Ne mogu da instaliram anti virus, i task manager mi je onesp

Ne mogu da instaliram anti virus, i task manager mi je onesp

offline
  • DBZ 
  • Novi MyCity građanin
  • Pridružio: 16 Maj 2009
  • Poruke: 4

ne mogu da instaliram neki redovan anti-virus, a onaj što sam imao mi je onesposobio taj virus il već šta je.Uspeo sam i jedino neki anti malware da instaliram i on pronadje ovo

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.

ali ne može da se reši toga. Reinstalirao sam windows i formatirao C disk i dalje je tu, verovatno se uvukao negde na D ali imam prefiše stvari tamo koje mi trebaju i ne mogu da ih obrišem. Ima li neke pomoći ?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...

Kreneš od ovoga...


offline
  • DBZ 
  • Novi MyCity građanin
  • Pridružio: 16 Maj 2009
  • Poruke: 4

evo ga

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:30:32 PM, on 16/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20772)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Flock\flock.exe
C:\Program Files\uTorrent\uTorrent.exe
F:\yxrs.exe
C:\Users\Dejan\Desktop\New Folder\asd.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5E579F29-5227-4038-AB44-32714F1E9307}: NameServer = 194.247.192.1 194.247.192.33
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 4953 bytes

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Šta ti je drive F: ? Particija na HDD-u, flash drive?




Arrow Skini program RSIT na Desktop:

http://images.malwareremoval.com/random/RSIT.exe


Pokreni ga dvoklikom a zatim klikni Continue.


Na kraju procesa će se otvoriti dva loga: prvi, log.txt će biti maksimizovan i njega je potrebno iskopirati u temu na forumu, te drugi, info.txt koji će biti minimizovan (koji nam za sada ne treba).


Postavi sadržaj file-a log.txt u iduću poruku (taj file će biti sačuvan kao C:\rsit\log.txt).

offline
  • DBZ 
  • Novi MyCity građanin
  • Pridružio: 16 Maj 2009
  • Poruke: 4

Logfile of random's system information tool 1.06 (written by random/random)
Run by Dejan at 2009-05-16 20:19:40
Microsoft Windows XP Professional Service Pack 3
System drive C: has 291 GB (97%) free of 300 GB
Total RAM: 2047 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:19:44 PM, on 16/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20772)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Flock\flock.exe
C:\Program Files\uTorrent\uTorrent.exe
D:\Program files\Rockstar Games\GTA San Andreas\gta_sa.exe
C:\Users\Dejan\Desktop\RSIT.exe
C:\Program Files\trend micro\Dejan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5E579F29-5227-4038-AB44-32714F1E9307}: NameServer = 194.247.192.1 194.247.192.33
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 5030 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll [2008-03-25 509328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"=C:\WINDOWS\system32\SysTray.Exe [2008-05-05 3072]
"RemoteControl9"=C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe [2009-02-16 87336]
"PDVD9LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe [2008-10-13 124200]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2009-05-10 75048]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-04-01 36352]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-07-03 16876032]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 135168]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-29 135168]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2007-01-23 178960]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-04-06 1347216]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-05-05 40448]

C:\Users\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-09-30 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-05-05 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-05-05 133632]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=1
"DisableTaskMgr"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SynchronousMachineGroupPolicy"=0
"SynchronousUserGroupPolicy"=0
"EnableLUA"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMConfigurePrograms"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSMConfigurePrograms"=
"NoToolbarCustomize"=
"NoBandCustomize"=
"NoActiveDesktop"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Programi\ACDSee 10\acdsee-10-0-219-en.exe"="D:\Programi\ACDSee 10\acdsee-10-0-219-en.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE:*:Enabled:ipsec"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe"="C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe:*:Enabled:ipsec"
"C:\Program Files\Logitech\SetPoint\LULnchr.exe"="C:\Program Files\Logitech\SetPoint\LULnchr.exe:*:Enabled:ipsec"
"C:\WINDOWS\RTHDCPL.EXE"="C:\WINDOWS\RTHDCPL.EXE:*:Enabled:ipsec"
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe:*:Enabled:ipsec"
"C:\Program Files\Logitech\SetPoint\SetPoint.exe"="C:\Program Files\Logitech\SetPoint\SetPoint.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\userinit.exe"="C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec"
"C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"="C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe:*:Enabled:ipsec"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76de4f71-412a-11de-a981-4d6564696130}]
shell\AUtOplay\command - F:\yxrs.exe
shell\AutoRun\command - F:\yxrs.exe
shell\exPLoRe\command - F:\yxrs.exe
shell\open\command - F:\yxrs.exe


