anti malware software

anti malware software

offline
  • Pridružio: 14 Maj 2013
  • Poruke: 3

može li neko da mi preporuči efikasan anti malware softver?
koristim windows 7

non stop mi se pojavljuju reklame po stranicama u svim browserima sem u operi. tipa







probala sam malwarebytes, rootkit, hitmanpro, spybot, adwcleaner - nisu ništa pronašli
skenirala sistem kasperskim - opet ništa

hvala unapred na odgovoru

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Pozdrav,

Isprati uputstvo i dostavi izvestaje

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 14 Maj 2013
  • Poruke: 3

ne radi link za download dds-a

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Preuzmi ga sa ovog linka

https://www.mycity.rs/must-login.png

offline
  • Pridružio: 14 Maj 2013
  • Poruke: 3

Napisano: 14 Maj 2013 17:42

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.21.2
Run by natasa at 17:30:19 on 2013-05-14
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3327.294 [GMT 2:00]
.
AV: Kaspersky Internet Security *Enabled/Updated* {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
SP: Kaspersky Internet Security *Enabled/Updated* {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Kaspersky Internet Security *Enabled* {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe
C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
C:\Program Files\HTC\HTC Sync Manager\HSMServiceEntry.exe
C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\Program Files\Online Games Manager\ogmservice.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Program Files\PC Auto Shutdown\ShutdownService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Windows\System32\PAStiSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\Last.fm\Last.fm Scrobbler.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Last.fm\iPodScrobbler.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
uProxyOverride = <local>;*.local
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
uURLSearchHooks: GagetBox: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} -
uURLSearchHooks: SHOUTcast Toolbar Search Class: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
mURLSearchHooks: SHOUTcast Toolbar Search Class: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
mURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mURLSearchHooks: GagetBox: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} -
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Content Blocker Plugin: {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\contentblocker\ie_content_blocker_plugin.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: Virtual Keyboard Plugin: {73455575-E40C-433C-9784-C78DC7761455} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: SelectionLinks: {7825CFB6-490A-436B-9F26-4A7B5CFC01A9} -
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Safe Money Plugin: {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\onlinebanking\online_banking_bho.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: SHOUTcast Loader: {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: URL Advisor Plugin: {E33CF602-D945-461A-83F0-819F76A199F8} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
BHO: DVDVideoSoft WebPageAdjuster Class: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
TB: SHOUTcast Radio Toolbar: {0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
TB: SHOUTcast Radio Toolbar: {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
TB: GagetBox: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} -
EB: GagetBox: {3B81079D-2AC9-425f-A494-A1C7D93AFA3C} -
uRun: [AdobeBridge] <no file>
uRunOnce: [SpybotDeletingF2165] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\application updater\ApplicationUpdater.exe"
uRunOnce: [SpybotDeletingF4614] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\SearchSettings.exe"
uRunOnce: [SpybotDeletingF8881] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\application updater\config.ini"
uRunOnce: [SpybotDeletingF243] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\baidu_ff.xml"
uRunOnce: [SpybotDeletingF4595] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\baidu_ie.xml"
uRunOnce: [SpybotDeletingF8855] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\config.ini"
uRunOnce: [SpybotDeletingF8356] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\yandex_ff.xml"
uRunOnce: [SpybotDeletingF5794] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1031.ini"
uRunOnce: [SpybotDeletingF2729] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1033.ini"
uRunOnce: [SpybotDeletingF6467] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1034.ini"
uRunOnce: [SpybotDeletingF6914] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1036.ini"
uRunOnce: [SpybotDeletingF9625] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1040.ini"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NBAgent] "c:\program files\nero\nero 10\nero backitup\NBAgent.exe" /WinStart
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [XeroxEndeavorBackgroundTask] rundll32.exe xrWCbgnd.dll,LaunchBgTask 1
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [CloneCDTray] "c:\program files\slysoft\clonecd\CloneCDTray.exe" /s
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [PC Auto Shutdown] "c:\program files\pc auto shutdown\AutoShutdown.exe"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2013\avp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
mRunOnce: [SpybotDeletingE7657] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\application updater\ApplicationUpdater.exe"
mRunOnce: [SpybotDeletingE4410] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\SearchSettings.exe"
mRunOnce: [SpybotDeletingE8094] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\application updater\config.ini"
mRunOnce: [SpybotDeletingE3522] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\baidu_ff.xml"
mRunOnce: [SpybotDeletingE2308] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\baidu_ie.xml"
mRunOnce: [SpybotDeletingE7921] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\config.ini"
mRunOnce: [SpybotDeletingE6574] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\yandex_ff.xml"
mRunOnce: [SpybotDeletingE4777] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1031.ini"
mRunOnce: [SpybotDeletingE1865] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1033.ini"
mRunOnce: [SpybotDeletingE2884] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1034.ini"
mRunOnce: [SpybotDeletingE7923] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1036.ini"
mRunOnce: [SpybotDeletingE8051] "c:\program files\spybot - search & destroy 2\sddelfile.exe" "c:\program files\common files\spigot\search settings\lang\res1040.ini"
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: &SHOUTcast Search - c:\programdata\shoutcast radio toolbar\ietoolbar\resources\en-us\local\search.html
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2013\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\program files\common files\dvdvideosoft\plugins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files\common files\dvdvideosoft\plugins\freeytmp3downloader.htm
