Problem sa IE


Problem sa IE

  • Pridružio: 01 Okt 2008
  • Poruke: 66

Problem je u tome sto non-stop (dok sam u IE) otvara neke sajtove (vecinom kineske i erotske). To je pocelo da se desava kada sam skidao neki screenserver. Virus nisam nasao, precesljao sam ceo komp sa nodom. Skinuo sam programe Spybot Search & Destroy i SuperAntiSpyware , i sve precesljao sa njima, nasao je gomilu nekakvih pretnji i obrisao. Ali opet se pojavljuje isti problem.

  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

  • Pridružio: 01 Okt 2008
  • Poruke: 66

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:17:50, on 20.1.2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16764)
Boot mode: Normal

Running processes:
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Korisnik\Desktop\New Folder\TR3.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: CashBackAssistant - {00F5B5BA-E3C2-4b70-BF51-42A557914FAD} - C:\Program Files\Nice Prosper\CashBackAssistant\CashBackAssistantIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: NP Helper Class - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Internet Saving Optimizer\\NPIEAddOn.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live pomagac za prijavljivanje - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: System Search Dispatcher - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - C:\PROGRAM FILES\SYSTEM SEARCH DISPATCHER\\SSD.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Myweather] "D:\Programi\WEATHER\MyWeather.exe" /autorun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Korisnik\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

End of file - 6898 bytes

  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Privremeno iskljuci sav zastitni softver i uradi sledece :

Skini ComboFix sa jedne od sledecih adresa na Desktop:

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

  • Pridružio: 01 Okt 2008
  • Poruke: 66

ComboFix 09-01-19.03 - Korisnik 2009-01-20 1:33:55.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2046.1100 [GMT 1:00]
Running from: c:\users\Korisnik\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated)
* Created a new restore point
* Resident AV is active


((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))