======List of files/folders created in the last 1 months======

2009-05-16 20:19:40 ----D---- C:\rsit
2009-05-16 20:19:40 ----D---- C:\Program Files\trend micro
2009-05-16 17:50:27 ----A---- C:\Program Files\cgckbgej.txt
2009-05-15 22:32:24 ----D---- C:\Users\Dejan\Application Data\WinRAR
2009-05-15 12:57:49 ----D---- C:\Users\All Users\Application Data\GRETECH
2009-05-15 12:57:04 ----D---- C:\Users\Dejan\Application Data\GRETECH
2009-05-15 12:56:55 ----D---- C:\Program Files\GRETECH
2009-05-15 11:18:24 ----D---- C:\Users\Dejan\Application Data\CyberLink
2009-05-15 11:14:30 ----D---- C:\Users\Dejan\Application Data\Winamp
2009-05-15 10:29:13 ----D---- C:\Users\Dejan\Application Data\BSplayer PRO
2009-05-15 09:51:45 ----D---- C:\Users\Dejan\Application Data\Malwarebytes
2009-05-15 09:28:56 ----D---- C:\Users\Dejan\Application Data\Flock
2009-05-15 00:53:04 ----A---- C:\WINDOWS\system32\h323log.txt
2009-05-15 00:52:12 ----A---- C:\WINDOWS\system32\hidserv.dll
2009-05-15 00:51:49 ----A---- C:\WINDOWS\adidsl.ini
2009-05-15 00:50:23 ----A---- C:\WINDOWS\system32\usbui.dll
2009-05-15 00:49:11 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-05-15 00:49:10 ----SHD---- C:\WINDOWS\Installer
2009-05-15 00:49:10 ----D---- C:\Program Files\Common Files\ODBC
2009-05-15 00:49:10 ----A---- C:\WINDOWS\ODBCINST.INI
2009-05-15 00:49:07 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-05-15 00:49:06 ----RD---- C:\Program Files
2009-05-15 00:49:06 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-15 00:49:06 ----D---- C:\Program Files\Common Files
2009-05-15 00:49:02 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-05-15 00:49:02 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-05-15 00:49:02 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-05-15 00:48:51 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-05-15 00:48:46 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-05-15 00:48:46 ----A---- C:\WINDOWS\system32\irclass.dll
2009-05-15 00:48:46 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-05-15 00:48:46 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-05-15 00:48:45 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-05-15 00:48:43 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-05-15 00:48:43 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-05-15 00:48:42 ----A---- C:\WINDOWS\system32\batt.dll
2009-05-15 00:48:41 ----A---- C:\WINDOWS\system32\storprop.dll
2009-05-15 00:48:41 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-05-15 00:48:35 ----ASH---- C:\Users\All Users\Application Data\desktop.ini
2009-05-15 00:46:50 ----RA---- C:\WINDOWS\SET8.tmp
2009-05-15 00:46:49 ----RA---- C:\WINDOWS\SET4.tmp
2009-05-15 00:46:47 ----RA---- C:\WINDOWS\SET3.tmp
2009-05-15 00:46:43 ----D---- C:\WINDOWS\system32\CatRoot2
2009-05-15 00:46:43 ----D---- C:\WINDOWS\system32\CatRoot
2009-05-15 00:46:38 ----SD---- C:\Users\All Users\Application Data\Microsoft
2009-05-15 00:45:52 ----A---- C:\WINDOWS\setuplog.txt
2009-05-15 00:45:46 ----A---- C:\ShowWPI.ini
2009-05-15 00:43:59 ----A---- C:\WINDOWS\system32\adadix32.dll
2009-05-15 00:43:59 ----A---- C:\WINDOWS\system32\ADADIX2K.DLL
2009-05-15 00:42:06 ----D---- C:\ppGames
2009-05-15 00:42:06 ----D---- C:\ppApps
2009-05-15 00:42:04 ----A---- C:\WINDOWS\~DF6C7F.tmp
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\sleep.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\pskill.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\oeminfo.ini
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\nircmdc.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\nircmd.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\myuninst.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\cmdhide.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\WAIT.EXE
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\Tweakui.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\Refresh.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\MyCleaner.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\cWnd.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\calc.exe
2009-05-15 00:41:55 ----A---- C:\WINDOWS\system32\DELTREE.EXE
2009-05-15 00:41:55 ----A---- C:\WINDOWS\system32\ChangeWallpaper.exe
2009-05-15 00:41:37 ----A---- C:\WINDOWS\Removes.ini
2009-05-15 00:41:35 ----AD---- C:\WINDOWS\LastXP
2009-05-15 00:41:05 ----D---- C:\Users
2009-05-15 00:41:04 ----SHD---- C:\System Volume Information
2009-05-15 00:40:31 ----RSH---- C:\boot.ini
2009-05-15 00:34:24 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-05-15 00:34:24 ----RSD---- C:\WINDOWS\Fonts
2009-05-15 00:34:24 ----RD---- C:\WINDOWS\Offline Web Pages
2009-05-15 00:34:24 ----HD---- C:\WINDOWS\inf
2009-05-15 00:34:24 ----D---- C:\WINDOWS\WinSxS
2009-05-15 00:34:24 ----D---- C:\WINDOWS\WBEM
2009-05-15 00:34:24 ----D---- C:\WINDOWS\twain_32
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Temp
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\wins
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\wbem
