Gube mi se ikone na desktopu!! pomoc...

3

Gube mi se ikone na desktopu!! pomoc...

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

opet sam u igri.....zavrsio sam s onim norton removal tool-om , resetirao komp(makar mi to puno oduzima na vremenu,pa bih te zamolio da mi kazes di nije potrebno resetirati sustav) i otvorila mi se ova stranica --> service1.symantec.com/support/tsgeninfo.nsf.....d=Symantec

sta dalje??

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Aj, sad da probamo u Admin modu da uradis sledece:

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

ComboFix 09-03-10.03 - vinko 2009-03-11 17:40:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.1023.740 [GMT 1:00]
Running from: c:\documents and settings\vinko\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *On-access scanning disabled* (Updated)
FW: Bitdefender Firewall *disabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - svchost.exe: deleted 32768 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\vinko\Application Data\.#
c:\documents and settings\vinko\Application Data\.#\MBX@74C@3F3790.###
c:\documents and settings\vinko\Application Data\.#\MBX@74C@3F37A0.###
c:\documents and settings\vinko\Application Data\addon.dat
c:\documents and settings\vinko\Application Data\FunWebProducts
c:\documents and settings\vinko\Application Data\FunWebProducts\Data\vinko\avatar.dat
c:\documents and settings\vinko\Local Settings\Application Data\baidu
c:\documents and settings\vinko\ravmonlog
C:\lsass.exe
c:\program files\FBrowserAdvisor
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Images\00356714.urr
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\OneStepSearch
c:\windows\17PHolmes1889.exe
c:\windows\BMf7e87a09.txt
c:\windows\BMf7e87a09.xml
c:\windows\cookies.ini
c:\windows\f49f4daa.dat
c:\windows\pskt.ini
c:\windows\system32\abbyymsh.ini
c:\windows\system32\abpvvrjv.ini
c:\windows\system32\adwvlgrs.ini
c:\windows\system32\agebuaoc.ini
c:\windows\system32\ahfkgmbf.ini
c:\windows\system32\ajhscine.ini
c:\windows\system32\akwoxjgw.ini
c:\windows\system32\alhvfdkt.ini
c:\windows\system32\apqbxihj.ini
c:\windows\system32\aqokqhmb.ini
c:\windows\system32\auhtsmdj.ini
c:\windows\system32\awjhitmv.ini
c:\windows\system32\awtuVnlk.dll
c:\windows\system32\axpjiwca.ini
c:\windows\system32\ayctjkiv.ini
c:\windows\system32\bbrjdnbe.ini
c:\windows\system32\bbxgjmmy.ini
c:\windows\system32\bdkmqugi.ini
c:\windows\system32\bebpqllw.ini
c:\windows\system32\bputwwsp.ini
c:\windows\system32\bsvuvdpq.ini
c:\windows\system32\bsyirdrp.ini
c:\windows\system32\bxetvljo.ini
c:\windows\system32\cbemhxll.ini
c:\windows\system32\Cdgfgfii.ini
c:\windows\system32\Cdgfgfii.ini2
c:\windows\system32\cinmghaw.ini
c:\windows\system32\cjjslbsw.ini
c:\windows\system32\cmnaltve.ini
c:\windows\system32\cmuoukta.ini
c:\windows\system32\cmyjhrgj.ini
c:\windows\system32\cppchwjd.ini
c:\windows\system32\crypts.dll
c:\windows\system32\cxstakjn.ini
c:\windows\system32\daotmyog.ini
c:\windows\system32\dbxcixsn.ini
c:\windows\system32\dewjhbnt.ini
c:\windows\system32\dfqfvlyq.ini
c:\windows\system32\dlsfhijm.ini
c:\windows\system32\dNWxayay.ini
c:\windows\system32\dNWxayay.ini2
c:\windows\system32\dordxsyb.ini
c:\windows\system32\dteiwvjj.ini
c:\windows\system32\dtrfysvl.ini
c:\windows\system32\dulifpoi.ini
c:\windows\system32\dwplblvr.ini
c:\windows\system32\dyktpfse.ini
c:\windows\system32\echgcqfe.ini
c:\windows\system32\ednvbvig.ini
c:\windows\system32\eeoyckok.ini
c:\windows\system32\efcaXnnl.dll
c:\windows\system32\EOpWDfii.ini
c:\windows\system32\EOpWDfii.ini2
c:\windows\system32\ewnbvcoi.ini
c:\windows\system32\eyrtbrkj.ini
c:\windows\system32\faceikyt.ini
c:\windows\system32\fbwsslgs.ini
c:\windows\system32\fcmpnoxy.ini
c:\windows\system32\fdnjasbt.ini
c:\windows\system32\ferqfxtj.ini
c:\windows\system32\ffiovtxy.ini
c:\windows\system32\ffyhwiwi.ini
c:\windows\system32\fiRuEfhk.ini
c:\windows\system32\fiRuEfhk.ini2
c:\windows\system32\fjebpwus.ini
c:\windows\system32\fkksmbvj.ini
c:\windows\system32\fnokgots.ini
c:\windows\system32\fpsrgefx.ini
c:\windows\system32\fqikmder.ini
c:\windows\system32\fsvorqwm.ini
c:\windows\system32\gbwwxlsr.ini
c:\windows\system32\ggalmqtt.ini
c:\windows\system32\gjxifjwc.ini
c:\windows\system32\gkydxphr.ini
c:\windows\system32\gnuscrbd.ini
c:\windows\system32\gpaiondv.ini
c:\windows\system32\gpldqajc.ini
c:\windows\system32\gprnaaap.ini
c:\windows\system32\gptcpwby.ini
c:\windows\system32\gqdcncqf.ini
c:\windows\system32\gtqbupsl.ini
c:\windows\system32\gwdibsxn.ini
c:\windows\system32\gyytukai.ini
c:\windows\system32\habbfgbw.ini
c:\windows\system32\hagwcvmf.ini
c:\windows\system32\haqkealm.ini
c:\windows\system32\hbugriok.ini
c:\windows\system32\hfocbhcu.ini
c:\windows\system32\hkpxbxwb.ini
c:\windows\system32\hnayvngc.ini
c:\windows\system32\hnrnscco.ini
c:\windows\system32\hpiyepbt.ini
c:\windows\system32\hrpjrvgj.ini
c:\windows\system32\hykecnwr.ini
c:\windows\system32\iexp_log.txt
c:\windows\system32\iifgfgdC.dll
c:\windows\system32\inopyioo.ini
c:\windows\system32\isjnvrti.ini
c:\windows\system32\itpyxwkb.ini
c:\windows\system32\ixodpaeq.ini
c:\windows\system32\ixometcu.ini
c:\windows\system32\jdfdchgb.ini
c:\windows\system32\jenkqirb.ini
c:\windows\system32\jfrjwkfr.ini
c:\windows\system32\jjdpxryv.ini
c:\windows\system32\jklnqlga.ini
c:\windows\system32\jlmqwtyg.ini
c:\windows\system32\jlweimvn.ini
c:\windows\system32\jmdjmljr.ini
c:\windows\system32\jmxmljcy.ini
c:\windows\system32\jnhxtjdq.ini
c:\windows\system32\jsgwhusu.ini
c:\windows\system32\kapfglav.ini
c:\windows\system32\kaxtipda.ini
c:\windows\system32\kbjkvstb.ini
