Gamad

1

Gamad

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Zakacio sam neku gamad i ne mogu da je skinem nikako i ne pusta me da instaliram Malwarebytes,pa evo ga log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:56 PM, on 1/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.bearshare.com/intl/
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe (file missing)
O9 - Extra 'Tools' menuitem: &Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4028 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Potrebno je da ime programa HijackThis.exe promenis u neko drugo ime, onda skeniras i postavis mi log.

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:20 AM, on 1/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\bla\bla.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.bearshare.com/intl/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\byXOiFUK.dll
O2 - BHO: (no name) - {84AB57A5-6DF1-49C4-B2C5-F3C1DB89E9DC} - C:\WINDOWS\system32\iifFyXOh.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe (file missing)
O9 - Extra 'Tools' menuitem: &Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O20 - Winlogon Notify: byXOiFUK - C:\WINDOWS\SYSTEM32\byXOiFUK.dll
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4713 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

* Klikni desnim tasterom na Kaspersky ikonicu ( ) u donjem, desnom uglu ekrana i izaberi Pause Protection.
* U prozoru koji se otvori, izaberi By User Request.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.

----------------------------

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Ni sa jedne adrese ne mogu da skinem ComboFix.

Dopuna: 04 Jan 2009 13:30

Evo sada sam skinuo i ne mogu da ga pokrenem.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Jesi iskljucio Antivirus?

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Jesam i nece da se pokrene.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ajde probaj ovako,

ponovo iskljuci Antivirus i skini ga sa sledeceg linka:

http://amf.mycity.rs/programs/mirrored/C-F.exe

pa probaj da skeniras.

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Skenirao sam i pobrisa neke file-ove.


ComboFix 08-12-31.01 - Milos 2009-01-04 17:05:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.294 [GMT 1:00]
Running from: c:\documents and settings\Milos\Desktop\C-F.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated)
FW: Kaspersky Internet Security *enabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\crypts.dll
c:\windows\system32\drivers\TDSSmhxt.sys
c:\windows\system32\hOXyFfii.ini
c:\windows\system32\hOXyFfii.ini2
c:\windows\system32\mcrh.tmp
c:\windows\system32\msssc.dll
c:\windows\system32\pwxvmvcx.ini
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSfxwp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\xcvmvxwp.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TDSSserv.sys
-------\Legacy_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 )))))))))))))))))))))))))))))))
.

