You are on page 1of 3

Malwarebytes Anti-Malware

www.malwarebytes.org
Scan Date: 16.10.2016
Scan Time: 11:59
Logfile: Virusi koje je naso MB prilikom prvog skeniranja.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.10.16.02
Rootkit Database: v2016.09.26.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Jasko
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 289470
Time Elapsed: 6 min, 41 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 5
Trojan.Glupteba, C:\Users\Jasko\AppData\Roaming\VDI\Shared\Product Updater\produ
pd.exe, 2540, , [62804257a2f8a096cd7323e6a1648977]
Trojan.Glupteba, C:\Users\Jasko\AppData\Roaming\VDI\Shared\Product Updater\monho
st.exe, 3660, , [4f93c8d1abeffa3cef4f9970b94c9967]
Trojan.Injector, C:\Users\Jasko\AppData\Local\UPmedia\9a3e0f04234f71644e58d8b123
6a9983.exe, 4108, , [40a2ecad3367f244a31dad5d996c17e9]
PUP.Optional.Clicker, C:\Users\Jasko\AppData\Roaming\VDI\Shared\Product Updater\
monhost.exe, 3660, , [02e0abee079375c1d72952933cc88878]
PUP.Optional.Clicker, C:\Users\Jasko\AppData\Roaming\VDI\Shared\Product Updater\
produpd.exe, 2540, , [bf239801643654e2996b6a7b51b37090]
Modules: 11
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\UPmedia\qqcrervd.dll, , [845e1782326
8ec4a709dbc43946cd12f],
Trojan.ProxyAgent, C:\Users\Jasko\AppData\Local\apower.dll, , [736f9cfd8a10e452a
363eb210ff6e11f],
Registry Keys: 3
Trojan.ProxyAgent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION
\WINLOGON\NOTIFY\apower, , [736f9cfd8a10e452a363eb210ff6e11f],
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHED
ULE\TASKCACHE\TASKS\{58AFB892-4BEF-4C03-97E1-59B86C57361C}, , [a0420a8f24761f17f
61a84464eb404fc],
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHED
ULE\TASKCACHE\TREE\PPI Update, , [865c7c1d9dfd7bbbe928676352b0837d],
Registry Values: 6
Trojan.Glupteba, HKU\S-1-5-21-1688423098-464368325-331052766-1000\SOFTWARE\MICRO
SOFT\WINDOWS\CURRENTVERSION\RUN|produpd, "C:\Users\Jasko\AppData\Roaming\VDI\Sha
red\Product Updater\produpd.exe" /8175, , [62804257a2f8a096cd7323e6a1648977]
Trojan.ProxyAgent, HKU\S-1-5-21-1688423098-464368325-331052766-1000\SOFTWARE\MIC
ROSOFT\WINDOWS\CURRENTVERSION\RUN|apower, rundll32.exe "C:\Users\Jasko\AppData\L
ocal\apower.dll",apower, , [736f9cfd8a10e452a363eb210ff6e11f]
Trojan.Injector, HKU\S-1-5-21-1688423098-464368325-331052766-1000\SOFTWARE\MICRO
SOFT\WINDOWS\CURRENTVERSION\RUN|UPmedia, C:\Users\Jasko\AppData\Local\UPmedia\9a
3e0f04234f71644e58d8b1236a9983.exe, , [40a2ecad3367f244a31dad5d996c17e9]
PUP.Optional.Clicker, HKU\S-1-5-21-1688423098-464368325-331052766-1000\SOFTWARE\
MICROSOFT\WINDOWS\CURRENTVERSION\RUN|produpd, "C:\Users\Jasko\AppData\Roaming\VD
I\Shared\Product Updater\produpd.exe" /8175, , [bf239801643654e2996b6a7b51b37090
]
PUP.Optional.Downloader, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHED
ULE\TASKCACHE\TASKS\{58AFB892-4BEF-4C03-97E1-59B86C57361C}|Path, \PPI Update, ,