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\usmt
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\spool
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\ShellExt
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\Setup
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\scripting
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\ras
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\oobe
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\npp
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\mui
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\inetsrv
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\IME
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\icsxml
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\ias
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\export
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\en-US
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\en
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\drivers
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\dhcp
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\config
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\3com_dmi
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\3076
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\2052
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1054
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1042
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1041
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1037
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1033
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1031
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1028
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1025
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system
2009-05-15 00:34:24 ----D---- C:\WINDOWS\security
2009-05-15 00:34:24 ----D---- C:\WINDOWS\repair
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Provisioning
2009-05-15 00:34:24 ----D---- C:\WINDOWS\PeerNet
2009-05-15 00:34:24 ----D---- C:\WINDOWS\pchealth
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Network Diagnostic
2009-05-15 00:34:24 ----D---- C:\WINDOWS\mui
2009-05-15 00:34:24 ----D---- C:\WINDOWS\msapps
2009-05-15 00:34:24 ----D---- C:\WINDOWS\msagent
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Media
2009-05-15 00:34:24 ----D---- C:\WINDOWS\L2Schemas
2009-05-15 00:34:24 ----D---- C:\WINDOWS\java
2009-05-15 00:34:24 ----D---- C:\WINDOWS\ime
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Help
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Driver Cache
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Debug
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Cursors
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Connection Wizard
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Config
2009-05-15 00:34:24 ----D---- C:\WINDOWS\AppPatch
2009-05-15 00:34:24 ----D---- C:\WINDOWS\addins
2009-05-15 00:34:24 ----D---- C:\WINDOWS
2009-05-15 00:34:24 ----AD---- C:\WINDOWS\Web
2009-05-15 00:34:24 ----AD---- C:\WINDOWS\system32
2009-05-15 00:34:24 ----AD---- C:\WINDOWS\Resources
2009-05-14 23:57:07 ----D---- C:\Program Files\uTorrent
2009-05-14 23:56:41 ----D---- C:\Users\Dejan\Application Data\uTorrent
2009-05-14 23:55:31 ----D---- C:\Program Files\WinRAR
2009-05-14 23:54:45 ----D---- C:\Users\Dejan\Application Data\Macromedia
2009-05-14 23:54:45 ----D---- C:\Users\Dejan\Application Data\Adobe
2009-05-14 23:43:23 ----D---- C:\Users\Dejan\Application Data\Logitech
2009-05-14 23:43:06 ----SHD---- C:\RECYCLER
2009-05-14 23:43:06 ----R---- C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2009-05-14 23:42:19 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
2009-05-14 23:42:13 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-05-14 23:42:12 ----A---- C:\WINDOWS\system32\WdfCoInstaller01005.dll
2009-05-14 23:42:12 ----A---- C:\WINDOWS\KHALMNPR.Exe
2009-05-14 23:42:08 ----A---- C:\WINDOWS\system32\KemXML.dll
2009-05-14 23:42:08 ----A---- C:\WINDOWS\system32\KemWnd.dll
2009-05-14 23:42:08 ----A---- C:\WINDOWS\system32\KemUtil.dll
2009-05-14 23:42:08 ----A---- C:\WINDOWS\system32\kemutb.dll
2009-05-14 23:41:55 ----D---- C:\Users\All Users\Application Data\Logitech
2009-05-14 23:41:54 ----D---- C:\Program Files\Logitech
2009-05-14 23:41:52 ----D---- C:\Program Files\Common Files\Logitech
2009-05-14 23:38:35 ----D---- C:\Users\Dejan\Application Data\Mozilla
2009-05-14 23:38:31 ----D---- C:\Program Files\Mozilla Firefox
2009-05-14 23:35:44 ----D---- C:\WINDOWS\system32\Lang
2009-05-14 23:35:40 ----D---- C:\Users\Dejan\Application Data\ATI
2009-05-14 23:35:40 ----D---- C:\Users\All Users\Application Data\ATI
2009-05-14 23:35:25 ----D---- C:\Users\Dejan\Application Data\Identities
2009-05-14 23:35:25 ----A---- C:\WINDOWS\OEWABLog.txt
2009-05-14 23:35:11 ----ASH---- C:\Users\Dejan\Application Data\desktop.ini
2009-05-14 23:35:10 ----SD---- C:\Users\Dejan\Application Data\Microsoft
