anti malware software

anti malware software

offline
  • Pridružio: 14 Maj 2013
  • Poruke: 3

može li neko da mi preporuči efikasan anti malware softver?
koristim windows 7

non stop mi se pojavljuju reklame po stranicama u svim browserima sem u operi. tipa







probala sam malwarebytes, rootkit, hitmanpro, spybot, adwcleaner - nisu ništa pronašli
skenirala sistem kasperskim - opet ništa

hvala unapred na odgovoru

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15874
  • Gde živiš: Beograd

Pozdrav,

Isprati uputstvo i dostavi izvestaje

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 14 Maj 2013
  • Poruke: 3

ne radi link za download dds-a

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15874
  • Gde živiš: Beograd

Preuzmi ga sa ovog linka

https://www.mycity.rs/must-login.png

offline
  • Pridružio: 14 Maj 2013
  • Poruke: 3

Napisano: 14 Maj 2013 17:42

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.21.2
Run by natasa at 17:30:19 on 2013-05-14
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3327.294 [GMT 2:00]
.
AV: Kaspersky Internet Security *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
SP: Kaspersky Internet Security *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Kaspersky Internet Security *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe
C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\Program Files\Online Games Manager\ogmservice.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Program Files\PC Auto Shutdown\ShutdownService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Windows\System32\PAStiSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\Last.fm\Last.fm Scrobbler.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Last.fm\iPodScrobbler.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
uProxyOverride = <local>;*.local
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
uURLSearchHooks: GagetBox: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} -
uURLSearchHooks: SHOUTcast Toolbar Search Class: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
mURLSearchHooks: SHOUTcast Toolbar Search Class: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: GagetBox: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} -
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\contentblocker\ie_content_blocker_plugin.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: SelectionLinks: {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} -
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\onlinebanking\online_banking_bho.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: SHOUTcast Loader: {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
BHO: DVDVideoSoft WebPageAdjuster Class: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
TB: SHOUTcast Radio Toolbar: {0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
TB: SHOUTcast Radio Toolbar: {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
TB: GagetBox: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} -
EB: GagetBox: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} -
uRun: [AdobeBridge] <no file>
uRunOnce: [SpybotDeletingF2165] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\application updater\ApplicationUpdater.exe"
uRunOnce: [SpybotDeletingF4614] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\SearchSettings.exe"
uRunOnce: [SpybotDeletingF8881] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\application updater\config.ini"
uRunOnce: [SpybotDeletingF243] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\baidu_ff.xml"
uRunOnce: [SpybotDeletingF4595] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\baidu_ie.xml"
uRunOnce: [SpybotDeletingF8855] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\config.ini"
uRunOnce: [SpybotDeletingF8356] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\yandex_ff.xml"
uRunOnce: [SpybotDeletingF5794] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1031.ini"
uRunOnce: [SpybotDeletingF2729] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1033.ini"
uRunOnce: [SpybotDeletingF6467] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1034.ini"
uRunOnce: [SpybotDeletingF6914] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1036.ini"
uRunOnce: [SpybotDeletingF9625] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1040.ini"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NBAgent] "c:\program files\nero\nero 10\nero backitup\NBAgent.exe" /WinStart
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [XeroxEndeavorBackgroundTask] rundll32.exe xrWCbgnd.dll,LaunchBgTask 1
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [CloneCDTray] "c:\program files\slysoft\clonecd\CloneCDTray.exe" /s
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [PC Auto Shutdown] "c:\program files\pc auto shutdown\AutoShutdown.exe"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRunOnce: [SpybotDeletingE7657] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\application updater\ApplicationUpdater.exe"
mRunOnce: [SpybotDeletingE4410] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\SearchSettings.exe"
mRunOnce: [SpybotDeletingE8094] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\application updater\config.ini"
mRunOnce: [SpybotDeletingE3522] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\baidu_ff.xml"
mRunOnce: [SpybotDeletingE2308] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\baidu_ie.xml"
mRunOnce: [SpybotDeletingE7921] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\config.ini"
mRunOnce: [SpybotDeletingE6574] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\yandex_ff.xml"
mRunOnce: [SpybotDeletingE4777] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1031.ini"
mRunOnce: [SpybotDeletingE1865] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1033.ini"
mRunOnce: [SpybotDeletingE2884] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1034.ini"
mRunOnce: [SpybotDeletingE7923] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1036.ini"
mRunOnce: [SpybotDeletingE8051] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1040.ini"
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: &SHOUTcast Search - c:\programdata\shoutcast radio toolbar\ietoolbar\resources\en-us\local\search.html
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2013\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\program files\common files\dvdvideosoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files\common files\dvdvideosoft\plugins\freeytmp3downloader.htm
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{2CB6F41B-FE32-4096-BD06-962216A6F48D} : DHCPNameServer = 192.168.55.1 89.216.1.40 89.216.1.50