c:\windows\system32\kdjbmnoh.ini
c:\windows\system32\kespqbcx.ini
c:\windows\system32\kfrjpmcv.ini
c:\windows\system32\kggqvrnh.ini
c:\windows\system32\khfEuRif.dll
c:\windows\system32\kjftfssx.ini
c:\windows\system32\kjpawvwe.ini
c:\windows\system32\klnVutwa.ini
c:\windows\system32\klnVutwa.ini2
c:\windows\system32\lcnrtwvo.ini
c:\windows\system32\liotdnmg.ini
c:\windows\system32\lmllm.bak1
c:\windows\system32\lmllm.bak2
c:\windows\system32\lmllm.ini
c:\windows\system32\lmllm.ini2
c:\windows\system32\lmllm.tmp2
c:\windows\system32\lngpqaej.ini
c:\windows\system32\lnnXacfe.ini
c:\windows\system32\lnnXacfe.ini2
c:\windows\system32\lophofin.ini
c:\windows\system32\lraafxal.ini
c:\windows\system32\lrjgdlvx.ini
c:\windows\system32\lrnfhtoq.ini
c:\windows\system32\lsckfmbg.ini
c:\windows\system32\ludncyog.ini
c:\windows\system32\lvtocvag.ini
c:\windows\system32\mcaljbmk.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\mdiootqq.ini
c:\windows\system32\meihaqre.ini
c:\windows\system32\mhiyoljf.ini
c:\windows\system32\mhwfyybu.ini
c:\windows\system32\mnlwummt.ini
c:\windows\system32\mtsispmw.ini
c:\windows\system32\mwfsiybd.ini
c:\windows\system32\nbfkemrp.ini
c:\windows\system32\nbwvyfan.ini
c:\windows\system32\nckjxrtx.ini
c:\windows\system32\nfghgkac.ini
c:\windows\system32\niyivpxq.ini
c:\windows\system32\nohwcprg.ini
c:\windows\system32\NooqYcfe.ini
c:\windows\system32\NooqYcfe.ini2
c:\windows\system32\nukoduib.ini
c:\windows\system32\nwetbuii.ini
c:\windows\system32\njwduers.ini
c:\windows\system32\oavokbge.ini
c:\windows\system32\obsxficy.ini
c:\windows\system32\oisllapf.ini
c:\windows\system32\ojjfovvj.ini
c:\windows\system32\ojlvbgsd.ini
c:\windows\system32\osmrhyos.ini
c:\windows\system32\oticqlgr.ini
c:\windows\system32\oubovrei.ini
c:\windows\system32\ougrvqoj.ini
c:\windows\system32\ovdexebh.ini
c:\windows\system32\ovybliti.ini
c:\windows\system32\owdevdkj.ini
c:\windows\system32\oxqofffa.ini
c:\windows\system32\oyrjotog.ini
c:\windows\system32\paiwcnai.ini
c:\windows\system32\pcqhnxcb.ini
c:\windows\system32\pefydpdj.ini
c:\windows\system32\peqfqqry.ini
c:\windows\system32\pigfujha.ini
c:\windows\system32\pjnpicmg.ini
c:\windows\system32\pklcnmgi.ini
c:\windows\system32\pmavjuma.ini
c:\windows\system32\ppbcvxmg.ini
c:\windows\system32\puchfurq.ini
c:\windows\system32\pugpcxyp.ini
c:\windows\system32\puhcspos.ini
c:\windows\system32\qfhlkhcs.ini
c:\windows\system32\qgioholv.ini
c:\windows\system32\qiogcgeo.ini
c:\windows\system32\qmiucpdj.ini
c:\windows\system32\qpkqgwlp.ini
c:\windows\system32\qubcxpnt.ini
c:\windows\system32\qxgxwknq.ini
c:\windows\system32\qxvtwwln.ini
c:\windows\system32\qynsmeao.ini
c:\windows\system32\qyrbocnf.ini
c:\windows\system32\rcxjfrom.ini
c:\windows\system32\rhouxljl.ini
c:\windows\system32\rijsyhnc.ini
c:\windows\system32\rrdhwmku.ini
c:\windows\system32\rsoexfgs.ini
c:\windows\system32\ruvshjej.ini
c:\windows\system32\ryxqlslt.ini
c:\windows\system32\ryydyosm.ini
c:\windows\system32\sbdcdbhc.ini
c:\windows\system32\sdpuxtlh.ini
c:\windows\system32\sfcrtmal.ini
c:\windows\system32\sglkdxfi.ini
c:\windows\system32\shquppsk.ini
c:\windows\system32\sjaiyqgn.ini
c:\windows\system32\srwbsynp.ini
c:\windows\system32\stftfaus.ini
c:\windows\system32\suevjghu.ini
c:\windows\system32\svsbxxpp.ini
c:\windows\system32\swdcenat.ini
c:\windows\system32\sxklrkks.ini
c:\windows\system32\tgpxehis.ini
c:\windows\system32\tmlmftpr.ini
c:\windows\system32\tmnsssax.ini
c:\windows\system32\tmurveks.ini
c:\windows\system32\torjsynp.ini
c:\windows\system32\tqhmagvk.ini
c:\windows\system32\tqnvcphb.ini
c:\windows\system32\tutpvfrl.ini
c:\windows\system32\tuvWnMGy.dll
c:\windows\system32\tvftbgut.ini
c:\windows\system32\tvwdmncl.ini
c:\windows\system32\twubxntn.ini
c:\windows\system32\ubbobxiy.ini
c:\windows\system32\uepeoset.ini
c:\windows\system32\ugcceqvw.ini
c:\windows\system32\uikyactj.ini
c:\windows\system32\ukgpuhxk.ini
c:\windows\system32\uldntpdj.ini
c:\windows\system32\unnapuai.ini
c:\windows\system32\uotienml.ini
c:\windows\system32\upwscktt.ini
c:\windows\system32\urnppkfa.ini
c:\windows\system32\urxjifle.ini
c:\windows\system32\usuluqgt.ini
c:\windows\system32\utjmcelx.ini
c:\windows\system32\utldsknu.ini
c:\windows\system32\uwajaoyu.ini
c:\windows\system32\uynpnqkl.ini
c:\windows\system32\uyxxekxr.ini
c:\windows\system32\vaiarfgq.ini
c:\windows\system32\vcqioofl.ini
c:\windows\system32\vgcycpug.ini
c:\windows\system32\vgtnxjdl.ini
c:\windows\system32\vgxhfhft.ini
c:\windows\system32\viruvhli.ini
c:\windows\system32\vlckniwj.ini
c:\windows\system32\voxwnjqy.ini
c:\windows\system32\vrarumrc.ini
c:\windows\system32\vrpqiemm.ini
c:\windows\system32\vtbyvjre.ini
c:\windows\system32\vuvibuhs.ini
c:\windows\system32\vypleuwg.ini
c:\windows\system32\vyrtpxqw.ini
c:\windows\system32\wcveeprr.ini
c:\windows\system32\weinbpjy.ini
c:\windows\system32\wgiduftr.ini
c:\windows\system32\whmeawjs.ini
c:\windows\system32\whtltosf.ini
c:\windows\system32\wpohwbtq.ini
c:\windows\system32\wpxfktgl.ini
c:\windows\system32\wxrrkwax.ini
c:\windows\system32\xcjlbkfl.ini
c:\windows\system32\xeqqmbup.ini
c:\windows\system32\xfhuwumy.ini
c:\windows\system32\xkccvnnx.ini
c:\windows\system32\xqhwidhq.ini
c:\windows\system32\xscrceyq.ini
c:\windows\system32\xvshcmka.ini
c:\windows\system32\xvsjxwiw.ini
c:\windows\system32\xvygfjvd.ini
c:\windows\system32\yayaxWNd.dll
c:\windows\system32\ydficcjk.ini
c:\windows\system32\yiiuousj.ini
c:\windows\system32\yrwkdosg.ini
c:\windows\system32\yvgtfnkr.ini
c:\windows\system32\yxbdtnoi.ini
c:\windows\system32\yyqsvswd.ini
c:\windows\Tasks\ggvmdutx.job
c:\windows\wr.txt