2009-05-14 23:31:30 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2009-05-14 23:31:28 ----RA---- C:\WINDOWS\system32\ATIODE.exe.manifest
2009-05-14 23:31:28 ----RA---- C:\WINDOWS\system32\ATIODCLI.exe.manifest
2009-05-14 23:31:28 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
2009-05-14 23:31:26 ----RA---- C:\WINDOWS\system32\ATIDEMGX.dll
2009-05-14 23:30:54 ----D---- C:\Program Files\ATI Technologies
2009-05-14 23:27:33 ----R---- C:\WINDOWS\system32\ChCfg.exe
2009-05-14 23:27:18 ----D---- C:\WINDOWS\system32\RTCOM
2009-05-14 23:27:17 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-05-14 23:27:14 ----R---- C:\WINDOWS\SoundMan.exe
2009-05-14 23:27:14 ----R---- C:\WINDOWS\SkyTel.exe
2009-05-14 23:27:13 ----R---- C:\WINDOWS\RtlUpd.exe
2009-05-14 23:27:11 ----R---- C:\WINDOWS\RTLCPL.exe
2009-05-14 23:27:06 ----R---- C:\WINDOWS\RTHDCPL.exe
2009-05-14 23:27:05 ----R---- C:\WINDOWS\MicCal.exe
2009-05-14 23:27:00 ----R---- C:\WINDOWS\Alcmtr.exe
2009-05-14 23:26:58 ----R---- C:\WINDOWS\alcwzrd.exe
2009-05-14 23:26:57 ----D---- C:\Program Files\Realtek
2009-05-14 23:26:49 ----A---- C:\WINDOWS\HideWin.exe
2009-05-14 23:26:48 ----R---- C:\WINDOWS\RtlExUpd.dll
2009-05-14 23:25:49 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-05-14 23:25:48 ----D---- C:\Program Files\AMD
2009-05-14 23:23:09 ----A---- C:\WINDOWS\Fast800.ini
2009-05-14 23:23:05 ----A---- C:\WINDOWS\system32\IPDETECT.EXE
2009-05-14 23:23:05 ----A---- C:\WINDOWS\adirasx64.exe
2009-05-14 23:23:05 ----A---- C:\WINDOWS\adiras.ini
2009-05-14 23:23:05 ----A---- C:\WINDOWS\adiras.exe
2009-05-14 23:23:00 ----A---- C:\WINDOWS\system32\coclassfast.dll
2009-05-14 23:23:00 ----A---- C:\WINDOWS\enddisk32.exe
2009-05-14 23:23:00 ----A---- C:\WINDOWS\autoclk.exe
2009-05-14 23:22:59 ----A---- C:\WINDOWS\system32\unaddrv.x64.exe
2009-05-14 23:22:59 ----A---- C:\WINDOWS\system32\unaddrv.exe
2009-05-14 23:22:59 ----A---- C:\WINDOWS\system32\ADADIX16.DLL
2009-05-14 23:22:49 ----D---- C:\Program Files\SAGEM
2009-05-14 23:21:12 ----A---- C:\WINDOWS\system32\unrar.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\dpl100.dll
2009-05-14 23:21:10 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2009-05-14 23:21:10 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2009-05-14 23:21:10 ----A---- C:\WINDOWS\system32\divx.dll
2009-05-14 23:21:09 ----D---- C:\Program Files\K-Lite Codec Pack
2009-05-14 23:20:25 ----D---- C:\Users\All Users\Application Data\Malwarebytes
2009-05-14 23:20:24 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\px.dll
2009-05-14 23:19:19 ----D---- C:\Program Files\Winamp
2009-05-14 23:18:28 ----D---- C:\totalcmd
2009-05-14 23:18:28 ----A---- C:\WINDOWS\wincmd.ini
2009-05-14 23:17:41 ----D---- C:\Program Files\Flock
2009-05-14 23:15:37 ----D---- C:\Users\All Users\Application Data\CyberLink
2009-05-14 23:15:32 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-14 23:15:32 ----D---- C:\Program Files\Common Files\CyberLink
2009-05-14 23:15:13 ----D---- C:\Program Files\CyberLink
2009-05-14 23:15:05 ----A---- C:\WINDOWS\system32\msxml3a.dll
2009-05-14 23:14:33 ----D---- C:\Users\All Users\Application Data\Temp
2009-05-14 23:13:33 ----D---- C:\Program Files\Webteh
2009-05-14 23:10:54 ----D---- C:\Users\All Users\Application Data\ACD Systems
2009-05-14 23:10:52 ----D---- C:\Program Files\Common Files\ACD Systems
2009-05-14 23:10:52 ----D---- C:\Program Files\ACD Systems
2009-05-14 23:07:57 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-05-14 23:07:08 ----D---- C:\Users\All Users\Application Data\Windows Genuine Advantage
2009-05-14 23:06:46 ----D---- C:\WINDOWS\SoftwareDistribution
2009-05-14 23:06:44 ----SD---- C:\WINDOWS\system32\Microsoft
2009-05-14 23:06:44 ----D---- C:\WINDOWS\Prefetch
2009-05-14 23:06:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-05-14 23:04:39 ----D---- C:\Program Files\Microsoft Silverlight
2009-05-14 23:04:35 ----A---- C:\WINDOWS\system32\javaws.exe
2009-05-14 23:04:35 ----A---- C:\WINDOWS\system32\javaw.exe
2009-05-14 23:04:35 ----A---- C:\WINDOWS\system32\java.exe
2009-05-14 23:04:25 ----D---- C:\Program Files\Java
2009-05-14 23:04:25 ----D---- C:\Program Files\Common Files\Java
2009-05-14 23:04:03 ----D---- C:\Program Files\Common Files\InstallShield
2009-05-14 23:00:57 ----D---- C:\WINDOWS\system32\XPSViewer
2009-05-14 23:00:57 ----D---- C:\Program Files\MSBuild
2009-05-14 23:00:56 ----D---- C:\Program Files\Reference Assemblies
2009-05-14 23:00:52 ----N---- C:\WINDOWS\system32\spmsg2.dll
2009-05-14 22:59:37 ----RSD---- C:\WINDOWS\assembly
2009-05-14 22:59:37 ----D---- C:\WINDOWS\Microsoft.NET
2009-05-14 22:59:36 ----D---- C:\WINDOWS\system32\URTTemp
2009-05-14 22:59:33 ----N---- C:\WINDOWS\system32\XpsSvcs.dll
2009-05-14 22:59:33 ----N---- C:\WINDOWS\system32\XPSSHHDR.dll
2009-05-14 22:59:24 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-05-14 22:58:38 ----D---- C:\Program Files\Windows Sidebar
2009-05-14 22:58:36 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-05-14 22:58:36 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-05-14 22:58:27 ----D---- C:\Program Files\Alky for Applications