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {0C4CC089-D306-440D-9772-464E226F6539} - {0BA14598-4178-4CE5-B1F1-B5C6408A3F2E} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\virtualkeyboard\ie_virtual_keyboard_plugin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2013\ieext\urladvisor\klwtbbho.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
IE: {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{2CB6F41B-FE32-4096-BD06-962216A6F48D} : DHCPNameServer = 192.168.55.1 89.216.1.40 89.216.1.50
TCP: Interfaces\{3E169190-C5B0-43F9-BAA5-B072BFEE86D2} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{4EE31D81-CAD7-493A-81A7-5AC370F44C3B} : DHCPNameServer = 192.168.55.1 89.216.1.40 89.216.1.50
TCP: Interfaces\{A0805690-122D-44C8-800F-3958E5D330DA} : NameServer = 192.168.1.1
TCP: Interfaces\{FB15C35E-4D57-4305-84B5-989F66F42AE3} : DHCPNameServer = 192.168.55.1 89.216.1.40 89.216.1.50
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20125.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\nokia\nokia suite\npNokiaSuiteEnabler.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\natasa\appdata\local\facebook\messenger\2.1.4814.0\npFbDesktopPlugin.dll
FF - plugin: c:\users\natasa\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\users\natasa\appdata\local\google\update\1.3.21.145\npGoogleUpdate3.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\plugins\np-mswmp.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\plugins\np-mswmp.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\users\natasa\appdata\roaming\mozilla\plugins\npo1d.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - ExtSQL: 2013-05-09 02:53; {DF53B24E-E1CD-428F-8B13-57E04022F1AF}; c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\extensions\{DF53B24E-E1CD-428F-8B13-57E04022F1AF}
FF - ExtSQL: 2013-05-09 20:07; addon@defaulttab.com; c:\users\natasa\appdata\roaming\mozilla\firefox\profiles\w2cody4r.default\extensions\addon@defaulttab.com.xpi
.
============= SERVICES / DRIVERS ===============
.
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-4-14 45736]
.
=============== Created Last 30 ================
.
2013-05-14 11:48:28 6906960 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{f1d26336-996b-44b4-9002-877077a901ea}\mpengine.dll
2013-05-14 11:47:56 -------- d-----w- C:\cf00bb78987c96ca2bfca3cf3102270f
2013-05-13 20:13:59 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2013-05-13 20:13:20 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-05-13 20:13:05 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-05-13 19:46:43 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-05-13 19:38:54 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-13 19:38:54 691592 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-13 17:54:58 -------- d-----w- c:\windows\ELAMBKUP
2013-05-13 17:54:44 -------- d-----w- c:\programdata\Kaspersky Lab
2013-05-13 17:54:44 -------- d-----w- c:\program files\Kaspersky Lab
2013-05-13 17:54:18 74848 ----a-w- c:\windows\system32\drivers\klflt.sys
2013-05-10 18:01:53 30464 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys
2013-05-10 17:49:20 -------- d-----w- c:\program files\HitmanPro
2013-05-10 17:48:51 -------- d-----w- c:\programdata\HitmanPro
2013-05-09 18:40:46 -------- d-----w- c:\users\natasa\appdata\roaming\Malwarebytes
2013-05-09 18:40:25 -------- d-----w- c:\programdata\Malwarebytes
2013-05-09 18:40:19 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-05-09 18:40:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-05-09 00:54:53 -------- d-----w- c:\programdata\PC Auto Shutdown
2013-05-09 00:54:53 -------- d-----w- c:\program files\PC Auto Shutdown
2013-05-07 01:03:38 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-01 13:11:12 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-05-01 13:11:12 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2013-05-01 13:09:56 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2013-05-01 13:09:46 156672 ----a-w- c:\windows\system32\ncsi.dll
2013-05-01 13:09:45 499712 ----a-w- c:\windows\system32\iphlpsvc.dll
2013-05-01 13:09:45 175104 ----a-w- c:\windows\system32\netcorehc.dll
2013-05-01 13:09:44 35328 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2013-05-01 13:09:44 242176 ----a-w- c:\windows\system32\nlasvc.dll
2013-05-01 13:09:43 52224 ----a-w- c:\windows\system32\nlaapi.dll
2013-05-01 13:09:43 18944 ----a-w- c:\windows\system32\netevent.dll
2013-05-01 13:08:58 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-05-01 13:08:54 193536 ----a-w- c:\windows\system32\dhcpcore6.dll
2013-05-01 13:08:53 44032 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2013-05-01 01:02:57 -------- d-----w- c:\windows\system32\SPReview
2013-05-01 01:02:06 -------- d-----w- c:\windows\system32\EventProviders
2013-04-30 14:11:59 585728 ----a-w- c:\windows\system32\qmgr.dll
2013-04-30 14:10:59 907776 ----a-w- c:\windows\system32\sdengin2.dll
2013-04-30 14:09:59 84480 ----a-w- c:\windows\system32\mciavi32.dll
2013-04-30 14:08:39 780288 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2013-04-30 14:08:39 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2013-04-30 14:08:39 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2013-04-30 14:08:39 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2013-04-30 14:08:39 189952 ----a-w- c:\program files\windows portable devices\sqmapi.dll
2013-04-30 14:08:23 697344 ----a-w- c:\windows\system32\SmiEngine.dll
2013-04-30 14:08:23 189952 ----a-w- c:\windows\system32\sqmapi.dll
2013-04-30 14:08:17 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2013-04-30 14:08:17 189952 ----a-w- c:\windows\system32\wdscore.dll
2013-04-30 14:07:35 323072 ----a-w- c:\windows\system32\drvstore.dll
2013-04-30 14:07:35 257024 ----a-w- c:\windows\system32\dpx.dll
2013-04-24 12:55:04 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-15 13:32:30 6128760 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
2013-04-15 13:32:30 6128760 ----a-w- c:\program files\mozilla firefox\browser\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
.
==================== Find3M ====================
.
2013-05-13 19:46:23 866720 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-05-13 19:46:23 788896 ----a-w- c:\windows\system32\deployJava1.dll
2013-05-13 18:50:10 44432 ----a-w- c:\windows\system32\drivers\kltdi.sys
2013-05-13 18:50:10 145040 ----a-w- c:\windows\system32\drivers\kneps.sys
2013-05-07 01:03:38 906240 ----a-w- c:\windows\system32\FntCache.dll
2013-05-02 00:06:08 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-05-01 01:09:36 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-03-19 05:04:13 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-19 05:04:10 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 04:48:45 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 02:49:16 69632 ----a-w- c:\windows\system32\smss.exe
2013-03-06 11:24:14 58712 ----a-w- c:\windows\system32\klfphc.dll
2013-03-06 11:24:14 25944 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2013-03-06 11:24:14 25944 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2013-03-01 03:09:59 2347008 ----a-w- c:\windows\system32\win32k.sys
2013-02-15 04:37:10 3217408 ----a-w- c:\windows\system32\mstscax.dll
2013-02-15 04:34:10 131584 ----a-w- c:\windows\system32\aaclient.dll
2013-02-15 03:25:51 36864 ----a-w- c:\windows\system32\tsgqec.dll
.
============= FINISH: 17:36:53,93 ===============