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BDGUARD
-------\Legacy_DOMAINSERVICE
-------\Legacy_fci
-------\Legacy_ONESTEP_SEARCH_SERVICE
-------\Legacy_SECONDARY_LOGON_(SECLOGON)_
-------\Service_DomainService
-------\Service_FCI


((((((((((((((((((((((((( Files Created from 2009-02-11 to 2009-03-11 )))))))))))))))))))))))))))))))
.

2009-03-11 16:45 . 2009-03-11 16:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-11 03:38 . 2009-03-11 03:38 <DIR> d-------- c:\documents and settings\aaaaaa\Application Data\Media Player Classic
2009-03-11 03:38 . 2009-03-11 03:38 <DIR> d-------- c:\documents and settings\aaaaaa\Application Data\GRETECH
2009-03-11 03:38 . 2009-03-11 03:38 <DIR> d-------- c:\documents and settings\aaaaaa\Application Data\DivX
2009-03-10 22:16 . 2009-03-10 22:16 <DIR> d-------- c:\documents and settings\aaaaaa\DoctorWeb
2009-03-10 21:52 . 2009-03-10 21:52 <DIR> d-------- c:\documents and settings\Administrator
2009-03-10 21:16 . 2009-03-10 21:17 <DIR> d-------- C:\32788R22FWJFW.0.tmp
2009-03-10 20:16 . 2009-03-10 22:59 <DIR> d-------- c:\documents and settings\aaaaaa\Contacts
2009-03-10 16:19 . 2009-03-10 16:19 <DIR> d-------- c:\documents and settings\new puki\Contacts
2009-03-10 16:16 . 2009-03-10 16:16 <DIR> d-------- c:\documents and settings\new puki\Application Data\MEGAUPLOADTOOLBAR
2009-03-10 15:06 . 2009-03-10 15:06 <DIR> d-------- c:\windows\system32\NtmsData
2009-03-10 14:20 . 2009-03-10 14:20 <DIR> d-------- c:\documents and settings\aaaaaa\Application Data\MEGAUPLOADTOOLBAR
2009-03-10 14:16 . 2009-03-10 22:16 <DIR> d-------- c:\documents and settings\aaaaaa
2009-03-10 12:33 . 2009-03-10 16:19 <DIR> d-------- c:\documents and settings\new puki
2009-03-09 17:59 . 2009-03-09 17:59 <DIR> d-------- c:\program files\Alwil Software
2009-03-09 17:22 . 2009-03-09 17:43 <DIR> d-------- c:\program files\ElcomSoft
2009-03-09 17:22 . 2009-03-09 17:24 789 --a------ c:\windows\ARPR.INI
2009-03-09 17:21 . 2009-03-09 17:21 1,313,104 --a------ c:\documents and settings\vinko\Application Data\setup.exe
2009-03-09 16:36 . 2009-03-10 12:23 19,968 --------- C:\xcgugvn.exe
2009-03-09 16:20 . 2009-03-11 18:15 100,846 --a------ c:\windows\system32\drivers\86ba83b4.sys
2009-03-09 16:09 . 2009-03-09 16:09 <DIR> d-------- c:\program files\Appwalk.com Technologies Canada
2009-03-09 15:39 . 2009-03-09 15:39 <DIR> d-------- c:\program files\MSBuild
2009-03-09 15:38 . 2009-03-09 15:57 <DIR> d-------- c:\windows\system32\XPSViewer
2009-03-09 15:38 . 2009-03-09 15:38 <DIR> d-------- c:\program files\Reference Assemblies
2009-03-09 15:37 . 2009-03-09 15:37 <DIR> d-------- c:\program files\MSXML 6.0
2009-03-09 15:37 . 2006-06-29 13:07 14,048 --a------ c:\windows\system32\spmsg2.dll
2009-03-09 15:32 . 2009-03-11 18:15 115,310 --a------ c:\windows\system32\drivers\d42368c4.sys
2009-03-09 15:32 . 2009-03-09 16:20 33,280 --a------ c:\windows\vgjacakh1.tmp
2009-03-09 15:32 . 2009-03-09 16:28 33,280 --a------ c:\windows\vgjacakh.dll
2009-03-09 14:55 . 2009-03-09 14:56 <DIR> d-------- c:\windows\system32\Adobe
2009-03-06 16:48 . 2009-03-06 16:48 <DIR> d-------- c:\program files\DVDVideoSoft
2009-03-06 16:48 . 2009-03-06 16:49 <DIR> d-------- c:\program files\Common Files\DVDVideoSoft
2009-03-06 16:29 . 2009-03-06 16:29 <DIR> d-------- C:\Mp3 Output
2009-03-06 16:29 . 2007-02-25 15:36 383,238 --a------ c:\windows\system32\libmp3lame-0.dll
2009-03-05 14:21 . 2009-03-05 14:21 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{017115B5-2F29-4ECD-8FD6-329F9F107B86}
2009-02-28 20:44 . 2009-02-28 20:44 <DIR> d-------- c:\program files\ImTOO
2009-02-28 17:01 . 2009-02-28 17:01 <DIR> d-------- C:\movies
2009-02-28 17:00 . 2009-02-28 17:01 67 --a------ c:\windows\Power Video Converter.INI
2009-02-28 16:59 . 2009-02-28 16:59 <DIR> d-------- c:\program files\Power Video Converter
2009-02-28 16:26 . 2004-08-04 00:56 159,232 --a------ c:\windows\system32\ptpusd.dll
2009-02-28 16:26 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-02-28 16:26 . 2004-08-03 22:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-02-28 16:26 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2009-02-17 18:47 . 2009-02-17 18:47 <DIR> d-------- c:\program files\Plus!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-11 16:28 --------- d-----w c:\documents and settings\vinko\Application Data\Deepnet Explorer
2009-03-11 15:54 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-11 15:53 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-10 21:44 --------- d-----w c:\documents and settings\All Users\Application Data\eq rect plus copy
2009-03-10 15:16 --------- d-----w c:\program files\Kaspersky Lab
2009-03-10 15:16 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-10 09:55 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-09 15:05 --------- d-----w c:\program files\DNA
