Poslao: 10 Maj 2013 14:03
|
offline
- B-u-B-i
- Novi MyCity građanin
- Pridružio: 10 Maj 2013
- Poruke: 4
|
Pozdrav, imam sledeci problem: Znaci kada udjem na FaceBook pocne se slati nekakav link prijateljima u inbox, ja msm da je to neki virus, al nez sta da uradim. Trenutno sam deaktiviro profil radi toga, salje se ko ludo, po 20-30 poruka u 2-3min. Nadam se da cete mi pomoci. Hvala!
DDS (Ver_2012-11-20.01) - FAT32_x86
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 10.17.2
Run by Bojan at 13:44:37 on 2013-05-10
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Bojan.BOJAN-10BB93A0A\Application Data\svchosts.exe
C:\Documents and Settings\Bojan.BOJAN-10BB93A0A\Application Data\nig1.tmp.bat
C:\Documents and Settings\Bojan.BOJAN-10BB93A0A\Application Data\nig2.tmp.bat
C:\DOCUME~1\BOJAN~1.BOJ\LOCALS~1\Temp\minerd.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&CUI=UN33495761603207119&ctid=CT3220468
BHO: {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Microsoft Corp] c:\documents and settings\bojan.bojan-10bb93a0a\application data\svchosts.exe
uRun: [WINSXS32] c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig2.tmp.bat
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [Microsoft Corp] c:\documents and settings\bojan.bojan-10bb93a0a\application data\svchosts.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mExplorerRun: [Microsoft Corp] c:\documents and settings\bojan.bojan-10bb93a0a\application data\svchosts.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{1588775F-0C14-4120-93E6-D33E81EC8F13} : DHCPNameServer = 192.168.1.1
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\bojan.bojan-10bb93a0a\application data\mozilla\firefox\profiles\kqe44taz.default\
FF - plugin: c:\program files\google\update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - ExtSQL: 2013-03-10 19:09; speedanalysis@SpeedAnalysis.com; c:\documents and settings\bojan.bojan-10bb93a0a\application data\mozilla\extensions\speedanalysis@SpeedAnalysis.com
FF - ExtSQL: !HIDDEN! 2013-03-10 19:09; speedanalysis@SpeedAnalysis.com; c:\documents and settings\bojan.bojan-10bb93a0a\application data\mozilla\extensions\speedanalysis@SpeedAnalysis.com
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2013-05-10 09:55:19 88912 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig1.tmp.bat
2013-05-10 09:55:19 300880 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig2.tmp.bat
2013-05-10 09:55:16 0 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig2.tmp
2013-05-10 09:55:16 0 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig1.tmp
2013-05-09 10:52:59 14336 ----a-w- c:\windows\system32\dllcache\tsprof.exe
2013-05-09 10:51:50 7680 ----a-w- c:\windows\system32\dllcache\migregdb.exe
2013-05-09 10:50:59 94208 ----a-w- c:\windows\system32\dllcache\fpencode.dll
2013-05-09 10:49:52 68608 ----a-w- c:\windows\system32\dllcache\isatq.dll
2013-05-09 10:41:24 24661 ----a-w- c:\windows\system32\spxcoins.dll
2013-05-09 10:41:24 24661 ----a-w- c:\windows\system32\dllcache\spxcoins.dll
2013-05-09 10:41:24 13312 ----a-w- c:\windows\system32\irclass.dll
2013-05-09 10:41:24 13312 ----a-w- c:\windows\system32\dllcache\irclass.dll
2013-05-09 10:21:22 -------- d-sh--w- C:\FOUND.005
2013-05-09 09:55:30 88912 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig6.tmp.bat
2013-05-09 09:55:26 0 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig6.tmp
2013-05-09 09:32:24 88912 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig15.tmp.bat
2013-05-09 09:32:22 0 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig15.tmp
2013-05-08 17:21:13 0 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig39E.tmp
2013-05-08 12:10:43 0 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig5.tmp
2013-05-06 19:35:16 -------- d-sh--w- C:\FOUND.004
2013-05-05 20:58:01 0 ----a-w- c:\documents and settings\bojan.bojan-10bb93a0a\application data\nig1918.tmp
2013-05-05 20:42:05 72528 --sh--r- c:\documents and settings\bojan.bojan-10bb93a0a\application data\svchosts.exe
.
==================== Find3M ====================
.
2013-04-05 14:35:38 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-04-05 14:35:36 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-10 17:58:04 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-10 17:58:02 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-10 17:58:00 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-03-10 17:58:00 782240 ----a-w- c:\windows\system32\deployJava1.dll
.
============= FINISH: 13:45:03.99 ===============
mycity.rs/must-login.png
|
|
|
|
|
|
|
|
Poslao: 12 Maj 2013 21:02
|
offline
- TwinHeadedEagle
- Anti Malware Fighter
Rank 2
- Pridružio: 09 Avg 2011
- Poruke: 15879
- Gde živiš: Beograd
|
Mozes li malo bolje da objasnis, sta nije htelo ocitati. Pri pokretanju ili posle...?
|
|
|
|
|
|