Gamad

1

Gamad

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Zakacio sam neku gamad i ne mogu da je skinem nikako i ne pusta me da instaliram Malwarebytes,pa evo ga log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:56 PM, on 1/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.bearshare.com/intl/
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe (file missing)
O9 - Extra 'Tools' menuitem: &Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4028 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8454
  • Gde živiš: Novi Beograd

Potrebno je da ime programa HijackThis.exe promenis u neko drugo ime, onda skeniras i postavis mi log.

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:20 AM, on 1/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\bla\bla.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.bearshare.com/intl/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\byXOiFUK.dll
O2 - BHO: (no name) - {84AB57A5-6DF1-49C4-B2C5-F3C1DB89E9DC} - C:\WINDOWS\system32\iifFyXOh.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe (file missing)
O9 - Extra 'Tools' menuitem: &Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O20 - Winlogon Notify: byXOiFUK - C:\WINDOWS\SYSTEM32\byXOiFUK.dll
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4713 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8454
  • Gde živiš: Novi Beograd

* Klikni desnim tasterom na Kaspersky ikonicu ( ) u donjem, desnom uglu ekrana i izaberi Pause Protection.
* U prozoru koji se otvori, izaberi By User Request.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.

----------------------------

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Ni sa jedne adrese ne mogu da skinem ComboFix.

Dopuna: 04 Jan 2009 13:30

Evo sada sam skinuo i ne mogu da ga pokrenem.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8454
  • Gde živiš: Novi Beograd

Jesi iskljucio Antivirus?

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Jesam i nece da se pokrene.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8454
  • Gde živiš: Novi Beograd

Ajde probaj ovako,

ponovo iskljuci Antivirus i skini ga sa sledeceg linka:

http://amf.mycity.rs/programs/mirrored/C-F.exe

pa probaj da skeniras.

offline
  • Pridružio: 03 Nov 2008
  • Poruke: 73

Skenirao sam i pobrisa neke file-ove.


ComboFix 08-12-31.01 - Milos 2009-01-04 17:05:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.294 [GMT 1:00]
Running from: c:\documents and settings\Milos\Desktop\C-F.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated)
FW: Kaspersky Internet Security *enabled*

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\crypts.dll
c:\windows\system32\drivers\TDSSmhxt.sys
c:\windows\system32\hOXyFfii.ini
c:\windows\system32\hOXyFfii.ini2
c:\windows\system32\mcrh.tmp
c:\windows\system32\msssc.dll
c:\windows\system32\pwxvmvcx.ini
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSfxwp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\xcvmvxwp.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TDSSserv.sys
-------\Legacy_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 )))))))))))))))))))))))))))))))
.