2009-03-09 15:05 --------- d-----w c:\documents and settings\vinko\Application Data\DNA
2009-03-07 01:33 --------- d-----w c:\documents and settings\vinko\Application Data\FrostWire
2009-03-06 16:30 --------- d-----w c:\program files\Deepnet Explorer
2009-03-06 15:48 --------- d-----w c:\program files\Smallvideosoft
2009-02-28 19:45 --------- d-----w c:\documents and settings\vinko\Application Data\ImTOO Software Studio
2009-02-28 15:57 --------- d-----w c:\documents and settings\vinko\Application Data\Any Video Converter
2009-02-10 23:36 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-09 15:41 --------- d-----w c:\program files\SweetIM
2009-02-09 15:41 --------- d-----w c:\documents and settings\All Users\Application Data\SweetIM
2009-02-07 02:12 --------- d-----w c:\program files\Reganam
2009-02-04 13:27 --------- d-----w c:\program files\FrostWire
2009-02-03 09:25 --------- d-----w c:\documents and settings\vinko\Application Data\DAPE
2009-02-01 12:58 --------- d-----w c:\documents and settings\vinko\Application Data\uTorrent
2009-01-30 16:44 --------- d-----w c:\program files\Common Files\Adobe
2009-01-30 11:21 --------- d-----w c:\program files\LunaPlayer
2009-01-29 11:25 --------- d-----w c:\program files\uTorrent
2009-01-27 13:19 --------- d-----w c:\program files\VideoLAN
2009-01-27 13:18 --------- d-----w c:\program files\Graboid
2009-01-26 14:48 --------- d-----w c:\documents and settings\admin.VINKO.000\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 14:38 --------- d-----w c:\documents and settings\admin.VINKO.000\Application Data\MozillaControl
2009-01-26 14:36 --------- d-----w c:\documents and settings\admin.VINKO.000\Application Data\grim htm
2009-01-26 14:09 --------- d-----w c:\documents and settings\admin.VINKO\Application Data\vlc
2009-01-26 13:53 --------- d-----w c:\documents and settings\admin.VINKO\Application Data\MozillaControl
2009-01-26 13:52 --------- d-----w c:\documents and settings\admin.VINKO\Application Data\grim htm
2009-01-26 13:51 --------- d-----w c:\documents and settings\admin.VINKO\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 13:29 --------- d-----w c:\documents and settings\admin\Application Data\grim htm
2009-01-26 13:27 --------- d-----w c:\documents and settings\admin\Application Data\Deepnet Explorer
2009-01-26 13:27 --------- d-----w c:\documents and settings\admin\Application Data\DAPE
2009-01-26 13:25 --------- d-----w c:\documents and settings\admin\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 13:10 --------- d-----w c:\documents and settings\pukšec\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 12:41 --------- d-----w c:\documents and settings\Guest\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 11:19 --------- d-----w c:\documents and settings\All Users\Application Data\Launcher
2009-01-25 23:11 --------- d-----w c:\documents and settings\All Users\Application Data\Graboid Inc
2009-01-25 10:43 --------- d-----w c:\program files\Java
2009-01-24 22:20 --------- d-----w c:\program files\Microsoft Works
2009-01-24 22:17 --------- d-----w c:\program files\Microsoft.NET
2009-01-24 11:28 --------- d-----w c:\program files\Word Recovery Toolbox
2009-01-23 10:18 --------- d-----w c:\documents and settings\vinko\Application Data\BitTorrent
2009-01-23 10:05 --------- d-----w c:\program files\BitTorrent
2009-01-23 10:04 --------- d-----w c:\program files\AskBarDis
2009-01-16 22:37 --------- d-----w c:\program files\Realtek Sound Manager
2009-01-16 22:37 --------- d-----w c:\program files\Realtek AC97
2009-01-16 22:37 --------- d-----w c:\program files\AvRack
2009-01-16 16:05 --------- d-----w c:\program files\Lavalys
2009-01-15 16:30 --------- d-----w c:\program files\Motorama
2009-01-15 16:19 --------- d-----w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-01-15 11:09 --------- d-----w c:\program files\Folder Lock 6
2009-01-15 10:45 --------- d-----w c:\program files\FDN
2009-01-15 10:12 --------- d-----w c:\program files\Folder Lock
2009-01-13 20:22 --------- d-----w c:\documents and settings\vinko\Application Data\MSN6
2009-01-12 20:44 --------- d-----w c:\documents and settings\vinko\Application Data\Skype
2008-12-27 20:23 16,896 --sh--r c:\program files\captcha5.dll
2007-01-25 02:52 65,536 ----a-w c:\program files\Common Files\NMSAccessU.exe
2008-07-17 17:46 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-07-17 17:46 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-07-17 17:46 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-07-17 17:46 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-07-17 17:46 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{db9d7a78-a76c-4bf2-97c6-258925ee1542}"= "c:\program files\Reganam\tbReg1.dll" [2009-03-02 1883672]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-10-08 173368]