2009-01-19 22:59 . 2009-01-19 22:59 <DIR> d-------- c:\users\Korisnik\AppData\Roaming\
2009-01-19 22:59 . 2009-01-19 22:59 <DIR> d-------- c:\users\All Users\
2009-01-19 22:59 . 2009-01-19 22:59 <DIR> d-------- c:\programdata\
2009-01-19 22:59 . 2009-01-19 23:44 <DIR> d-------- c:\program files\SUPERAntiSpyware
2009-01-19 22:58 . 2009-01-19 22:58 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-01-19 19:22 . 2009-01-19 22:01 <DIR> d-------- c:\users\All Users\Spybot - Search & Destroy
2009-01-19 19:22 . 2009-01-19 22:01 <DIR> d-------- c:\programdata\Spybot - Search & Destroy
2009-01-19 19:22 . 2009-01-19 22:00 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-01-19 17:16 . 2009-01-19 17:16 268,800 --a------ c:\windows\System32\es.dll
2009-01-19 17:13 . 2009-01-19 17:13 290,304 --a------ c:\windows\System32\drivers\srv.sys
2009-01-19 16:52 . 2009-01-19 16:52 <DIR> d-------- c:\program files\System Search Dispatcher
2009-01-19 16:52 . 2009-01-19 16:52 <DIR> d-------- c:\program files\Nice Prosper
2009-01-19 16:52 . 2009-01-19 16:52 <DIR> d-------- c:\program files\Internet Saving Optimizer
2009-01-19 16:51 . 2009-01-19 16:51 <DIR> d-------- c:\program files\DoubleD
2009-01-14 01:57 . 2009-01-14 01:57 <DIR> d-------- c:\program files\Java
2009-01-14 01:57 . 2009-01-14 01:57 410,984 --a------ c:\windows\System32\deploytk.dll
2009-01-10 23:17 . 2009-01-10 23:17 361,984 --a------ c:\windows\System32\IPSECSVC.DLL
2009-01-10 23:17 . 2009-01-10 23:17 272,896 --a------ c:\windows\System32\polstore.dll
2009-01-10 23:17 . 2009-01-10 23:17 61,440 --a------ c:\windows\System32\winipsec.dll
2009-01-10 23:17 . 2009-01-10 23:17 28,672 --a------ c:\windows\System32\FwRemoteSvr.dll
2009-01-10 23:15 . 2009-01-10 23:15 205,824 --a------ c:\windows\System32\msoeacct.dll
2009-01-10 23:15 . 2009-01-10 23:15 87,040 --a------ c:\windows\System32\msoert2.dll
2009-01-10 23:15 . 2009-01-10 23:15 39,424 --a------ c:\windows\System32\ACCTRES.dll
2009-01-10 23:14 . 2009-01-10 23:14 1,655,289 --a------ c:\windows\System32\wlan.tmf
2009-01-10 23:14 . 2009-01-10 23:14 714,240 --a------ c:\windows\System32\timedate.cpl
2009-01-10 23:14 . 2009-01-10 23:14 704,000 --a------ c:\windows\System32\PhotoScreensaver.scr
2009-01-10 23:14 . 2009-01-10 23:14 542,720 --a------ c:\windows\System32\sysmain.dll
2009-01-10 23:14 . 2009-01-10 23:14 502,784 --a------ c:\windows\System32\wlansvc.dll
2009-01-10 23:14 . 2009-01-10 23:14 297,984 --a------ c:\windows\System32\wlansec.dll
2009-01-10 23:14 . 2009-01-10 23:14 290,816 --a------ c:\windows\System32\wlanmsm.dll
2009-01-10 23:14 . 2009-01-10 23:14 258,232 --a------ c:\windows\System32\drivers\acpi.sys
2009-01-10 23:14 . 2009-01-10 23:14 67,584 --a------ c:\windows\System32\wlanhlp.dll
2009-01-10 23:14 . 2009-01-10 23:14 47,104 --a------ c:\windows\System32\wlanapi.dll
2009-01-10 23:14 . 2009-01-10 23:14 24,064 --a------ c:\windows\System32\wtsapi32.dll
2009-01-10 23:12 . 2009-01-10 23:12 194,560 --a------ c:\windows\System32\WebClnt.dll
2009-01-10 23:12 . 2009-01-10 23:12 110,080 --a------ c:\windows\System32\drivers\mrxdav.sys
2009-01-10 23:10 . 2009-01-10 23:10 1,244,672 --a------ c:\windows\System32\mcmde.dll
2009-01-10 23:10 . 2009-01-10 23:10 428,032 --a------ c:\windows\System32\EncDec.dll
2009-01-10 23:10 . 2009-01-10 23:10 376,320 --a------ c:\windows\System32\winsrv.dll
2009-01-10 23:10 . 2009-01-10 23:10 292,352 --a------ c:\windows\System32\psisdecd.dll
2009-01-10 23:10 . 2009-01-10 23:10 217,088 --a------ c:\windows\System32\
2009-01-10 23:10 . 2009-01-10 23:10 177,152 --a------ c:\windows\System32\