2009-01-04 16:14 . 2009-01-04 16:15 <DIR> d-------- c:\program files\Unlocker
2009-01-04 08:46 . 2009-01-04 08:46 <DIR> d-------- c:\documents and settings\Milos\Application Data\TransRender
2009-01-04 08:46 . 2009-01-04 08:46 <DIR> d-------- c:\documents and settings\Milos\Application Data\Temporary
2009-01-04 08:46 . 2009-01-04 08:46 <DIR> d-------- c:\documents and settings\Milos\Application Data\Samsung
2009-01-04 08:46 . 2009-01-04 08:46 <DIR> d-------- c:\documents and settings\Milos\Application Data\ConvertTemp
2009-01-04 08:43 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2009-01-04 08:41 . 2006-07-24 16:05 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2009-01-04 08:37 . 2009-01-04 08:42 <DIR> d-------- c:\windows\system32\Samsung_USB_Drivers
2009-01-04 08:37 . 2009-01-04 08:37 <DIR> d-------- c:\program files\Samsung
2009-01-04 08:37 . 2005-08-30 17:59 94,000 --a------ c:\windows\system32\drivers\ss_mdm.sys
2009-01-04 08:37 . 2005-08-30 17:57 58,320 --a------ c:\windows\system32\drivers\ss_bus.sys
2009-01-04 08:37 . 2005-08-30 17:58 8,304 --a------ c:\windows\system32\drivers\ss_mdfl.sys
2009-01-04 08:37 . 2005-08-30 17:58 6,144 --a------ c:\windows\system32\drivers\ss_cmnt.sys
2009-01-04 08:37 . 2005-08-30 17:58 6,144 --a------ c:\windows\system32\drivers\ss_cm.sys
2009-01-04 08:37 . 2005-08-30 17:57 5,808 --a------ c:\windows\system32\drivers\ss_whnt.sys
2009-01-04 08:37 . 2005-08-30 17:57 5,808 --a------ c:\windows\system32\drivers\ss_wh.sys
2009-01-04 08:37 . 2005-08-28 20:51 766 --a------ c:\windows\system32\Uninstall.ico
2009-01-03 18:57 . 2009-01-04 11:05 <DIR> d-------- c:\program files\Trend Micro
2008-12-28 19:15 . 2008-12-28 19:15 <DIR> d-------- c:\documents and settings\Administrator
2008-12-28 19:15 . 2008-12-28 19:15 45,056 --a------ c:\windows\system32\geBtTJBS.dll
2008-12-28 17:32 . 2008-12-28 17:36 0 --a------ c:\windows\system32\drivers\107d9969.sys
2008-12-28 17:06 . 2008-12-28 17:06 45,056 --a------ c:\windows\system32\iifeeDuS.dll
2008-12-28 16:26 . 2008-12-28 17:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-12-28 16:03 . 2008-12-28 16:03 <DIR> d-------- c:\program files\Oracle
2008-12-28 16:03 . 2007-09-24 10:57 774,144 --a------ c:\windows\cis_parser.dll
2008-12-28 16:03 . 2003-05-08 14:35 45,153 --a------ c:\windows\system32\plugincpl13113.cpl
2008-12-28 16:03 . 2003-06-05 16:30 36,864 --a------ c:\windows\svrpr.ocx
2008-12-28 16:03 . 2003-06-28 13:11 28,672 --a------ c:\windows\get_username.dll
2008-12-28 15:59 . 2003-05-01 13:26 5,220 -ra------ c:\windows\system32\drivers\CVirtA.sys
2008-12-28 15:55 . 2008-12-28 15:55 <DIR> d-------- c:\program files\Common Files\Deterministic Networks
2008-12-28 15:55 . 2008-12-28 15:55 <DIR> d-------- c:\program files\Cisco Systems
2008-12-28 15:55 . 2002-10-17 14:22 138,916 --a------ c:\windows\system32\drivers\dne2000.sys
2008-12-28 15:55 . 2002-10-17 14:22 114,000 --a------ c:\windows\system32\dneinobj.dll
2008-12-22 20:21 . 2008-12-22 20:21 <DIR> d-------- C:\The.Wackness[2008]DvDrip-aXXo
2008-12-20 20:31 . 2008-12-21 11:45 <DIR> d-------- C:\Matrix Reloaded
2008-12-13 18:39 . 2008-12-13 18:39 <DIR> d-------- c:\windows\Funnsystems