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 17:24 325000 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]
2009-03-02 17:56 1883672 --a------ c:\program files\Reganam\tbReg1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 12:22 1172792 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{db9d7a78-a76c-4bf2-97c6-258925ee1542}"= "c:\program files\Reganam\tbReg1.dll" [2009-03-02 1883672]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{DB9D7A78-A76C-4BF2-97C6-258925EE1542}"= "c:\program files\Reganam\tbReg1.dll" [2009-03-02 1883672]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"userfaultcheck"="c:\windows\system32\dumprep 0 -u" [X]
"8367"="C:\xcgugvn.exe" [2009-03-10 19968]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-19 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\program files\TGTSoft\StyleXP\Logon\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.3iv2"= c:\progra~1\K-LITE~1\codecs\3IVXVF~1.DLL
"VIDC.VP60"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP61"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP62"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP70"= c:\progra~1\K-LITE~1\codecs\vp7vfw.dll
"VIDC.VP31"= c:\progra~1\K-LITE~1\codecs\vp31vfw.dll
"VIDC.FFDS"= c:\progra~1\K-LITE~1\ffdshow\ff_vfw.dll
"msacm.l3fhg"= c:\progra~1\K-LITE~1\codecs\l3codecp.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C *\0aswBoot.exe /M:2bed903d

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winfi24.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Avant Browser\\avant.exe"=
"c:\\Program Files\\Deepnet Explorer\\Deepnet.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\OFFICE\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=