2009-05-14 22:58:15 ----A---- C:\WINDOWS\control.ini
2009-05-14 22:58:15 ----A---- C:\AUTOEXEC.BAT
2009-05-14 22:58:02 ----D---- C:\WINDOWS\system32\dllcache
2009-05-14 22:58:02 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-05-14 22:57:24 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-05-14 22:57:21 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-05-14 22:57:17 ----HD---- C:\Program Files\WindowsUpdate
2009-05-14 22:56:52 ----D---- C:\WINDOWS\system32\DirectX
2009-05-14 22:56:44 ----A---- C:\WINDOWS\system32\atrace.dll
2009-05-14 22:56:42 ----A---- C:\WINDOWS\system32\desktop.ini
2009-05-14 22:56:42 ----A---- C:\WINDOWS\desktop.ini
2009-05-14 22:56:34 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-05-14 22:56:32 ----D---- C:\Program Files\Common Files\Services
2009-05-14 22:56:32 ----A---- C:\WINDOWS\system32\acctres.dll
2009-05-14 22:56:28 ----SD---- C:\WINDOWS\Tasks
2009-05-14 22:56:28 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-05-14 22:56:27 ----D---- C:\Program Files\Common Files\MSSoap
2009-05-14 22:56:22 ----D---- C:\WINDOWS\srchasst
2009-05-14 22:56:21 ----D---- C:\WINDOWS\system32\Macromed
2009-05-14 22:56:18 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-05-14 22:56:18 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-05-14 22:56:18 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-05-14 22:56:18 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-05-14 22:56:17 ----A---- C:\WINDOWS\system32\wups.dll
2009-05-14 22:56:17 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-05-14 22:56:17 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-05-14 22:56:11 ----D---- C:\Program Files\Movie Maker
2009-05-14 22:55:48 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-05-14 22:55:48 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-05-14 22:55:48 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-05-14 22:55:47 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-05-14 22:55:43 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-05-14 22:55:43 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-05-14 22:55:42 ----D---- C:\WINDOWS\system32\Restore
2009-05-14 22:55:42 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-05-14 22:55:42 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-05-14 22:55:42 ----A---- C:\WINDOWS\system32\srclient.dll
2009-05-14 22:55:41 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-05-14 22:55:41 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-05-14 22:55:41 ----A---- C:\WINDOWS\system32\ils.dll
2009-05-14 22:55:40 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-05-14 22:55:40 ----A---- C:\WINDOWS\system32\msconf.dll
2009-05-14 22:55:40 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-05-14 22:55:37 ----D---- C:\Program Files\NetMeeting
2009-05-14 22:55:36 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-05-14 22:55:36 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-05-14 22:55:34 ----A---- C:\WINDOWS\system32\inetres.dll
2009-05-14 22:55:34 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-05-14 22:55:32 ----D---- C:\Program Files\Outlook Express
2009-05-14 22:55:32 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-05-14 22:55:32 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-05-14 22:55:31 ----A---- C:\WINDOWS\system32\mstask.dll
2009-05-14 22:55:31 ----A---- C:\WINDOWS\system32\isign32.dll
2009-05-14 22:55:31 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-05-14 22:55:31 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-05-14 22:55:30 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-05-14 22:55:23 ----D---- C:\Program Files\Common Files\System
2009-05-14 22:55:21 ----D---- C:\Program Files\Internet Explorer
2009-05-14 22:55:02 ----HD---- C:\Program Files\Uninstall Information
2009-05-14 22:54:53 ----D---- C:\Program Files\ComPlus Applications
2009-05-14 22:54:52 ----A---- C:\WINDOWS\vbaddin.ini
2009-05-14 22:54:52 ----A---- C:\WINDOWS\vb.ini
2009-05-14 22:54:48 ----D---- C:\WINDOWS\Registration
2009-05-14 22:54:33 ----D---- C:\Program Files\Windows Media Connect 2
2009-05-14 22:54:32 ----D---- C:\Program Files\Windows Media Player
2009-05-14 22:54:32 ----A---- C:\WINDOWS\system32\cygwin1.dll
2009-05-14 22:54:31 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2009-05-14 22:54:31 ----A---- C:\WINDOWS\system32\autoitx3.dll
2009-05-14 22:54:31 ----A---- C:\WINDOWS\system32\atl71.dll
2009-05-14 22:54:31 ----A---- C:\WINDOWS\system32\atl70.dll
2009-05-14 22:54:30 ----A---- C:\WINDOWS\system32\vb40032.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\ssleay32.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\openal32.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvcr71.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvcr70.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvcp71.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvcp70.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvci70.dll