TCP: Interfaces\{3E169190-C5B0-43F9-BAA5-B072BFEE86D2} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{4EE31D81-CAD7-493A-81A7-5AC370F44C3B} : DHCPNameServer = 192.168.55.1 89.216.1.40 89.216.1.50
TCP: Interfaces\{A0805690-122D-44C8-800F-3958E5D330DA} : NameServer = 192.168.1.1
TCP: Interfaces\{FB15C35E-4D57-4305-84B5-989F66F42AE3} : DHCPNameServer = 192.168.55.1 89.216.1.40 89.216.1.50
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\nokia\nokia suite\npNokiaSuiteEnabler.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\natasa\appdata\local\facebook\messenger\2.1.4814.0\npFbDesktopPlugin.dll
FF - plugin: c:\users\natasa\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\users\natasa\appdata\local\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\plugins\np-mswmp.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\plugins\np-mswmp.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\plugins\npo1d.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - ExtSQL: 2013-05-09 02:53; {DF53B24E-E1CD-428F-8B13-57E04022F1AF}; c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\extensions\{DF53B24E-E1CD-428F-8B13-57E04022F1AF}
FF - ExtSQL: 2013-05-09 20:07; addon@defaulttab.com; c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\extensions\addon@defaulttab.com.xpi
.
============= SERVICES / DRIVERS ===============
.
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-4-14 45736]
.
=============== Created Last 30 ================
.
2013-05-14 11:48:28 6906960 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{f1d26336-996b-44b4-9002-877077a901ea}\mpengine.dll
2013-05-14 11:47:56 -------- d-----w- C:\cf00bb78987c96ca2bfca3cf3102270f
2013-05-13 20:13:59 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-05-13 20:13:20 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-05-13 20:13:05 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-05-13 19:46:43 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-05-13 19:38:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-13 19:38:54 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-13 17:54:58 -------- d-----w- c:\windows\ELAMBKUP
2013-05-13 17:54:44 -------- d-----w- c:\programdata\Kaspersky Lab
2013-05-13 17:54:44 -------- d-----w- c:\program files\Kaspersky Lab
2013-05-13 17:54:18 74848 ----a-w- c:\windows\system32\drivers\klflt.sys
2013-05-10 18:01:53 30464 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys
2013-05-10 17:49:20 -------- d-----w- c:\program files\HitmanPro
2013-05-10 17:48:51 -------- d-----w- c:\programdata\HitmanPro
2013-05-09 18:40:46 -------- d-----w- c:\users\natasa\appdata\roaming\Malwarebytes
2013-05-09 18:40:25 -------- d-----w- c:\programdata\Malwarebytes
2013-05-09 18:40:19 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-05-09 18:40:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-05-09 00:54:53 -------- d-----w- c:\programdata\PC Auto Shutdown
2013-05-09 00:54:53 -------- d-----w- c:\program files\PC Auto Shutdown
2013-05-07 01:03:38 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-01 13:11:12 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-05-01 13:11:12 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2013-05-01 13:09:56 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2013-05-01 13:09:46 156672 ----a-w- c:\windows\system32\ncsi.dll
2013-05-01 13:09:45 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2013-05-01 13:09:45 175104 ----a-w- c:\windows\system32\netcorehc.dll
2013-05-01 13:09:44 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-05-01 13:09:44 242176 ----a-w- c:\windows\system32\nlasvc.dll
2013-05-01 13:09:43 52224 ----a-w- c:\windows\system32\nlaapi.dll
2013-05-01 13:09:43 18944 ----a-w- c:\windows\system32\netevent.dll
2013-05-01 13:08:58 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-05-01 13:08:54 193536 ----a-w- c:\windows\system32\dhcpcore6.dll
2013-05-01 13:08:53 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-05-01 01:02:57 -------- d-----w- c:\windows\system32\SPReview
2013-05-01 01:02:06 -------- d-----w- c:\windows\system32\EventProviders
2013-04-30 14:11:59 585728 ----a-w- c:\windows\system32\qmgr.dll
2013-04-30 14:10:59 907776 ----a-w- c:\windows\system32\sdengin2.dll
2013-04-30 14:09:59 84480 ----a-w- c:\windows\system32\mciavi32.dll
2013-04-30 14:08:39 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2013-04-30 14:08:39 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2013-04-30 14:08:39 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2013-04-30 14:08:39 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2013-04-30 14:08:39 189952 ----a-w- c:\program files\windows portable devices\sqmapi.dll
2013-04-30 14:08:23 697344 ----a-w- c:\windows\system32\SmiEngine.dll
2013-04-30 14:08:23 189952 ----a-w- c:\windows\system32\sqmapi.dll
2013-04-30 14:08:17 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2013-04-30 14:08:17 189952 ----a-w- c:\windows\system32\wdscore.dll
2013-04-30 14:07:35 323072 ----a-w- c:\windows\system32\drvstore.dll
2013-04-30 14:07:35 257024 ----a-w- c:\windows\system32\dpx.dll
2013-04-24 12:55:04 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-15 13:32:30 6128760 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2013-04-15 13:32:30 6128760 ----a-w- c:\program files\mozilla firefox\browser\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
.
==================== Find3M ====================
.
2013-05-13 19:46:23 866720 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-05-13 19:46:23 788896 ----a-w- c:\windows\system32\deployJava1.dll
2013-05-13 18:50:10 44432 ----a-w- c:\windows\system32\drivers\kltdi.sys
2013-05-13 18:50:10 145040 ----a-w- c:\windows\system32\drivers\kneps.sys
2013-05-07 01:03:38 906240 ----a-w- c:\windows\system32\FntCache.dll
2013-05-02 00:06:08 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-05-01 01:09:36 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-03-19 05:04:13 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-19 05:04:10 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 04:48:45 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 02:49:16 69632 ----a-w- c:\windows\system32\smss.exe
2013-03-06 11:24:14 58712 ----a-w- c:\windows\system32\klfphc.dll
2013-03-06 11:24:14 25944 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2013-03-06 11:24:14 25944 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2013-03-01 03:09:59 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-02-15 04:37:10 3217408 ----a-w- c:\windows\system32\mstscax.dll
2013-02-15 04:34:10 131584 ----a-w- c:\windows\system32\aaclient.dll
2013-02-15 03:25:51 36864 ----a-w- c:\windows\system32\tsgqec.dll
.
============= FINISH: 17:36:53,93 ===============