2009-01-10 23:10 . 2009-01-10 23:10 80,896 --a------ c:\windows\System32\
2009-01-10 23:10 . 2009-01-10 23:10 68,608 --a------ c:\windows\System32\
2009-01-10 23:10 . 2009-01-10 23:10 57,856 --a------ c:\windows\System32\
2009-01-10 23:10 . 2009-01-10 23:10 49,664 --a------ c:\windows\System32\csrsrv.dll
2009-01-10 23:07 . 2009-01-10 23:07 1,060,920 --a------ c:\windows\System32\drivers\ntfs.sys
2009-01-10 23:07 . 2009-01-10 23:07 297,472 --a------ c:\windows\System32\gdi32.dll
2009-01-10 23:07 . 2009-01-10 23:07 41,984 --a------ c:\windows\System32\drivers\monitor.sys
2009-01-10 23:05 . 2009-01-10 23:05 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-01-10 23:04 . 2009-01-10 23:04 211,456 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2009-01-10 23:03 . 2009-01-10 23:03 374,456 --a------ c:\windows\System32\mcupdate_GenuineIntel.dll
2009-01-10 23:03 . 2009-01-10 23:03 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2009-01-10 23:02 . 2009-01-10 23:02 4,247,552 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2009-01-10 23:02 . 2009-01-10 23:02 1,687,040 --a------ c:\windows\System32\gameux.dll
2009-01-10 23:02 . 2009-01-10 23:02 303,616 --a------ c:\windows\System32\wmpeffects.dll
2009-01-10 23:01 . 2009-01-10 23:01 2,027,520 --a------ c:\windows\System32\win32k.sys
2009-01-10 23:00 . 2009-01-10 23:00 1,194,496 --a------ c:\windows\System32\msxml3.dll
2009-01-10 23:00 . 2009-01-10 23:00 414,208 --a------ c:\windows\System32\msscp.dll
2009-01-10 23:00 . 2009-01-10 23:00 2,048 --a------ c:\windows\System32\msxml3r.dll
2009-01-10 22:59 . 2009-01-10 22:59 8,147,968 --a------ c:\windows\System32\wmploc.DLL
2009-01-10 22:59 . 2009-01-10 22:59 356,864 --a------ c:\windows\System32\MediaMetadataHandler.dll
2009-01-10 22:59 . 2009-01-10 22:59 7,680 --a------ c:\windows\System32\spwmp.dll
2009-01-10 22:59 . 2009-01-10 22:59 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-01-10 22:59 . 2009-01-10 22:59 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-01-10 22:58 . 2009-01-10 22:58 396,800 --a------ c:\windows\System32\MPSSVC.dll
2009-01-10 22:58 . 2009-01-10 22:58 392,192 --a------ c:\windows\System32\FirewallAPI.dll
2009-01-10 22:58 . 2009-01-10 22:58 178,688 --a------ c:\windows\System32\iphlpsvc.dll
2009-01-10 22:58 . 2009-01-10 22:58 86,016 --a------ c:\windows\System32\icfupgd.dll
2009-01-10 22:58 . 2009-01-10 22:58 63,488 --a------ c:\windows\System32\drivers\mpsdrv.sys
2009-01-10 22:58 . 2009-01-10 22:58 61,952 --a------ c:\windows\System32\cmifw.dll
2009-01-10 22:58 . 2009-01-10 22:58 23,040 --a------ c:\windows\System32\drivers\tunnel.sys
2009-01-10 22:58 . 2009-01-10 22:58 16,896 --a------ c:\windows\System32\wfapigp.dll
2009-01-10 22:58 . 2009-01-10 22:58 15,360 --a------ c:\windows\System32\drivers\TUNMP.SYS
2009-01-10 22:57 . 2009-01-10 22:57 2,048 --a------ c:\windows\System32\tzres.dll
2009-01-10 22:53 . 2009-01-10 22:53 211,000 --a------ c:\windows\System32\drivers\volsnap.sys
2009-01-10 22:53 . 2009-01-10 22:53 154,624 --a------ c:\windows\System32\drivers\nwifi.sys
2009-01-10 22:53 . 2009-01-10 22:53 109,624 --a------ c:\windows\System32\drivers\ataport.sys
2009-01-10 22:53 . 2009-01-10 22:53 104,448 --a------ c:\windows\System32\DWWIN.EXE
2009-01-10 22:53 . 2009-01-10 22:53 45,112 --a------ c:\windows\System32\drivers\pciidex.sys
2009-01-10 22:53 . 2009-01-10 22:53 21,560 --a------ c:\windows\System32\drivers\atapi.sys
2009-01-10 22:53 . 2009-01-10 22:53 15,928 --a------ c:\windows\System32\drivers\pciide.sys