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 16:30 --------- d-----w c:\documents and settings\Milos\Application Data\Skype
2009-01-04 16:30 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-01-04 16:04 3,108 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-01-04 16:04 286,752 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-01-04 07:41 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-04 07:36 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-04 07:21 --------- d-----w c:\documents and settings\Milos\Application Data\skypePM
2009-01-03 17:22 98,304 ----a-w c:\windows\DUMP5f85.tmp
2009-01-03 17:20 98,304 ----a-w c:\windows\DUMP608e.tmp
2009-01-03 17:18 98,304 ----a-w c:\windows\DUMP5cb7.tmp
2009-01-02 20:54 98,304 ----a-w c:\windows\DUMP5cb6.tmp
2009-01-02 20:52 98,304 ----a-w c:\windows\DUMP6198.tmp
2009-01-02 12:33 98,304 ----a-w c:\windows\DUMP5ef8.tmp
2008-12-31 19:23 98,304 ----a-w c:\windows\DUMP6050.tmp
2008-12-28 16:23 15,848 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-28 16:23 1,756,192 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-28 00:44 --------- d-----w c:\documents and settings\Milos\Application Data\uTorrent
2008-12-03 21:18 --------- d-----w c:\program files\Common Files\xing shared
2008-12-03 21:18 --------- d-----w c:\program files\Common Files\Real
2008-12-03 21:17 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-12-03 21:17 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-12-03 21:17 --------- d-----w c:\program files\Real
2008-11-29 14:10 --------- d-----w c:\program files\PC Wizard 2008
2008-11-24 16:26 --------- d-----w c:\program files\Common Files\Adobe
2008-11-20 21:37 98,304 ----a-w c:\windows\DUMP4ac4.tmp
2008-11-15 17:25 --------- d-----w c:\program files\Gigatron Konfygurator
2008-11-12 18:42 --------- d-----w c:\documents and settings\All Users\Application Data\RapidSolution
2008-11-12 18:30 --------- d-----w c:\program files\RapidSolution
2008-11-12 17:31 --------- d-----w c:\documents and settings\Milos\Application Data\Apple Computer
2008-11-12 17:29 --------- d-----w c:\program files\QuickTime
2008-11-12 17:29 --------- d-----w c:\program files\Common Files\Apple
2008-11-12 17:29 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-12 17:28 --------- d-----w c:\program files\Apple Software Update
2008-11-12 17:28 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-11-08 16:23 --------- d-----w c:\program files\BearShare Applications
2008-11-07 18:03 --------- d-----w c:\program files\Easy DVD Player
2008-10-25 13:50 737,280 ----a-w c:\windows\iun6002.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-29 21755688]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-03 185872]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
VPN Client.lnk - c:\windows\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico [2008-12-28 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R0 viasraid;viasraid;c:\windows\system32\DRIVERS\viasraid.sys [2008-10-25 77312]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S1 107d9969;107d9969;c:\windows\system32\drivers\107d9969.sys [2008-12-28 0]
S1 81797175;81797175;c:\windows\system32\drivers\81797175.sys []
.
Contents of the 'Scheduled Tasks' folder

2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-01-04 c:\windows\Tasks\ksmznspn.job
- c:\windows\system32\rundll32.exe [2008-04-14 05:42]
.
- - - - ORPHANS REMOVED - - - -

BHO-{3EBE8C0D-CC7C-4931-A787-75F98CDCDD4E} - c:\windows\system32\iifFyXOh.dll
BHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\byXOiFUK.dll
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\byXOiFUK.dll
Notify-byXOiFUK - byXOiFUK.dll
MSConfigStartUp-DLD - c:\program files\Download Direct\DLD.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.bearshare.com/intl/
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

O16 -: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF}
FF - ProfilePath - c:\documents and settings\Milos\Application Data\Mozilla\Firefox\Profiles\zyu4zcbk.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit13113.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-04 17:30:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-01-04 17:33:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-04 16:32:48

Pre-Run: 1,228,873,728 bytes free
Post-Run: 1,315,565,568 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

195

Dopuna: 04 Jan 2009 20:01

Sa zadnjeg linka sam skinuo CF i pobrisao je neke file-ove i posle toga sam uspeo da instaliram Malwarebytes i pokrenuo ga i ocistio jos 14 filova i sada sam pustio i KIS da ceslja da vidimo da li ce naci nesto kada.Kada zavrsi KIS postavicu HJ log pa da vidite samo da li je cist.Hvala na pomoci.

