 000114688 _____ C:\Users\Yama72\Downloads\fk.exe

2018-07-07 13:27 - 2018-07-07 13:27 - 001411136 _____ (Logixoft) C:\Users\Yama72\Downloads\rkfree_setup(dobreprogramy.pl).exe

Ja daję to do usuwania "Relevant Knowledge", ale jeśli chcesz go zostawić, to te linijki usuniesz z "fixlist".

 

Uruchom FRST. NA klawiaturze naciśnij jednocześnie CTRL+Y.

Otworzy się Notatnik - wklej do niego:

 

CHR Extension: (Adblocker for Youtube™) - C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\dccefhjaifdmpkjcbiojjennojmedchc [2018-07-07] [updateUrl: hxxps://clients88.google.com/service/update2/crx] <==== UWAGA

C:\Users\Yama72\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\dccefhjaifdmpkjcbiojjennojmedchc

RemoveDirectory: C:\ProgramData\rvlkl

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\rvlkl.lnk [2018-07-07]

ShortcutTarget: rvlkl.lnk -> C:\ProgramData\rvlkl\rvlkl.exe (Logixoft)

018-07-07 13:31 - 2018-07-07 13:32 - 000000000 ____D C:\ProgramData\rvlkl

2018-07-07 13:30 - 2018-07-07 13:30 - 000114688 _____ C:\Users\Yama72\Downloads\fk.exe

2018-07-07 13:27 - 2018-07-07 13:27 - 001411136 _____ (Logixoft) C:\Users\Yama72\Downloads\rkfree_setup(dobreprogramy.pl).exe

EmptyTemp:

 

 

Na klawiaturze naciśnij jednocześnie CTRL+S. W FRST kliknij na Fix (NAPRAW).

 

Jeśli w Chrome dalej będą reklamy, to przeinstalujesz go.

 

jessi

Odnośnik do komentarza

Jeśli chcesz dodać odpowiedź, zaloguj się lub zarejestruj nowe konto

Jedynie zarejestrowani użytkownicy mogą komentować zawartość tej strony.

Zarejestruj nowe konto

Załóż nowe konto. To bardzo proste!

Zarejestruj się

Zaloguj się

Posiadasz już konto? Zaloguj się poniżej.

Zaloguj się
  • Ostatnio przeglądający   0 użytkowników

    • Brak zarejestrowanych użytkowników przeglądających tę stronę.
×
×
  • Dodaj nową pozycję...