2009-05-14 22:54:28 ----A---- C:\WINDOWS\system32\msstkprp.dll
2009-05-14 22:54:28 ----A---- C:\WINDOWS\system32\msstdfmt.dll
2009-05-14 22:54:27 ----A---- C:\WINDOWS\system32\mfc71u.dll
2009-05-14 22:54:27 ----A---- C:\WINDOWS\system32\mfc71.dll
2009-05-14 22:54:27 ----A---- C:\WINDOWS\system32\mfc70u.dll
2009-05-14 22:54:26 ----A---- C:\WINDOWS\system32\mfc70.dll
2009-05-14 22:54:26 ----A---- C:\WINDOWS\system32\libssl32.dll
2009-05-14 22:54:26 ----A---- C:\WINDOWS\system32\libmmd.dll
2009-05-14 22:54:25 ----A---- C:\WINDOWS\system32\libintl3.dll
2009-05-14 22:54:25 ----A---- C:\WINDOWS\system32\libiconv2.dll
2009-05-14 22:54:25 ----A---- C:\WINDOWS\system32\libeay32.dll
2009-05-14 22:54:24 ----A---- C:\WINDOWS\system32\cygwinb19.dll
2009-05-14 22:54:14 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-05-14 22:54:14 ----A---- C:\WINDOWS\system32\hticons.dll
2009-05-14 22:54:13 ----D---- C:\Program Files\Windows NT
2009-05-14 22:54:13 ----A---- C:\WINDOWS\system32\winchat.exe
2009-05-14 22:54:12 ----A---- C:\WINDOWS\system32\reset.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tskill.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tscon.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\shadow.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\regini.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\msg.exe
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\logoff.exe
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-05-14 22:54:02 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-05-14 22:54:02 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-05-14 22:54:02 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-05-14 22:54:02 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-05-14 22:54:01 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-05-14 22:54:00 ----A---- C:\WINDOWS\system32\tsgqec.dll
2009-05-14 22:54:00 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-05-14 22:54:00 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2009-05-14 22:54:00 ----A---- C:\WINDOWS\system32\aaclient.dll
2009-05-14 22:53:59 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-05-14 22:53:59 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-05-14 22:53:59 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-05-14 22:53:57 ----D---- C:\WINDOWS\system32\MsDtc
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-05-14 22:53:56 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-05-14 22:53:56 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-05-14 22:53:56 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-05-14 22:53:56 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-05-14 22:53:55 ----D---- C:\WINDOWS\system32\Com
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\colbact.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\stclient.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-05-14 22:53:53 ----A---- C:\WINDOWS\system32\comuid.dll
2009-05-14 22:53:53 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-05-14 22:53:53 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-05-14 22:53:53 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-05-14 22:53:45 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-05-14 22:53:45 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-05-14 22:53:45 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-05-14 22:53:45 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2009-05-14 23:14:30 ----A---- C:\WINDOWS\system32\msxml3r.dll
2009-05-14 23:08:41 ----A---- C:\WINDOWS\system.ini
2009-05-14 22:58:13 ----A---- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/05/14 23:15:37]; \??\C:\Program Files\CyberLink\PowerDVD9\000.fcl []
R3 abp470n5;abp470n5; \??\C:\WINDOWS\system32\drivers\ikkoon.sys []
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2007-02-07 118552]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-09-30 3331584]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-07-02 89600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-05-05 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-07-03 4745216]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-01-23 34576]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2007-01-23 33296]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [2007-01-23 28176]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S2 ELOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2007-02-07 56088]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-05-05 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-05-05 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-09-30 581632]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-09-30 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 143360]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 991232]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-05-05 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Sality virus - ovo ne može da se očisti na valjan način.