R0 tihlayxx;tihlayxx;c:\windows\system32\drivers\tihlayxx.sys [2001-08-23 23424]
S0 Winfi24;Winfi24;c:\windows\system32\Drivers\Winfi24.sys --> c:\windows\system32\Drivers\Winfi24.sys [?]
S2 JBouvoaqcji;JBouvoaqcji;c:\windows\System32\svchost.exe -k netsvcs [2001-08-23 14336]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2001-08-23 3584]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [2009-01-16 23152]
S3 usb2vcom;DKU-5 Connectivity Adapter Cable;c:\windows\system32\drivers\usb2vcom.sys [2008-06-02 28704]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
JBouvoaqcji

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-03-11 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

2009-03-11 c:\windows\Tasks\User_Feed_Synchronization-{2D66750F-BFE6-4E89-AC8F-9B92B15CD980}.job
- c:\windows\system32\msfeedssync.exe [2009-01-15 02:01]
.
- - - - ORPHANS REMOVED - - - -

BHO-{00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
BHO-{05C56B17-5A02-4F18-A9D2-E4CF4A8F6645} - (no file)
BHO-{07B18EA1-A523-4961-B6BB-170DE4475CCA} - (no file)
BHO-{100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)
BHO-{13807400-768B-4791-A5A6-1A95462E8944} - c:\documents and settings\vinko\Local Settings\Temporary Internet Files\Content.IE5\R3DRZVKQ\silent.dll[1].bak
BHO-{1D0B1B2F-4D44-48DC-AE5A-F4BBBAE2A83F} - (no file)
BHO-{2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
BHO-{3A6D079E-4234-4CFC-9180-DB4462ABEF9A} - (no file)
BHO-{508ad95d-5798-4eda-a928-a72a921fb43f} - c:\windows\system32\khfEuRif.dll
BHO-{5953598F-83BD-44A0-8F5F-38912B03AA05} - (no file)
BHO-{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\tuvWnMGy.dll
BHO-{8DE62E58-BA3D-40D3-AD5A-2BA5FD6E5A90} - c:\windows\system32\iifDWpOE.dll
BHO-{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - (no file)
BHO-{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - (no file)
BHO-{E9BD0828-1FD9-410C-A50F-43EBE65D310F} - (no file)
BHO-{F1E96EDC-E0C8-BE98-1F15-C29DBED83B53} - (no file)
Toolbar-{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
Toolbar-{07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
WebBrowser-{89FDCC4B-8D91-49B0-81A6-18BCFF582735} - (no file)
WebBrowser-{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
ShellExecuteHooks-{E9BD0828-1FD9-410C-A50F-43EBE65D310F} - (no file)
ShellExecuteHooks-{1D0B1B2F-4D44-48DC-AE5A-F4BBBAE2A83F} - (no file)
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\tuvWnMGy.dll
Notify-cbXOfdcA - (no file)
Notify-urqnmmk - (no file)
Notify-winjpq32 - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hr/
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: Ispuni obrasce - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Prilagodi izbornik - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: RF Alatna traka - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Spremi obrasce - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{C5428486-50A0-4a02-9D20-520B59A9F9B2} - {C9CCBB35-D123-4a31-AFFC-9B2933132116} -
IE: {{C5428486-50A0-4a02-9D20-520B59A9F9B3} - {A16AD1E9-F69A-45af-9462-B1C286708842} -
TCP: {AE8C66A4-2AB9-4342-96A4-93E9821D3E2B} = 195.29.149.196,195.29.149.197
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0.0.15-3.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-11 18:14:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\docume~1\vinko\LOCALS~1\Temp\PrePict.htm 770 bytes
c:\docume~1\vinko\LOCALS~1\Temp\quadra000 0 bytes
c:\docume~1\vinko\LOCALS~1\Temp\rip10.exe 72704 bytes executable
c:\docume~1\vinko\LOCALS~1\Temp\seneka000 0 bytes
c:\docume~1\vinko\LOCALS~1\Temp\setup.log 3374 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Sym4.tmp 186770 bytes
c:\docume~1\vinko\LOCALS~1\Temp\SymNRT 3-11-2009 16h44m53s.log 15361632 bytes
c:\docume~1\vinko\LOCALS~1\Temp\tdss000 0 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\0[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\1061030468_02[1].swf 23756 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\1[2].gif 364 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\local-fm[1].gif 1668 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\logo[1].gif 10154 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\logo[1].png 8788 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mail[1].txt 5508 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mail[2] 108 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mail[4] 113709 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\google-earth[1].gif 9771 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_bul_3[1].gif 50 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_mdl_bg[1].gif 157 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_nav_02[1].gif 350 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_search[1].gif 54 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_top_bg[1].jpg 11087 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\header_topline[1].png 47988 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\hig[1].css 31041 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\hig[2].css 31041 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\shareaza-turbo-accelerator[1].jpg 8781 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\shared[1].css 5364 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\shared[1].js 6902 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\show_ads[1].js 30022 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\sl[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\sma[1].png 728 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\camera[1] 14062 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\cat_10[1].jpg 644 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\cat_12[1].jpg 626 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\cat_17[1].jpg 884 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\p[1].gif 42 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\button1-bm[1].gif 637 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\desktop.ini 67 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\dnserrordiagoff_webOC[2] 6766 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\dnserror[1] 5947 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\download-kaspersky-virus-removal-tool[1].html 33142 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\downloads[1].txt 18323 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\ErrorPageTemplate[1] 2168 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\ES[2].gif 992 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\allPics[1].gif 58870 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\pfeil_zu[1].jpg 562 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\pixel-vfl73[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\javafunction[1].js 1253 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\K2ZO6CAUC8Z5LCAJ62BUDCAKW5ZXMCA1N7YU3CA2Y4FKICAFT5DDLCAG8JM9PCAYDDYDHCAOEG7QICALFZ2JICAO82AFOCAMQG1P4CA1CEXB4CAL05188CAZ7G3G0CAF83FOBCASOLWWZCA18BGD7CA69MI6YCA840FGVCAKRVVTP.txt 7611 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\Kaspersky-Anti-Virus[1].txt 34705 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\knights[1].gif 346 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\the-battle-for-wesnoth[1].gif 923 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tooltip-vfl56131[1].gif 531 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\top[1].gif 2289 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\nav_logo4[1].png 7121 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bearshare-turbo-accelerator[1].gif 1236 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\behavior[1].js 33954 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fl_logo_b[1].gif 890 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\folder_big[1].gif 612 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\folder_locked_big[1].gif 370 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\footer-croportal-icon[1].gif 347 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\footer_bg[1].jpg 13241 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\FormBG[1].gif 413 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\ga[1].js 22759 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStatCALQBB2D.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[1].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[2].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[3].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[4].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[5].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[6].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[7].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[8].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[9].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\2817[1].png 9836 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\300299803[1].jpg 27189 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\3[1].gif 238 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\star1[1].gif 147 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\starbw[1].gif 137 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\UAHelp_Classic[1].css 339 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\urchin[1].js 22645 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\users32[1] 2238 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\VeriSignSeal_klein[1].gif 1856 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\search 425 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\searchBG[1].gif 555 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\search[10] 495 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\search[11] 429 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\search_bg_1[1].jpg 16925 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\launchhelp[1].js 2274 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\brand[1].txt 616 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\btnSmall[1].gif 699 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\favicon[4].ico 7078 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\favicon[5].ico 1150 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fdn[1].js 1475 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fdn[2].js 810 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\createpage[1] 705 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\croportal-logo[1].png 15397 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\dap[1].js 13249 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\rc[1].png 121 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\real-temp[1].gif 1747 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\stil2[1].css 7132 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\styles[2].css 5810 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\st[2] 4397 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\728x90_croportal_ver_6[1].swf 44563 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\aaa_lft[1].gif 571 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_30_tage_ohne_zusatz_en[2].jpg 13787 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\ProfilePhoto_UserTileSmall,Thumbnail[1].jpg 875 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\new_tabs_pas_bg[1].gif 152 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\new_tabs_sel[1].gif 426 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\nusrmgr[1] 1760 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\nusrmgr[2] 8119 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\n_2[1].gif 350 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\n_7[1].gif 344 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\n_9[1].gif 554 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mail[6] 122136 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStatCAAKGYM8.