46 crva nađeno lepteje
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 5/24/2016
Scan Time: 1:06 PM
Logfile:
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.05.24.03
Rootkit Database: v2016.05.20.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 10
CPU: x64
File System: NTFS
User: HP
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 366980
Time Elapsed: 37 min, 1 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.Ghokswa.Gen, C:\ProgramData\Guntony\protect\protect.exe, 6224, , [fdb690494c4d999d72fb30a9a65dc739]
Modules: 0
(No malicious items detected)
Registry Keys: 13
PUP.Optional.Ghokswa.Gen, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Guntony_protect, , [fdb690494c4d999d72fb30a9a65dc739],
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{083B7B39-C1A3-41F0-B392-32EFBEBB30B1}, , [fcb78e4ba1f887aff7804d8cf60d0ef2],
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{14FFD870-8BD8-43A4-A5F6-0F867FD4A7C5}, , [7e35a831b7e2ae88324363765ca70ff1],
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4B3A5E80-44DF-43F9-B69D-9F61011004D2}, , [07ac05d40198102677fee6f3d42f22de],
PUP.Optional.TweakBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{DD1EBF84-0789-4FD9-8A0C-CDC5B07674B5}, , [6f44e3f6debb60d6bbd797471de6837d],
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\GuntonyBrowserUpdateCore, , [258e469334653df96c0c0ccd49ba30d0],
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\GuntonyBrowserUpdateUA, , [8c275287643570c682f74f8aeb18e31d],
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\GuntonyCheckTask, , [9c1732a706939d998ded726763a09967],
PUP.Optional.TweakBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\TWEAKBIT\FIXMYPC\Start FixMyPC automatic scanning, , [cbe8b920b5e4de58058e2db1e81bad53],
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}, , [63507b5e732680b6ecec3180ed15e020],
PUP.Optional.TweakBit, HKLM\SOFTWARE\WOW6432NODE\TWEAKBIT\ATPopups, , [1b98f4e5a6f3b87e0219b0fd35cd6d93],
PUP.Optional.TweakBit, HKLM\SOFTWARE\WOW6432NODE\TWEAKBIT\ATUpdaters, , [6c470fca841550e6c42a7525bf44c43c],
PUP.Optional.TweakBit, HKLM\SOFTWARE\WOW6432NODE\TWEAKBIT\Google Analytics Package, , [7d3631a878213bfbc9270298748f738d],
Registry Values: 10
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{083B7B39-C1A3-41F0-B392-32EFBEBB30B1}|Path, \GuntonyCheckTask, , [fcb78e4ba1f887aff7804d8cf60d0ef2]
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{14FFD870-8BD8-43A4-A5F6-0F867FD4A7C5}|Path, \GuntonyBrowserUpdateCore, , [7e35a831b7e2ae88324363765ca70ff1]
PUP.Optional.Ghokswa.Gen, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4B3A5E80-44DF-43F9-B69D-9F61011004D2}|Path, \GuntonyBrowserUpdateUA, , [07ac05d40198102677fee6f3d42f22de]
PUP.Optional.TweakBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{DD1EBF84-0789-4FD9-8A0C-CDC5B07674B5}|Path, \TweakBit\FixMyPC\Start FixMyPC automatic scanning, , [6f44e3f6debb60d6bbd797471de6837d]
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|hp,
http://www.yessearches.com/?ts=AHEq...50CF1CBB994B517C4816A&ptid=wak&mode=ffsengext, , [63507b5e732680b6ecec3180ed15e020]
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|tab,
http://www.yessearches.com/?ts=AHEq...50CF1CBB994B517C4816A&ptid=wak&mode=ffsengext, , [654ec811e8b106305880a70a40c2669a]
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|sp, http://www.yessearches.com/chrome.php?uid=25FB425D27E50CF1CBB994B517C4816A&ptid=wak&q={searchTerms}&ts=AHEqAn4rAXYmBU..&v=20160513&mode=ffsengext, , [ded56970485190a67464ab06c53d857b]
PUP.Optional.YesSearches, HKLM\SOFTWARE\MOZILLA\FIREFOX\{EB52F1AB-3C2B-424F-9794-833C687025CF}|surl,
http://www.yessearches.com/chrome.p...qAn4rAXYmBU..&v=20160513&mode=ffexttoolbar&q=, , [fbb800d9b7e26ec8e9ef2988ad553cc4]
PUP.Optional.xRocketToolbar, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|arthurj8283@gmail.com, C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\smggnx76.default\extensions\arthurj8283@gmail.com, , [2b88c217b6e3f54131f73b785da54db3]