2009-01-04 16:14 . 2009-01-04 16:15 <DIR> d-------- c:\program files\Unlocker
2009-01-04 08:46 . 2009-01-04 08:46 <DIR> d-------- c:\documents and settings\Milos\Application Data\TransRender
2009-01-04 08:46 . 2009-01-04 08:46 <DIR> d-------- c:\documents and settings\Milos\Application Data\Temporary
2009-01-04 08:46 . 2009-01-04 08:46 <DIR> d-------- c:\documents and settings\Milos\Application Data\Samsung
2009-01-04 08:46 . 2009-01-04 08:46 <DIR> d-------- c:\documents and settings\Milos\Application Data\ConvertTemp
2009-01-04 08:43 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2009-01-04 08:41 . 2006-07-24 16:05 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2009-01-04 08:37 . 2009-01-04 08:42 <DIR> d-------- c:\windows\system32\Samsung_USB_Drivers
2009-01-04 08:37 . 2009-01-04 08:37 <DIR> d-------- c:\program files\Samsung
2009-01-04 08:37 . 2005-08-30 17:59 94,000 --a------ c:\windows\system32\drivers\ss_mdm.sys
2009-01-04 08:37 . 2005-08-30 17:57 58,320 --a------ c:\windows\system32\drivers\ss_bus.sys
2009-01-04 08:37 . 2005-08-30 17:58 8,304 --a------ c:\windows\system32\drivers\ss_mdfl.sys
2009-01-04 08:37 . 2005-08-30 17:58 6,144 --a------ c:\windows\system32\drivers\ss_cmnt.sys
2009-01-04 08:37 . 2005-08-30 17:58 6,144 --a------ c:\windows\system32\drivers\ss_cm.sys
2009-01-04 08:37 . 2005-08-30 17:57 5,808 --a------ c:\windows\system32\drivers\ss_whnt.sys
2009-01-04 08:37 . 2005-08-30 17:57 5,808 --a------ c:\windows\system32\drivers\ss_wh.sys
2009-01-04 08:37 . 2005-08-28 20:51 766 --a------ c:\windows\system32\Uninstall.ico
2009-01-03 18:57 . 2009-01-04 11:05 <DIR> d-------- c:\program files\Trend Micro
2008-12-28 19:15 . 2008-12-28 19:15 <DIR> d-------- c:\documents and settings\Administrator
2008-12-28 19:15 . 2008-12-28 19:15 45,056 --a------ c:\windows\system32\geBtTJBS.dll
2008-12-28 17:32 . 2008-12-28 17:36 0 --a------ c:\windows\system32\drivers\107d9969.sys
2008-12-28 17:06 . 2008-12-28 17:06 45,056 --a------ c:\windows\system32\iifeeDuS.dll
2008-12-28 16:26 . 2008-12-28 17:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-12-28 16:03 . 2008-12-28 16:03 <DIR> d-------- c:\program files\Oracle
2008-12-28 16:03 . 2007-09-24 10:57 774,144 --a------ c:\windows\cis_parser.dll
2008-12-28 16:03 . 2003-05-08 14:35 45,153 --a------ c:\windows\system32\plugincpl13113.cpl
2008-12-28 16:03 . 2003-06-05 16:30 36,864 --a------ c:\windows\svrpr.ocx
2008-12-28 16:03 . 2003-06-28 13:11 28,672 --a------ c:\windows\get_username.dll
2008-12-28 15:59 . 2003-05-01 13:26 5,220 -ra------ c:\windows\system32\drivers\CVirtA.sys
2008-12-28 15:55 . 2008-12-28 15:55 <DIR> d-------- c:\program files\Common Files\Deterministic Networks
2008-12-28 15:55 . 2008-12-28 15:55 <DIR> d-------- c:\program files\Cisco Systems
2008-12-28 15:55 . 2002-10-17 14:22 138,916 --a------ c:\windows\system32\drivers\dne2000.sys
2008-12-28 15:55 . 2002-10-17 14:22 114,000 --a------ c:\windows\system32\dneinobj.dll
2008-12-22 20:21 . 2008-12-22 20:21 <DIR> d-------- C:\The.Wackness[2008]DvDrip-aXXo
2008-12-20 20:31 . 2008-12-21 11:45 <DIR> d-------- C:\Matrix Reloaded
2008-12-13 18:39 . 2008-12-13 18:39 <DIR> d-------- c:\windows\Funnsystems