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_30_tage_ohne_zusatz_en[1].jpg 13787 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\hover[1].js 509 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\http_404_webOC[1] 6381 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\icon_friend[1].gif 1035 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\icon_members[1].gif 1067 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\icon_search[1].gif 1131 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mojtv[1].gif 1513 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\motion_log[1].php 0 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\whosonline[1].gif 842 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\widget02[1].css 4337 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bad[1].txt 394 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\6158[1].htm 2513 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\trazi[1].gif 1560 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tv-listing-bottom[1].gif 235 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tv-raspored[1].txt 78003 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\repltx[2].aspx 25 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\rpics[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\switch2_ua[1].gif 3136 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tab-hover-left[1].gif 1455 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tab-link-left[1].gif 1455 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\table_header_gradient[1].png 132 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\taskbullet[1] 995 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bind[1].txt 661 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\borderBottom[1].gif 191 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bottomCorner[1].gif 125 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStatCA5TBIVG.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStatCA8AFUMV.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\test_domain[1].js 54 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\www-core-vfl82316[1].css 69302 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\chg_common[2] 2666 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\cleardot[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\demoreg[2].html 45789 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mainpage[1] 3291 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\main[1].js 3347 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\menu07[1].js 12604 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\safari[1].jpg 3753 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\script[1].aspx 2072 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bgLeft[1].gif 364 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\portable-miranda-im[1].gif 1170 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_2_paybycall[1].jpg 3187 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_2_paybycall[2].jpg 3187 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_2_reseller[1].jpg 2934 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_2_reseller[2].jpg 2934 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfoicon_fileactivity[1].gif 594 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfoicon_website[1].gif 589 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo[1].css 7552 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo_aliasimage[1].gif 3247 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo_fileactivityimage[1].gif 2706 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo_headerbg[1].gif 264 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo_malwareimage[1].gif 3336 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\file_linktothispage_cro[1].gif 501 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\file_tab1[1].gif 727 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\button-login[1].gif 2004 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0000000001_000000000000000163039[1].jpg 5453 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0000000001_000000000000000301317[1].jpg 9756 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0[1].gif 57934 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0[1].jpg 94182 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0[2].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\swfobject[1].js 6880 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\s_code_50105[1].js 22039 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\newplaytoy[1].htm 3773 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\newzfind_com[1].htm 88202 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\n_1[1].gif 341 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\n_3[1].gif 348 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ads[11].txt 6869 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\301[2].gif 2683 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\vghd_768x245_youporn[1].swf 36299 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\search[10] 497 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\search[2].txt 10422 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\download-kaspersky-anti-virus[1].html 33138 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\downloadit[1].gif 506 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\down[1] 3414 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\preisschild_365_tage_ohne_zusatz_en[1].jpg 15649 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\preisschild_3_leer[1].jpg 1290 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\preisschild_3_leer[2].jpg 1290 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\k1VYXjgOIbk[1].js 20472 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\Kasp[2].rar 39230252 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\kis_09_eng_90_120[1].png 19936 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\tv-listing-top[1].gif 271 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfoicon_arrow[1].gif 298 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfoicon_registry[1].gif 587 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_behaviourimage[1].gif 3738 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_headerimageblue[1].gif 2899 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_logo[1].gif 3086 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_networkimage[1].gif 3621 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_vendorimage[1].gif 3207 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g[2].png 193 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g_06_btm_line[1].gif 1393 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g_06_nav_01_sel[1].gif 155 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g_06_nav_02[1].gif 350 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g_06_search[1].gif 54 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\sortArr[1].gif 57 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\button[1].gif 1405 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\bysoft-free-bmi-calculator[1].gif 1322 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_11[1].jpg 900 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_13[1].jpg 916 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_14[1].jpg 948 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_3[1].jpg 805 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_6[1].jpg 936 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ads.txt 6721 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ADSAdClient31[3].txt 5082 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ads[10].txt 4379 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\menu_header_1[1].gif 1352 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\menu_off[1].gif 356 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\miracles[1].gif 1387 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\links[1].htm 214 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\logo_small[1].gif 826 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\UAHelp[1] 597 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\users[1] 25214 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\vbulletin_md5[1].js 9661 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\vbulletin_md5[2].js 5464 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\icon_report[1].gif 585 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\9DI8NCA6DRL17CAF53RNBCA23EEULCAKPI5JRCAAZFMRJCAU2U8YACA2D7K1ACAKD8WB5CAAJM82QCA73R0RTCABQLEFDCABEAOGJCAUKVR9OCA70J3GJCAK2V75RCAZ4B0UMCAA16TY6CA8A5BFFCAK4ZB64CA8XT8H6CAIQ8EKN.txt 4678 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\abg-en-100c-000000[1].png 1006 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\abg-hr-100c-000000[1].png 951 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\AccountPage[1] 3379 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\accountpage[2] 1088 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\acct_common[2] 1505 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\AC_RunActiveContent[1].js 8321 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\e5_main[1].js 514 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\rslogo[1].gif 3913 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\PicturePage[1] 3243 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\picturepage[2] 6744 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\pinnacle-videospin[1].gif 1433 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\top[1].png 2470 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ChangePage[1] 1582 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cleardot[2].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\Common[1].js 3159 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\Common[2].js 3159 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cpwebvw[1] 3611 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\Default[1].aspx 7806 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\desktop.ini 67 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\divider-archive-to-footerlinks[1].png 2934 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\divider-copyright-top[1].png 2849 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\PlayToyStatCADZ0PZO.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\PlayToyStatCAOK8QIL.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\PlayToyStatCAWXBADG.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\preisschild_1_paypal[1].jpg 2853 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\2KFTNCAQC6UWSCABVYKG0CAUUI217CA4640UCCANZHX8ACA22QQMBCA0KWD8LCARB3Y2ZCA6Z76CACAEB9CDXCAM1JAX9CA5IPOI8CAJ5BW6TCAUE7ZJ4CA6BUK6DCA6KJI7UCAA4AT3ECAX7OAU1CAOLNCX6CAOXZQG0CAYXH2ZK.txt 11429 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\sizer-bg[1].gif 23925 bytes
c:\docume~1\vinko\L