PUM.Optional.LowRiskFileTypes, HKU\S-1-5-21-2519315359-960235382-301679856-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LowRiskFileTypes, .avi;.bat;.com;.cmd;.exe;.htm;.html;.lnk;.mpg;.mpeg;.mov;.mp3;.msi;.m3u;.rar;.reg;.txt;.vbs;.wav;.zip;, , [872ca6330693b1859ad5d2e526dd9769]
Registry Data: 0
(No malicious items detected)
Folders: 2
PUP.Optional.Ghokswa.Gen, C:\ProgramData\Guntony\protect, , [fdb690494c4d999d72fb30a9a65dc739],
PUP.Optional.Ghokswa.Gen, C:\ProgramData\Guntony, , [fdb690494c4d999d72fb30a9a65dc739],
Files: 20
PUP.Optional.Elex, C:\Program Files (x86)\Reikuchreawopy\trz7188.tmp, , [e2d106d39bfe1323b391f7c79f62659b],
Trojan.Dropper.IR, C:\Users\HP\AppData\Local\Temp\frag.exe, , [e7cc6277d5c4c96d9c4d6760867b758b],
PUP.Optional.TweakBit, C:\Users\HP\AppData\Local\Temp\pc-cleaner-setup.exe, , [e0d32baed0c90b2b33e55f0a867ef709],
Trojan.Dropper.IR, C:\Users\HP\AppData\Local\Temp\_ir_sf_temp_1\after.exe, , [12a1a2372c6d49ed9e72e2e6af52e61a],
PUP.Optional.Ghokswa.Gen, C:\ProgramData\Guntony\protect\protect.exe, , [fdb690494c4d999d72fb30a9a65dc739],
PUP.Optional.Ghokswa.Gen, C:\Windows\System32\Tasks\GuntonyBrowserUpdateCore, , [f3c0c2173861979f1857499040c3649c],
PUP.Optional.Ghokswa.Gen, C:\Windows\System32\Tasks\GuntonyBrowserUpdateUA, , [6b48c811edac082e690712c74db64cb4],
PUP.Optional.Ghokswa.Gen, C:\Windows\System32\Tasks\GuntonyCheckTask, , [43701dbc46534bebadc49841d1329b65],
PUP.Optional.Ghokswa.Gen, C:\Windows\Tasks\GuntonyBrowserUpdateCore.job, , [7c37617899004aecb3bfd900986b05fb],
PUP.Optional.Ghokswa.Gen, C:\Windows\Tasks\GuntonyBrowserUpdateUA.job, , [ddd64198afea1f17fd76c019709339c7],
PUP.Optional.Ghokswa.Gen, C:\Windows\Tasks\GuntonyCheckTask.job, , [981bd6039ffa5dd9264e36a313f08d73],
PUP.Optional.GsearchFinder, C:\Users\HP\AppData\Roaming\Profiles\yzzfdyu4.default\extensions\@E9438230-A7DF-4D1F-8F2D-CA1D0F0F7924.xpi, , [9d16a237336648eef23ca03ffb08768a],
PUP.Optional.Amonetize, C:\Users\HP\AppData\Local\Temp\amipixel.cfg, , [595a756429702610c6743e353acafa06],
PUP.Optional.YesSearches, C:\Users\HP\AppData\Roaming\Profiles\yzzfdyu4.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "http://www.yessearches.com/?ts=AHEqAn4rAXYmBU..&v=20160513&uid=25FB425D27E50CF1CBB994B517C4816A&ptid=wak&mode=loadm")

, ,[5b58b1284158e3534e04452fe51fc53b]
PUP.Optional.YesSearches, C:\Users\HP\AppData\Roaming\Profiles\yzzfdyu4.default\prefs.js, Good: (), Bad: (erification", 1459858112);
user_pref("browser.bookmarks.restore_default_bookmarks", false);
user_pref("browser.cache.disk.capacity", 358400);
user_pref("browser), ,[b0034594940545f1fa58591b3fc5956b]
PUP.Optional.YesSearches, C:\Users\HP\AppData\Roaming\Profiles\yzzfdyu4.default\prefs.js, Good: (), Bad: (le while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
*/
u), ,[d5de08d12475171f51016f05f113c23e]
PUP.Optional.YesSearches, C:\Users\HP\AppData\Roaming\Profiles\yzzfdyu4.default\prefs.js, Good: (), Bad: (ake a manual change to preferences, you can visit the URL about:config
*/
user_pref("accessibility.typeaheadfind", true);
user_pref("app.update.auto", false);
user_pref("app.update.enable), ,[753e9c3d207992a457fbe78d54b016ea]
PUP.Optional.YesSearches, C:\Users\HP\AppData\Roaming\Profiles\yzzfdyu4.default\prefs.js, Good: (), Bad: (f("app.update.lastUpdateTime.addon-background-update-timer", 1459857872);
user_pref("app.update.lastUpdateTime.background-update-timer", 1459857631);
user_), ,[b5fe15c49cfd5cda8bc71a5a709426da]
PUP.Optional.YesSearches, C:\Users\HP\AppData\Roaming\Profiles\yi6l10jf.default\searchplugins\y4bh1vc8.xml, , [a90afcdde7b248ee2be9650f17edd52b],
PUP.Optional.YesSearches, C:\Users\HP\AppData\Roaming\Profiles\yzzfdyu4.default\searchplugins\y4bh1vc8.xml, , [71428b4ec3d6b48255bf75ffc63ed62a],
Physical Sectors: 0
(No malicious items detected)
(end)