[a0420a8f24761f17f61a84464eb404fc]
Trojan.Boaxxe.Gen, HKU\S-1-5-21-1688423098-464368325-331052766-1000\SOFTWARE\MIC
ROSOFT\WINDOWS\CURRENTVERSION\RUN|YfmPack, regsvr32.exe C:\Users\Jasko\AppData\L
ocal\YfmPack\ppmnygrc.dll, , [a33f41589bff64d20c3358a77e854db3]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 20
Trojan.Miuref, C:\Users\Jasko\AppData\Local\YfmPack\ppmnygrc.dll, , [b2301f7aa2f
8fb3b64a9817e629e10f0],
Trojan.Glupteba, C:\Users\Jasko\AppData\Roaming\VDI\Shared\Product Updater\produ
pd.exe, , [62804257a2f8a096cd7323e6a1648977],
Trojan.Miuref, C:\Users\Jasko\AppData\Local\UPmedia\qqcrervd.dll, , [845e1782326
8ec4a709dbc43946cd12f],
Trojan.ProxyAgent, C:\Users\Jasko\AppData\Local\apower.dll, , [736f9cfd8a10e452a
363eb210ff6e11f],
Trojan.Glupteba, C:\Users\Jasko\AppData\Roaming\VDI\Shared\Product Updater\monho
st.exe, , [4f93c8d1abeffa3cef4f9970b94c9967],
Trojan.Injector, C:\Users\Jasko\AppData\Local\UPmedia\9a3e0f04234f71644e58d8b123
6a9983.exe, , [40a2ecad3367f244a31dad5d996c17e9],
Trojan.Injector, C:\Users\Jasko\AppData\Roaming\ProxySettings.dll, , [4d955e3b6f
2b2a0cd6ea8783cb3a3ac6],
Trojan.Injector, C:\Program Files (x86)\Windows Loader\9a3e0f04234f71644e58d8b12
36a9983.exe, , [855d0c8d118948eefec2df2b7c89718f],
PUP.Optional.DownLoadAdmin, C:\Program Files (x86)\Windows Loader\Registry_Activ
ation-176554725.exe, , [4e944653a0fa0d29e58b6c59db26659b],
PUP.Optional.Amonetize, C:\Program Files (x86)\Windows Loader\Windows Loader 3.1
__8175_il792.exe, , [439f0198cfcbec4a06860efba75edc24],
PUP.Optional.Amonetize, C:\$Recycle.Bin\S-1-5-21-1688423098-464368325-331052766-
1000\$R4Q0R1R.zip, , [eef48c0dadedff37312575fd629f738d],
PUP.Optional.Amonetize, C:\$Recycle.Bin\S-1-5-21-1688423098-464368325-331052766-
1000\$RAWJNM2.zip, , [61818415fb9fd46268eefd75dd2453ad],
PUP.Optional.Amonetize, C:\$Recycle.Bin\S-1-5-21-1688423098-464368325-331052766-
1000\$RG6QFBC.exe, , [8062b8e1772354e23c1a30424cb55fa1],
HackTool.Agent, C:\$Recycle.Bin\S-1-5-21-1688423098-464368325-331052766-1000\$RO
718XT.rar, , [db077623594183b3aaac66bc2bd619e7],
HackTool.Agent, C:\$Recycle.Bin\S-1-5-21-1688423098-464368325-331052766-1000\$R0
VE5RA.2\Windows Loader.exe, , [26bc8f0a8c0eea4c26302bf7d031f40c],
PUP.Optional.Downloader, C:\Windows\System32\Tasks\PPI Update, , [687ac8d1cbcf9b
9b34da8446a35f847c],
PUP.Optional.Clicker, C:\Users\Jasko\AppData\Roaming\VDI\Shared\Product Updater\
monhost.exe, , [02e0abee079375c1d72952933cc88878],
PUP.Optional.Clicker, C:\Users\Jasko\AppData\Roaming\Microsoft\Windows\Start Men
u\Programs\Startup\produpd.lnk, , [4e94c2d73a60c4721fe306df56ae6a96],
PUP.Optional.Clicker, C:\Users\Jasko\AppData\Roaming\VDI\Shared\Product Updater\
produpd.exe, , [bf239801643654e2996b6a7b51b37090],
PUP.Optional.Amonetize, C:\Users\Jasko\AppData\Local\Temp\amipixel.cfg, , [06dc8
b0e8e0cf442d3945d3ff60e0bf5],
Physical Sectors: 0
(No malicious items detected)

(end)

You might also like