Ono što treba da uradiš jeste:

- formatiraj C: particiju i instaliraj Windows.
- odmah nakon toga skini i skeniraj ovim programom:

http://www.freedrweb.com/download+cureit/gr/

Potrebno je skenirati kompletan HDD kako se ne bi opet inficirao.

Nakon toga bi sve trebalo biti ok.

Ono što je bitno - skeniranje moraš izvršiti odmah nakon instalacije Windows-a. Znači, nikakve instalacije programa ili otvaranje ostalih particija pomoću Windows Explorer-a pre no što sve bude dezinfikovano.


Nisi mi odgovorio šta ti je F: drive. U svakom slučaju, i on je inficiran. Imaj to na umu.


Detaljno uputstvo za skeniranje:

Preuzmi Dr.Web CureIt (~13 MB).
Dvoklikom pokreni launch.exe, nakon čega će se pojaviti uvodni prozor - klikni Start

Pojaviće se obaveštenje o započinjanju uvodnog skeniranja - klikni OK

Sačekaj nekoliko minuta da Dr.Web CureIt izvrši Express Scan; ukoliko malware bude pronađen, klikom na taster Yes to All u prozoru koji se pojavi dozvoli programu da izvrši dezinfekciju

Klikni Options > Change settings F9; u prozoru koji će se otvoriti, dečekiraj opciju Heuristic Analysis a zatim klikni OK

U glavnom prozoru obeleži opciju Complete scan a zatim klikni i Dr.Web CureIt će započeti skeniranje

Ukoliko malware bude pronađen, klikom na taster Yes to All u prozoru koji se pojavi dozvoli programu da izvrši dezinfekciju

Kada skeniranje bude završeno, klikni Select all taster (ukoliko je dostupan), a zatim klikni Cure i,
u meniju koji se otvori, klikni Move incurable:


Po završetku procesa, klikni File > Save report list i sačuvaj log na Desktopu

offline
  • DBZ 
  • Novi MyCity građanin
  • Pridružio: 16 Maj 2009
  • Poruke: 4

Jesam ga, hvala ti mnogo.Predlpostavljam da hoces da vidis log pa cu ti prekopirati.