Dopuna: 04 Jan 2009 21:46

"Milos" - 2009-01-04 21:35:17 Service Pack 3
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Milos\Desktop\"


((((((((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 ))))))))))))))))))))))))))))))))))


2009-01-04 21:37 4,224 --a------ C:\WINDOWS\system32\drivers\beep.sys
2009-01-04 17:34 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-01-04 17:34 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2009-01-04 17:34 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-04 17:01 98,816 --a------ C:\WINDOWS\sed.exe
2009-01-04 17:01 89,504 --a------ C:\WINDOWS\fdsv.exe
2009-01-04 17:01 80,412 --a------ C:\WINDOWS\grep.exe
2009-01-04 17:01 68,096 --a------ C:\WINDOWS\zip.exe
2009-01-04 17:01 49,152 --a------ C:\WINDOWS\VFIND.exe
2009-01-04 17:01 28,672 --a------ C:\WINDOWS\NIRCMD.exe
2009-01-04 17:01 212,480 --a------ C:\WINDOWS\SWXCACLS.exe
2009-01-04 17:01 161,792 --a------ C:\WINDOWS\SWREG.exe
2009-01-04 17:01 136,704 --a------ C:\WINDOWS\SWSC.exe
2009-01-04 08:46 <DIR> d-------- C:\DOCUME~1\Milos\APPLIC~1\TransRender
2009-01-04 08:46 <DIR> d-------- C:\DOCUME~1\Milos\APPLIC~1\Temporary
2009-01-04 08:46 <DIR> d-------- C:\DOCUME~1\Milos\APPLIC~1\Samsung
2009-01-04 08:46 <DIR> d-------- C:\DOCUME~1\Milos\APPLIC~1\ConvertTemp
2009-01-04 08:43 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2009-01-04 08:41 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2009-01-04 08:37 94,000 --a------ C:\WINDOWS\system32\drivers\ss_mdm.sys
2009-01-04 08:37 8,304 --a------ C:\WINDOWS\system32\drivers\ss_mdfl.sys
2009-01-04 08:37 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cmnt.sys
2009-01-04 08:37 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cm.sys
2009-01-04 08:37 58,320 --a------ C:\WINDOWS\system32\drivers\ss_bus.sys
2009-01-04 08:37 5,808 --a------ C:\WINDOWS\system32\drivers\ss_whnt.sys
2009-01-04 08:37 5,808 --a------ C:\WINDOWS\system32\drivers\ss_wh.sys
2009-01-04 08:37 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2009-01-04 08:37 <DIR> d-------- C:\Program Files\Samsung
2009-01-03 18:57 <DIR> d-------- C:\Program Files\Trend Micro
2008-12-28 19:17 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\WinRAR
2008-12-28 19:15 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2008-12-28 19:15 <DIR> d--hs---- C:\WINDOWS\CSC
2008-12-28 17:32 0 --a------ C:\WINDOWS\system32\drivers\107d9969.sys
2008-12-28 16:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ESET
2008-12-28 16:03 774,144 --a------ C:\WINDOWS\cis_parser.dll
2008-12-28 16:03 28,672 --a------ C:\WINDOWS\get_username.dll
2008-12-28 16:03 <DIR> d-------- C:\Program Files\Oracle
2008-12-28 15:59 5,220 -ra------ C:\WINDOWS\system32\drivers\CVirtA.sys
2008-12-28 15:55 138,916 --a------ C:\WINDOWS\system32\drivers\dne2000.sys
2008-12-28 15:55 114,000 --a------ C:\WINDOWS\system32\dneinobj.dll
2008-12-28 15:55 <DIR> d-------- C:\Program Files\Common Files\Deterministic Networks
2008-12-28 15:55 <DIR> d-------- C:\Program Files\Cisco Systems
2008-12-22 20:21 <DIR> d-------- C:\The.Wackness[2008]DvDrip-aXXo
2008-12-20 20:31 <DIR> d-------- C:\Matrix Reloaded
2008-12-13 18:39 <DIR> d-------- C:\WINDOWS\Funnsystems