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 16:30 --------- d-----w c:\documents and settings\Milos\Application Data\Skype
2009-01-04 16:30 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-01-04 16:04 3,108 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-01-04 16:04 286,752 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-01-04 07:41 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-04 07:36 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-04 07:21 --------- d-----w c:\documents and settings\Milos\Application Data\skypePM
2009-01-03 17:22 98,304 ----a-w c:\windows\DUMP5f85.tmp
2009-01-03 17:20 98,304 ----a-w c:\windows\DUMP608e.tmp
2009-01-03 17:18 98,304 ----a-w c:\windows\DUMP5cb7.tmp
2009-01-02 20:54 98,304 ----a-w c:\windows\DUMP5cb6.tmp
2009-01-02 20:52 98,304 ----a-w c:\windows\DUMP6198.tmp
2009-01-02 12:33 98,304 ----a-w c:\windows\DUMP5ef8.tmp
2008-12-31 19:23 98,304 ----a-w c:\windows\DUMP6050.tmp
2008-12-28 16:23 15,848 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-28 16:23 1,756,192 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-28 00:44 --------- d-----w c:\documents and settings\Milos\Application Data\uTorrent
2008-12-03 21:18 --------- d-----w c:\program files\Common Files\xing shared
2008-12-03 21:18 --------- d-----w c:\program files\Common Files\Real
2008-12-03 21:17 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-12-03 21:17 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-12-03 21:17 --------- d-----w c:\program files\Real
2008-11-29 14:10 --------- d-----w c:\program files\PC Wizard 2008
2008-11-24 16:26 --------- d-----w c:\program files\Common Files\Adobe
2008-11-20 21:37 98,304 ----a-w c:\windows\DUMP4ac4.tmp
2008-11-15 17:25 --------- d-----w c:\program files\Gigatron Konfygurator
2008-11-12 18:42 --------- d-----w c:\documents and settings\All Users\Application Data\RapidSolution
2008-11-12 18:30 --------- d-----w c:\program files\RapidSolution
2008-11-12 17:31 --------- d-----w c:\documents and settings\Milos\Application Data\Apple Computer
2008-11-12 17:29 --------- d-----w c:\program files\QuickTime
2008-11-12 17:29 --------- d-----w c:\program files\Common Files\Apple
2008-11-12 17:29 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-12 17:28 --------- d-----w c:\program files\Apple Software Update
2008-11-12 17:28 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-11-08 16:23 --------- d-----w c:\program files\BearShare Applications
2008-11-07 18:03 --------- d-----w c:\program files\Easy DVD Player
2008-10-25 13:50 737,280 ----a-w c:\windows\iun6002.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-29 21755688]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-03 185872]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
VPN Client.lnk - c:\windows\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico [2008-12-28 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R0 viasraid;viasraid;c:\windows\system32\DRIVERS\viasraid.sys [2008-10-25 77312]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S1 107d9969;107d9969;c:\windows\system32\drivers\107d9969.sys [2008-12-28 0]
S1 81797175;81797175;c:\windows\system32\drivers\81797175.sys []
.
Contents of the 'Scheduled Tasks' folder

2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-01-04 c:\windows\Tasks\ksmznspn.job
- c:\windows\system32\rundll32.exe [2008-04-14 05:42]
.
- - - - ORPHANS REMOVED - - - -

BHO-{3EBE8C0D-CC7C-4931-A787-75F98CDCDD4E} - c:\windows\system32\iifFyXOh.dll
BHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\byXOiFUK.dll
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\byXOiFUK.dll
Notify-byXOiFUK - byXOiFUK.dll
MSConfigStartUp-DLD - c:\program files\Download Direct\DLD.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.bearshare.com/intl/
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

O16 -: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF}
FF - ProfilePath - c:\documents and settings\Milos\Application Data\Mozilla\Firefox\Profiles\zyu4zcbk.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit13113.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-04 17:30:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-01-04 17:33:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-04 16:32:48

Pre-Run: 1,228,873,728 bytes free
Post-Run: 1,315,565,568 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

195

Dopuna: 04 Jan 2009 20:01

Sa zadnjeg linka sam skinuo CF i pobrisao je neke file-ove i posle toga sam uspeo da instaliram Malwarebytes i pokrenuo ga i ocistio jos 14 filova i sada sam pustio i KIS da ceslja da vidimo da li ce naci nesto kada.Kada zavrsi KIS postavicu HJ log pa da vidite samo da li je cist.Hvala na pomoci.