It_s_the_Great_Pumpkin__1966_.exe;D:\Dejan\Charile Brown and Snoopy;Win32.Sector.17;Cured.;
daemon4121-lite.exe\data051;D:\Dejan\Programi\daemon4121-lite.exe;Adware.Shopper;;
daemon4121-lite.exe;D:\Dejan\Programi;Archive contains infected objects;Moved.;
ffdshow_rev1928_20080410_xxl_setup.exe;D:\Dejan\Programi;Trojan.MulDrop.15890;Deleted.;
Firefox Setup 3.0.10.exe;D:\Dejan\Programi;Win32.Sector.17;Cured.;
GOMPLAYERENSETUP.EXE;D:\Dejan\Programi;Win32.Sector.17;Cured.;
xchat-2.8.7c.exe\data011;D:\Dejan\Programi\xchat-2.8.7c.exe;Trojan.DownLoad.31821;;
xchat-2.8.7c.exe;D:\Dejan\Programi;Archive contains infected objects;Moved.;
acdsee-10-0-219-en.exe;D:\Dejan\Programi\ACDSee 10;Win32.Sector.17;Cured.;
bsplayer_pro231.974.exe;D:\Dejan\Programi\BSplayer Pro v2.31 Build 974 [Software][Players][www.erostorrent.com];Win32.Sector.17;Cured.;
CORE10k.EXE;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz];Win32.Sector.17;Cured.;
CLSM.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup;Win32.Sector.17;Cured.;
instmsiw.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup;Win32.Sector.17;Cured.;
setup.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup;Win32.Sector.17;Cured.;
RichVideo.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup\RichVideo;Win32.Sector.17;Cured.;
RichVideoInstall.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup\RichVideo;Win32.Sector.17;Cured.;
RichVideoUnInstall.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup\RichVideo;Win32.Sector.17;Cured.;
7za.exe;D:\Program files\Activision\Call of Duty 4 - Modern Warfare\Mods\ModWarfare;Win32.Sector.17;Cured.;
Transformers.exe;D:\Program files\Activision\Transformers - The Game;Win32.Sector.17;Cured.;
Launcher.exe;D:\Program files\Capcom\MotoGP 08;Win32.Sector.17;Cured.;
Pure.exe;D:\Program files\Disney Interactive Studios\Pure;Win32.Sector.17;Cured.;
DSN1.exe;D:\Program files\Disney Interactive Studios\Pure\eReg;Win32.Sector.17;Cured.;
Fouc.exe;D:\Program files\Empire Interactive\FlatOut Ultimate Carnage\FlatOut Ultimate Carnage;Win32.Sector.17;Cured.;
launcher.exe;D:\Program files\Empire Interactive\FlatOut Ultimate Carnage\FlatOut Ultimate Carnage;Win32.Sector.17;Cured.;
dxwebsetup.exe;D:\Program files\Empire Interactive\FlatOut Ultimate Carnage\FlatOut Ultimate Carnage\#readme#\redist;Win32.Sector.17;Cured.;
vcredist_x86.exe;D:\Program files\Empire Interactive\FlatOut Ultimate Carnage\FlatOut Ultimate Carnage\#readme#\redist;Win32.Sector.17;Cured.;
protect.exe;D:\Program files\Empire Interactive\FlatOut2;Win32.Sector.17;Cured.;
settings.exe;D:\Program files\KONAMI\Pro Evolution Soccer 2008;Win32.Sector.17;Cured.;
Unleashed Editor.exe;D:\Program files\THQ\MX vs ATV Unleashed;Win32.Sector.17;Cured.;
_isdel.exe;D:\Program files\THQ\MX vs ATV Unleashed;Win32.Sector.17;Cured.;
A0004073.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP1;Win32.Sector.17;Cured.;
A0004474.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004499.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004599.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004645.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004699.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004748.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004920.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004921.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004937.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004957.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004958.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004959.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004960.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004961.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004965.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004970.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004977.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004978.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005025.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005045.EXE;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005236.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005237.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005247.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005248.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005249.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005250.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005251.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005252.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005255.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005260.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005263.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005264.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005371.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005390.EXE;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005587.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005588.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005599.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005600.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005601.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005602.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005603.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005604.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005607.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005612.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005615.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005616.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005717.EXE;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP11;Win32.Sector.17;Cured.;
A0005746.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP11;Win32.Sector.17;Cured.;
A0004102.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP2;Win32.Sector.17;Cured.;
A0004229.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP4;Win32.Sector.17;Cured.;
A0004263.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP5;Win32.Sector.17;Cured.;
A0004379.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP8;Win32.Sector.17;Cured.;
A0000794.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000796.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000798.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000799.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000806.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000807.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000810.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000811.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000795.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000796.exe\data051;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3\A0000796.exe;Adware.Shopper;;
A0000796.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Archive contains infected objects;Moved.;
A0000797.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Trojan.MulDrop.15890;Deleted.;
A0000798.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000799.EXE;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000800.exe\data011;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3\A0000800.exe;Trojan.DownLoad.31821;;
A0000800.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Archive contains infected objects;Moved.;
A0000801.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000802.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000803.EXE;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000804.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000805.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000806.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000807.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000808.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000809.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000810.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000811.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000812.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000813.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000814.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000815.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000816.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000817.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000818.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000819.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000820.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000821.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000822.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
uoiyi.exe;F:\;Win32.Sector.17;Deleted.;
vvcfo.exe;F:\;Win32.Sector.17;Deleted.;
yxrs.exe;F:\;Win32.Sector.17;Deleted.;

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

To bi trebalo biti to. Instaliraj antivirus i onda polako dalje...


poz

Ko je trenutno na forumu
 

Ukupno su 856 korisnika na forumu :: 50 registrovanih, 5 sakrivenih i 801 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: anta, bankulen, bojank, cikadeda, darionis, darkangel, Dimitrije Paunovic, Dimitrise93, Djokislav, DonRumataEstorski, Dovla, draganv97, drimer, dushan, galerija, Georgius, hyla, Ilija Cvorovic, Ivica1102, kljift, Kubovac, laurusri, lord sir giga, Lošmi, MB120mm, mercedesamg, Metanoja, mikrimaus, milenko crazy north, MiroslavD, mocnijogurt, nikoladim, NikolaGTR, nuke92, proka89, rajkoplje, rodoljub, Romibrat, ruma, saputnik plavetnila, Sir Budimir, SR-3m, Srle993, stegonosa, TheBeastOfMG, zbazin, ZetaMan, zlaya011, šumar bk2, 79693