mycity.rs/must-login.png

Dopuna: 14 Maj 2013 17:44

zaboravih da dodam da je pre nekih 10 dana počelo sve to da se pojavljuje

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15877
  • Gde živiš: Beograd

Korak 1.

Preuzmi "Xplode"-ov AdwCleaner i sacuvaj ga na Desktop
Pokreni ga, a zatim klikni na dugme [Delete] i pricekaj da program zavrsi.
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok

Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S1].txt




Korak 2.


Preuzmi program GMER sa donjeg linka na Desktop:


GMER download
Klikni dati link;
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.



Dvoklikom pokrenite GMER.
Sačekaj da se završi uvodno skeniranje - ukoliko se pojavi bilo kakav upit, klikni No;

klikni Scan i sačekaj da skeniranje bude završeno;

klikni Save ... - izveštaj sačuvaj na Desktop (pod nazivom Gmer1);

klikni desnim tasterom u prozor programa Gmer i odaberi Options > 3rd party - klikni Scan;

po završetku skeniranja klikni Save ... - izveštaj sačuvaj na Desktop (pod nazivom Gmer2);

klikni taster >>> i odaberi Autostart karticu;

po završetku kratkotrajnog skeniranja, klikni Copy;

otvori Notepad i u njega postavi kopirani tekst - izveštaj sačuvaj na Desktop (pod nazivom Gmer3);


Slikoviti prikaz postupka

Priloži sva tri izveštaja uz poruku korišćenjem opcije Prikači fajl.

Ko je trenutno na forumu
 

Ukupno su 1217 korisnika na forumu :: 69 registrovanih, 16 sakrivenih i 1132 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 39mm, _Rade, aboris, amaterSRB, amstel, bankulen, Bobrock1, Bojan85, bojank, Bubili, Bubimir, bufanje, chichabg, CrazyDiablo, ddjxxi, dekan.m, Denaya, Doca, doklevise, Dorcolac, draganl, dragoljub11987, dragon986, Duh sa sekirom, dule10savic, FileFinder, Georgius, HogarStrashni, ikan, Insan, Istman, kobaja77, krkalon, kuntalo, mackenzie, Marko Marković, Metanoja, Mi lao shu, Milan A. Nikolic, milenko crazy north, milimoj, MiroslavD, mkukoleca, naki011, nenooo, niksa517, oldtimer, Paško, Perkele, raketaš, rikirubio, savuni, Skakac7, Srle993, suton, t84dar, theNedjeljko, tmanda323, Toni, VJ, Vojvoda86, Wisdomseeker, wizzardone, wulfy, zorzpapadubi, Zvrk, |_MeD_|, Žrnov, 125