2009-01-10 22:52 . 2009-01-10 22:52 2,923,520 --a------ c:\windows\explorer.exe
2009-01-10 22:49 . 2009-01-10 22:49 7,964,672 --a------ c:\windows\System32\NlsLexicons0024.dll
2009-01-10 22:48 . 2009-01-10 22:48 12,240,896 --a------ c:\windows\System32\NlsLexicons0007.dll
2009-01-10 22:46 . 2009-01-10 22:46 1,585,664 --a------ c:\windows\System32\setupapi.dll
2009-01-10 22:44 . 2009-01-10 22:44 223,232 --a------ c:\windows\System32\WMASF.DLL
2009-01-10 22:44 . 2009-01-10 22:44 9,728 --a------ c:\windows\System32\LAPRXY.DLL
2009-01-10 22:44 . 2009-01-10 22:44 2,048 --a------ c:\windows\System32\asferror.dll
2009-01-10 22:43 . 2009-01-10 22:43 2,605,568 --a------ c:\windows\System32\SLsvc.exe
2009-01-10 22:43 . 2009-01-10 22:43 566,784 --a------ c:\windows\System32\SLCommDlg.dll
2009-01-10 22:43 . 2009-01-10 22:43 351,232 --a------ c:\windows\System32\SLUI.exe
2009-01-10 22:43 . 2009-01-10 22:43 268,288 --a------ c:\windows\System32\mcbuilder.exe
2009-01-10 22:43 . 2009-01-10 22:43 223,232 --a------ c:\windows\System32\SLC.dll
2009-01-10 22:43 . 2009-01-10 22:43 186,368 --a------ c:\windows\System32\SLLUA.exe
2009-01-10 22:43 . 2009-01-10 22:43 57,856 --a------ c:\windows\System32\SLUINotify.dll
2009-01-10 22:43 . 2009-01-10 22:43 39,936 --a------ c:\windows\System32\slcinst.dll
2009-01-10 22:43 . 2009-01-10 22:43 33,280 --a------ c:\windows\System32\slwmi.dll
2009-01-10 22:42 . 2009-01-10 22:42 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2009-01-10 22:42 . 2009-01-10 22:42 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2009-01-10 22:42 . 2009-01-10 22:42 347,648 --a------ c:\windows\System32\WindowsCodecsExt.dll
2009-01-10 22:40 . 2009-01-10 22:40 11,776 --a------ c:\windows\System32\sbunattend.exe
2009-01-10 22:36 . 2009-01-10 22:36 1,645,568 --a------ c:\windows\System32\connect.dll
2009-01-10 22:36 . 2009-01-10 22:36 1,327,104 --a------ c:\windows\System32\quartz.dll
2009-01-10 22:36 . 2009-01-10 22:36 788,992 --a------ c:\windows\System32\rpcrt4.dll
2009-01-10 22:36 . 2009-01-10 22:36 737,792 --a------ c:\windows\System32\inetcomm.dll
2009-01-10 22:36 . 2009-01-10 22:36 152,576 --a------ c:\windows\System32\imagehlp.dll
2009-01-10 22:36 . 2009-01-10 22:36 84,480 --a------ c:\windows\System32\INETRES.dll
2009-01-10 22:36 . 2009-01-10 22:36 12,800 --a------ c:\windows\System32\drivers\fs_rec.sys
2009-01-10 22:36 . 2009-01-10 22:36 5,120 --a------ c:\windows\System32\wmi.dll
2009-01-10 22:35 . 2009-01-10 22:35 3,505,208 --a------ c:\windows\System32\ntkrnlpa.exe
2009-01-10 22:35 . 2009-01-10 22:35 3,470,904 --a------ c:\windows\System32\ntoskrnl.exe
2009-01-10 22:35 . 2009-01-10 22:35 1,341,440 --a------ c:\windows\System32\msxml6.dll
2009-01-10 22:35 . 2009-01-10 22:35 974,336 --a------ c:\windows\System32\crypt32.dll
2009-01-10 22:35 . 2009-01-10 22:35 633,856 --a------ c:\windows\System32\user32.dll
2009-01-10 22:35 . 2009-01-10 22:35 2,048 --a------ c:\windows\System32\msxml6r.dll
2009-01-10 22:34 . 2009-01-10 22:34 750,080 --a------ c:\windows\System32\qmgr.dll
2009-01-10 17:44 . 2009-01-10 17:44 249,856 --------- c:\windows\Setup1.exe
2009-01-10 17:44 . 2009-01-10 17:44 73,216 --a------ c:\windows\ST6UNST.EXE
2009-01-09 22:56 . 2009-01-10 23:05 <DIR> d-------- c:\windows\Debug
2009-01-09 22:54 . 2009-01-09 23:00 <DIR> d-------- c:\windows\Panther
2009-01-09 22:54 . 2009-01-09 22:54 <DIR> d--hs---- C:\Boot
2009-01-09 22:54 . 2006-11-02 10:53 438,840 -rahs---- C:\bootmgr
2009-01-09 22:54 . 2009-01-09 22:54 8,192 -ra-s---- C:\BOOTSECT.BAK
2009-01-09 21:29 . 2009-01-09 21:29 1,809,944 --a------ c:\windows\System32\wuaueng.dll