Dopuna: 04 Jan 2009 21:46

"Milos" - 2009-01-04 21:35:17 Service Pack 3
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Milos\Desktop\"


((((((((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 ))))))))))))))))))))))))))))))))))


2009-01-04 21:37 4,224 --a------ C:\WINDOWS\system32\drivers\beep.sys
2009-01-04 17:34 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-01-04 17:34 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2009-01-04 17:34 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-04 17:01 98,816 --a------ C:\WINDOWS\sed.exe
2009-01-04 17:01 89,504 --a------ C:\WINDOWS\fdsv.exe
2009-01-04 17:01 80,412 --a------ C:\WINDOWS\grep.exe
2009-01-04 17:01 68,096 --a------ C:\WINDOWS\zip.exe
2009-01-04 17:01 49,152 --a------ C:\WINDOWS\VFIND.exe
2009-01-04 17:01 28,672 --a------ C:\WINDOWS\NIRCMD.exe
2009-01-04 17:01 212,480 --a------ C:\WINDOWS\SWXCACLS.exe
2009-01-04 17:01 161,792 --a------ C:\WINDOWS\SWREG.exe
2009-01-04 17:01 136,704 --a------ C:\WINDOWS\SWSC.exe
2009-01-04 08:46 <DIR> d-------- C:\DOCUME~1\Milos\APPLIC~1\TransRender
2009-01-04 08:46 <DIR> d-------- C:\DOCUME~1\Milos\APPLIC~1\Temporary
2009-01-04 08:46 <DIR> d-------- C:\DOCUME~1\Milos\APPLIC~1\Samsung
2009-01-04 08:46 <DIR> d-------- C:\DOCUME~1\Milos\APPLIC~1\ConvertTemp
2009-01-04 08:43 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2009-01-04 08:41 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2009-01-04 08:37 94,000 --a------ C:\WINDOWS\system32\drivers\ss_mdm.sys
2009-01-04 08:37 8,304 --a------ C:\WINDOWS\system32\drivers\ss_mdfl.sys
2009-01-04 08:37 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cmnt.sys
2009-01-04 08:37 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cm.sys
2009-01-04 08:37 58,320 --a------ C:\WINDOWS\system32\drivers\ss_bus.sys
2009-01-04 08:37 5,808 --a------ C:\WINDOWS\system32\drivers\ss_whnt.sys
2009-01-04 08:37 5,808 --a------ C:\WINDOWS\system32\drivers\ss_wh.sys
2009-01-04 08:37 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2009-01-04 08:37 <DIR> d-------- C:\Program Files\Samsung
2009-01-03 18:57 <DIR> d-------- C:\Program Files\Trend Micro
2008-12-28 19:17 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\WinRAR
2008-12-28 19:15 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2008-12-28 19:15 <DIR> d--hs---- C:\WINDOWS\CSC
2008-12-28 17:32 0 --a------ C:\WINDOWS\system32\drivers\107d9969.sys
2008-12-28 16:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ESET
2008-12-28 16:03 774,144 --a------ C:\WINDOWS\cis_parser.dll
2008-12-28 16:03 28,672 --a------ C:\WINDOWS\get_username.dll
2008-12-28 16:03 <DIR> d-------- C:\Program Files\Oracle
2008-12-28 15:59 5,220 -ra------ C:\WINDOWS\system32\drivers\CVirtA.sys
2008-12-28 15:55 138,916 --a------ C:\WINDOWS\system32\drivers\dne2000.sys
2008-12-28 15:55 114,000 --a------ C:\WINDOWS\system32\dneinobj.dll
2008-12-28 15:55 <DIR> d-------- C:\Program Files\Common Files\Deterministic Networks
2008-12-28 15:55 <DIR> d-------- C:\Program Files\Cisco Systems
2008-12-22 20:21 <DIR> d-------- C:\The.Wackness[2008]DvDrip-aXXo
2008-12-20 20:31 <DIR> d-------- C:\Matrix Reloaded
2008-12-13 18:39 <DIR> d-------- C:\WINDOWS\Funnsystems