mycity.rs/must-login.png

Dopuna: 14 Maj 2013 17:44

zaboravih da dodam da je pre nekih 10 dana počelo sve to da se pojavljuje

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15874
  • Gde živiš: Beograd

Korak 1.

Preuzmi "Xplode"-ov AdwCleaner i sacuvaj ga na Desktop
Pokreni ga, a zatim klikni na dugme [Delete] i pricekaj da program zavrsi.
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok

Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S1].txt




Korak 2.


Preuzmi program GMER sa donjeg linka na Desktop:


GMER download
Klikni dati link;
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.



Dvoklikom pokrenite GMER.
Sačekaj da se završi uvodno skeniranje - ukoliko se pojavi bilo kakav upit, klikni No;

klikni Scan i sačekaj da skeniranje bude završeno;

klikni Save ... - izveštaj sačuvaj na Desktop (pod nazivom Gmer1);

klikni desnim tasterom u prozor programa Gmer i odaberi Options > 3rd party - klikni Scan;

po završetku skeniranja klikni Save ... - izveštaj sačuvaj na Desktop (pod nazivom Gmer2);

klikni taster >>> i odaberi Autostart karticu;

po završetku kratkotrajnog skeniranja, klikni Copy;

otvori Notepad i u njega postavi kopirani tekst - izveštaj sačuvaj na Desktop (pod nazivom Gmer3);


Slikoviti prikaz postupka

Priloži sva tri izveštaja uz poruku korišćenjem opcije Prikači fajl.

Ko je trenutno na forumu
 

Ukupno su 754 korisnika na forumu :: 38 registrovanih, 4 sakrivenih i 712 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 1798 - dana 19 Sep 2019 18:42

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., antosky, Atomski čoban, Boris90, caesar, Crki, Djokkinen, Dok, Dusko Nikolin, Ehinacea, Georgius2, GreenMan, helen1, ibssa, Ivan Gajic2, Kubovac, mali41, marija_ned, MarKhan, Maschinekalibar, MB120mm, Mercury, Mikulino, nemkea71, nesic1, rovac, SAA fan, sale755, sergio88nis, shsoft02, Snorks, srecko81, tanakadzo, Trpe Grozni, vasa.93, voja64, wolf431, zoidbergs