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2009-01-19 16:19 --------- d-----w c:\program files\Windows Mail
2009-01-10 22:23 174 --sha-w c:\program files\desktop.ini
2009-01-10 22:19 --------- d-----w c:\program files\Windows Sidebar
2009-01-10 22:19 --------- d-----w c:\program files\Windows Defender
2009-01-10 22:19 --------- d-----w c:\program files\Windows Calendar
2009-01-10 22:03 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2009-01-10 22:02 537,600 ----a-w c:\windows\AppPatch\AcLayers.dll
2009-01-10 22:02 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-10 22:02 449,536 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2009-01-10 22:02 2,144,256 ----a-w c:\windows\AppPatch\AcGenral.dll
2009-01-10 22:02 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2009-01-10 21:50 826,368 ----a-w c:\windows\System32\wininet.dll
2009-01-10 21:50 56,320 ----a-w c:\windows\System32\iesetup.dll
2009-01-10 21:50 26,624 ----a-w c:\windows\System32\ieUnatt.exe
2009-01-10 21:48 9,892,864 ----a-w c:\windows\System32\NlsLexicons000a.dll
2009-01-10 21:45 944,184 ----a-w c:\windows\System32\winload.exe
2009-01-10 21:41 88,576 ----a-w c:\windows\System32\avifil32.dll
2009-01-10 21:37 996,352 ----a-w c:\windows\System32\WMNetMgr.dll
2008-12-08 11:53 57,344 ----a-w c:\windows\System32\ff_vfw.dll
2008-12-07 12:08 795,648 ----a-w c:\windows\System32\xvidcore.dll
2008-12-07 12:08 130,048 ----a-w c:\windows\System32\xvidvfw.dll
2008-12-04 22:27 308,072 ----a-w c:\windows\WLXPGSS.SCR
2008-12-02 21:37 49,480 ----a-w c:\windows\System32\sirenacm.dll