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2009-01-04 19:48:54 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\Skype
2009-01-04 17:14:32 1,744 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2009-01-04 07:41:29 -------- d--h--w C:\Program Files\InstallShield Installation Information
2009-01-04 07:36:45 -------- d-----w C:\Program Files\Common Files\InstallShield
2009-01-04 07:21:46 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\skypePM
2008-12-28 00:44:39 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\uTorrent
2008-12-03 21:19:44 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\Real
2008-12-03 21:18:41 -------- d-----w C:\Program Files\Common Files\xing shared
2008-12-03 21:18:30 -------- d-----w C:\Program Files\Common Files\Real
2008-12-03 21:17:57 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-12-03 21:17:57 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-12-03 21:17:57 -------- d-----w C:\Program Files\Real
2008-11-29 14:11:14 1,632 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2008-11-29 14:10:35 -------- d-----w C:\Program Files\PC Wizard 2008
2008-11-29 12:47:52 -------- d-----w C:\Program Files\Messenger
2008-11-29 12:12:51 -------- d-----w C:\Program Files\Movie Maker
2008-11-29 12:09:55 -------- d-----w C:\Program Files\Windows NT
2008-11-15 17:25:45 -------- d-----w C:\Program Files\Gigatron Konfygurator
2008-11-12 18:30:53 -------- d-----w C:\Program Files\RapidSolution
2008-11-12 17:31:11 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\Apple Computer
2008-11-12 17:29:44 -------- d-----w C:\Program Files\QuickTime
2008-11-12 17:29:12 -------- d-----w C:\Program Files\Common Files\Apple
2008-11-12 17:28:22 -------- d-----w C:\Program Files\Apple Software Update
2008-11-08 16:23:27 -------- d-----w C:\Program Files\BearShare Applications
2008-11-07 18:03:26 -------- d-----w C:\Program Files\Easy DVD Player
2008-10-25 14:35:54 56 ---ha-w C:\WINDOWS\system32\ezsidmv.dat
2008-10-25 14:19:46 0 ----a-w C:\WINDOWS\nsreg.dat
2008-10-25 13:50:32 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-10-25 13:19:39 0 --sha-r C:\MSDOS.SYS
2008-10-25 13:19:39 0 --sha-r C:\IO.SYS
2008-10-25 13:19:39 0 ----a-w C:\CONFIG.SYS
2008-10-25 13:19:39 0 ----a-w C:\AUTOEXEC.BAT
2008-10-25 13:15:02 21,640 ----a-w C:\WINDOWS\system32\emptyregdb.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{3049C3E9-B461-4BC5-8870-4C09146192CA}=C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-12-03 22:18]
{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll [2008-10-25 15:57]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 07:57]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 17:21]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 15:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 01:04]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-12-03 22:17]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 18:19]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-09-29 16:57]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 05:42]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
%SystemRoot%\System32\dimsntfy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
napagent


Contents of the 'Scheduled Tasks' folder
2008-12-27 12:05:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2009-01-04 17:00:00 C:\WINDOWS\tasks\ksmznspn.job

********************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, gmer.net
Rootkit scan 2009-01-04 21:37:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2009-01-04 21:38:56
C:\ComboFix-quarantined-files.txt ... 2009-01-04 21:38
C:\ComboFix2.txt ... 2009-01-04 17:33

--- E O F ---









Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:40:39 PM, on 1/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Milos\Desktop\bla\ola.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.bearshare.com/intl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4268 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

A, sto volim kad ljudi traze pomoc, pa onda rade na svoju ruku.

I jos pola pobrisu, pola ne, pa onda ja sve iz pocetka da gledam.

Ma, super. Bebee Dol


Daj mi MBAM log i Kaspersky log.

Ko je trenutno na forumu
 

Ukupno su 907 korisnika na forumu :: 26 registrovanih, 5 sakrivenih i 876 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Ben Roj, bojank, cikadeda, DragoslavS, ILGromovnik, Istman, ivicasimo, Lazarus, m0nstrum_, Misirac, moldway, Ne doznajem se u oružje, nemkea71, Parker, royst33, saputnik plavetnila, slonic_tonic, sombrero, SR-3m, Srki94, Srle993, tubular, vaso1, Vlad000, wizzardone, šumar bk2