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

mycity.rs/must-login.png

Dopuna: 11 Mar 2009 18:36

skužih.. Smile

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

OK.

Trebace mi dosta vremena dok sve pregledam i napisem sta da se brise.

Citamo se kasnije....

Ne brini, popravicemo.

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

ne steka mi zasad nista... ,svaka ti cast..

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\xcgugvn.exe
c:\windows\system32\drivers\86ba83b4.sys
c:\windows\system32\drivers\d42368c4.sys
c:\windows\vgjacakh1.tmp
c:\windows\vgjacakh.dll
c:\windows\system32\drivers\tihlayxx.sys
c:\windows\system32\Drivers\Winfi24.sys
c:\program files\captcha5.dll

Folder::
c:\documents and settings\All Users\Application Data\eq rect plus copy
c:\documents and settings\admin.VINKO.000\Application Data\grim htm
c:\documents and settings\admin.VINKO\Application Data\grim htm
c:\documents and settings\admin\Application Data\grim htm
c:\program files\grim htm

Driver::
tihlayxx
Winfi24
JBouvoaqcji
86ba83b4
d42368c4

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"8367"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winfi24.sys]

NetSvc::
JBouvoaqcji


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

mycity.rs/must-login.png

javlja i ovu gresku: C:\$Mft is corrupt and unreadable. please run the chkdsk utilly.
mislim da je tu i glavni problem jer meni nije mogao zavrsiti checkdisk na c disku zapeo je negdje na stage 2.. nisam siguran , ali morao sam rucno restartati os i odbiti checkdisk da bi mi se windows "normalno" pokrenuo .. neka greska ne ja c disku

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Preuzmi gmer.zip sa ovog linka i sačuvaj na Desktopu.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde ta dva fajla koja smo malopre snimili.

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

oprosti ali kako pokrenuti taj "autostart" tab ????

Ko je trenutno na forumu
 

Ukupno su 1294 korisnika na forumu :: 62 registrovanih, 7 sakrivenih i 1225 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, _Petar, Aleksandar Tomić, aramis s, Atomski čoban, Ben Roj, Bobrock1, botta, brundo65, BSD, comi_pfc, dane007, darkangel, delrey, Denaya, DPera, Dukelander, Excalibur13, flash12, gmlale, Istman, jukeboxer, kjkszpj, Koridor, Krusarac, kubura91, kunktator, kybonacci, Litostroton, ljuba, LUDI, Luka Blažević, Magistar78, Marko Marković, mačković, mercedesamg, MILICAT, Mixelotti, Nemanja.M, nemkea71, oldtimer, pein, raptorsi, repac, Romibrat, rovac, sasa87, Sirius, SR-3m, stegonosa, theNedjeljko, tubular, Viceroy, VJ, vladaa012, vladulns, vobo, voja64, wizzardone, wolf431, Wrangler, yufighter