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00F5B5BA-E3C2-4b70-BF51-42A557914FAD}]
2008-12-22 12:12 835584 --a------ c:\program files\Nice Prosper\CashBackAssistant\CashBackAssistantIE.dll

"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-01-10 1232896]
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 507904]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2009-01-09 171448]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
"Myweather"="d:\programi\WEATHER\MyWeather.exe" [2008-09-25 1576448]
"Google Update"="c:\users\Korisnik\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-01-15 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]

"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-04-12 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-12 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-12 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-14 136600]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1598111960-1725439960-2952766009-1000]

"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

"{78DDC511-A884-4696-B652-04E34D64D1AD}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{0CE6D9FF-49FB-48AF-8BA1-F095009EFDE6}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{F59BEAE7-C8D7-4978-A0AD-CAB580E89EC3}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{8D20CA10-770C-431A-8823-2B07CA2FC9F9}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{2A0267BF-B351-4C8A-9E9D-7C9DBC2B6C81}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{DEDA94CA-DE05-43C0-9F60-5A7BB4A669C1}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{707D5068-D447-4FA7-A3F3-BD363FD45C76}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{F72210EA-0DCF-49D2-9B2E-987304886A5C}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{89B13FF9-42C2-47AE-8EFE-19B8DEAE136A}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{41DB5D31-D29E-4CB8-BDD8-40F6CD027C1C}d:\\igre\\cs1.6\\hl.exe"= UDP:d:\igre\cs1.6\hl.exe:Half-Life Launcher
"UDP Query User{EA49D6E9-F923-4098-A040-CBC7343C099E}d:\\igre\\cs1.6\\hl.exe"= TCP:d:\igre\cs1.6\hl.exe:Half-Life Launcher

"DoNotAllowExceptions"= 1 (0x1)

"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [2007-12-21 33800]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
R4 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
R4 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [2009-01-09 55264]
S3 fsssvc;Windows Live Porodicna bezbednost;c:\program files\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]

\shell\AutoRun\command - J:\gg.exe 0o
\shell\explore\Command - J:\gg.exe 0e
\shell\open\Command - J:\gg.exe 0o
Contents of the 'Scheduled Tasks' folder

2009-01-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1598111960-1725439960-2952766009-1000.job
- c:\users\Korisnik\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-15 18:24]

2009-01-19 c:\windows\Tasks\User_Feed_Synchronization-{6CF4450E-8C99-42AD-8F91-422A72AC1864}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 10:45]
------- Supplementary Scan -------
uStart Page = hxxp://
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Korisnik\AppData\Roaming\Mozilla\Firefox\Profiles\44gzldc5.default\
FF - prefs.js: browser.startup.homepage -
FF - component: c:\program files\Internet Saving Optimizer\\FF\components\NPFFAddOn.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Korisnik\AppData\Local\Google\Update\\npGoogleOneClick7.dll


catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-01-20 01:35:27
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

Completion time: 2009-01-20 1:36:55
ComboFix-quarantined-files.txt 2009-01-20 00:36:51

Pre-Run: bytes free
Post-Run: 20,134,035,456 bytes free

267 --- E O F --- 2009-01-19 21:52:57

Dopuna: 20 Jan 2009 3:10

Za sad je sve uredu. Jel to sve cisto sad?

  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Uploaduj sledeći file na proveru: C:\Program Files\Nice Prosper\CashBackAssistant\CashBackAssistantIE.dll

Upload link:

  • Pridružio: 01 Okt 2008
  • Poruke: 66

Uspesno sam uploadovao.

  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Pogledaj da li imas u add/remove listi program sa sledecim nazivom :

Internet Saving Optimizer

Ukoliko imas.. deinstaliraj ga.

Ukoliko nemas, obrisi sledeci folder C:\Program Files\Internet Saving Optimizer

Kada to uradis pokreni HijackThis i stikliraj sledecu liniju:

O2 - BHO: NP Helper Class - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - C:\Program Files\Internet Saving Optimizer\\NPIEAddOn.dll

I klikni Fix Checked.

Nakon toga postavi mi svez Hijackthis log.

  • Pridružio: 01 Okt 2008
  • Poruke: 66

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:52:55, on 21.1.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: CashBackAssistant - {00F5B5BA-E3C2-4b70-BF51-42A557914FAD} - C:\Program Files\Nice Prosper\CashBackAssistant\CashBackAssistantIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {35B8D58C-B0CB-46b0-BA64-05B3804E4E86} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live pomagac za prijavljivanje - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Myweather] "D:\Programi\WEATHER\MyWeather.exe" /autorun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Korisnik\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

End of file - 6555 bytes

  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Kakvo je sada stanje? Da li jos ima redirekcija...

Ko je trenutno na forumu

Ukupno su 861 korisnika na forumu :: 6 registrovanih, 1 sakriven i 854 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Avalon015, draganl, ILGromovnik, marsovac 2, Neutral-M, voja64