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2009-01-04 19:48:54 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\Skype
2009-01-04 17:14:32 1,744 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2009-01-04 07:41:29 -------- d--h--w C:\Program Files\InstallShield Installation Information
2009-01-04 07:36:45 -------- d-----w C:\Program Files\Common Files\InstallShield
2009-01-04 07:21:46 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\skypePM
2008-12-28 00:44:39 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\uTorrent
2008-12-03 21:19:44 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\Real
2008-12-03 21:18:41 -------- d-----w C:\Program Files\Common Files\xing shared
2008-12-03 21:18:30 -------- d-----w C:\Program Files\Common Files\Real
2008-12-03 21:17:57 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-12-03 21:17:57 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-12-03 21:17:57 -------- d-----w C:\Program Files\Real
2008-11-29 14:11:14 1,632 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2008-11-29 14:10:35 -------- d-----w C:\Program Files\PC Wizard 2008
2008-11-29 12:47:52 -------- d-----w C:\Program Files\Messenger
2008-11-29 12:12:51 -------- d-----w C:\Program Files\Movie Maker
2008-11-29 12:09:55 -------- d-----w C:\Program Files\Windows NT
2008-11-15 17:25:45 -------- d-----w C:\Program Files\Gigatron Konfygurator
2008-11-12 18:30:53 -------- d-----w C:\Program Files\RapidSolution
2008-11-12 17:31:11 -------- d-----w C:\DOCUME~1\Milos\APPLIC~1\Apple Computer
2008-11-12 17:29:44 -------- d-----w C:\Program Files\QuickTime
2008-11-12 17:29:12 -------- d-----w C:\Program Files\Common Files\Apple
2008-11-12 17:28:22 -------- d-----w C:\Program Files\Apple Software Update
2008-11-08 16:23:27 -------- d-----w C:\Program Files\BearShare Applications
2008-11-07 18:03:26 -------- d-----w C:\Program Files\Easy DVD Player
2008-10-25 14:35:54 56 ---ha-w C:\WINDOWS\system32\ezsidmv.dat
2008-10-25 14:19:46 0 ----a-w C:\WINDOWS\nsreg.dat
2008-10-25 13:50:32 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-10-25 13:19:39 0 --sha-r C:\MSDOS.SYS
2008-10-25 13:19:39 0 --sha-r C:\IO.SYS
2008-10-25 13:19:39 0 ----a-w C:\CONFIG.SYS
2008-10-25 13:19:39 0 ----a-w C:\AUTOEXEC.BAT
2008-10-25 13:15:02 21,640 ----a-w C:\WINDOWS\system32\emptyregdb.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{3049C3E9-B461-4BC5-8870-4C09146192CA}=C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-12-03 22:18]
{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll [2008-10-25 15:57]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 07:57]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 17:21]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 15:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 01:04]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-12-03 22:17]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 18:19]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-09-29 16:57]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 05:42]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
%SystemRoot%\System32\dimsntfy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
napagent


Contents of the 'Scheduled Tasks' folder
2008-12-27 12:05:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2009-01-04 17:00:00 C:\WINDOWS\tasks\ksmznspn.job

********************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, gmer.net
Rootkit scan 2009-01-04 21:37:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2009-01-04 21:38:56
C:\ComboFix-quarantined-files.txt ... 2009-01-04 21:38
C:\ComboFix2.txt ... 2009-01-04 17:33

--- E O F ---









Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:40:39 PM, on 1/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Milos\Desktop\bla\ola.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = search.bearshare.com/intl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CAFECAFE-0013-0001-0013-ABCDEFABCDEF} (JInitiator 1.3.1.13) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4268 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8454
  • Gde živiš: Novi Beograd

A, sto volim kad ljudi traze pomoc, pa onda rade na svoju ruku.

I jos pola pobrisu, pola ne, pa onda ja sve iz pocetka da gledam.

Ma, super. Bebee Dol


Daj mi MBAM log i Kaspersky log.

Ko je trenutno na forumu
 

Ukupno su 835 korisnika na forumu :: 39 registrovanih, 5 sakrivenih i 791 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, _Sale, A.R.Chafee.Jr., alkatraz080, amaterSRB, ArmyBoss, Atomski čoban, babaroga, dac, dragon986, girici2, HrcAk47, Krusarac, kuntalo, kybonacci, lukac, mane123, MB120mm, mercedesamg, miodrag, MrNo, nenad81, NoOneEver Dreams, pein, Recce, robertino, sakota79, Sirius, Steeeefan, tomigun, Toni, trajkoni018, vlad the impaler, Vlad000, vladas87, voja64, yamato, zajcev1, zexoni