Gube mi se ikone na desktopu!! pomoc...

3

Gube mi se ikone na desktopu!! pomoc...

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

opet sam u igri.....zavrsio sam s onim norton removal tool-om , resetirao komp(makar mi to puno oduzima na vremenu,pa bih te zamolio da mi kazes di nije potrebno resetirati sustav) i otvorila mi se ova stranica --> [Link mogu videti samo ulogovani korisnici]

sta dalje??



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8652
  • Gde živiš: Novi Beograd

Aj, sad da probamo u Admin modu da uradis sledece:

Skini ComboFix sa jedne od sledecih adresa na Desktop:
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.



offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

ComboFix 09-03-10.03 - vinko 2009-03-11 17:40:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.1023.740 [GMT 1:00]
Running from: c:\documents and settings\vinko\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *On-access scanning disabled* (Updated)
FW: Bitdefender Firewall *disabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - svchost.exe: deleted 32768 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\vinko\Application Data\.#
c:\documents and settings\vinko\Application Data\.#\MBX@74C@3F3790.###
c:\documents and settings\vinko\Application Data\.#\MBX@74C@3F37A0.###
c:\documents and settings\vinko\Application Data\addon.dat
c:\documents and settings\vinko\Application Data\FunWebProducts
c:\documents and settings\vinko\Application Data\FunWebProducts\Data\vinko\avatar.dat
c:\documents and settings\vinko\Local Settings\Application Data\baidu
c:\documents and settings\vinko\ravmonlog
C:\lsass.exe
c:\program files\FBrowserAdvisor
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Images\00356714.urr
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\OneStepSearch
c:\windows\17PHolmes1889.exe
c:\windows\BMf7e87a09.txt
c:\windows\BMf7e87a09.xml
c:\windows\cookies.ini
c:\windows\f49f4daa.dat
c:\windows\pskt.ini
c:\windows\system32\abbyymsh.ini
c:\windows\system32\abpvvrjv.ini
c:\windows\system32\adwvlgrs.ini
c:\windows\system32\agebuaoc.ini
c:\windows\system32\ahfkgmbf.ini
c:\windows\system32\ajhscine.ini
c:\windows\system32\akwoxjgw.ini
c:\windows\system32\alhvfdkt.ini
c:\windows\system32\apqbxihj.ini
c:\windows\system32\aqokqhmb.ini
c:\windows\system32\auhtsmdj.ini
c:\windows\system32\awjhitmv.ini
c:\windows\system32\awtuVnlk.dll
c:\windows\system32\axpjiwca.ini
c:\windows\system32\ayctjkiv.ini
c:\windows\system32\bbrjdnbe.ini
c:\windows\system32\bbxgjmmy.ini
c:\windows\system32\bdkmqugi.ini
c:\windows\system32\bebpqllw.ini
c:\windows\system32\bputwwsp.ini
c:\windows\system32\bsvuvdpq.ini
c:\windows\system32\bsyirdrp.ini
c:\windows\system32\bxetvljo.ini
c:\windows\system32\cbemhxll.ini
c:\windows\system32\Cdgfgfii.ini
c:\windows\system32\Cdgfgfii.ini2
c:\windows\system32\cinmghaw.ini
c:\windows\system32\cjjslbsw.ini
c:\windows\system32\cmnaltve.ini
c:\windows\system32\cmuoukta.ini
c:\windows\system32\cmyjhrgj.ini
c:\windows\system32\cppchwjd.ini
c:\windows\system32\crypts.dll
c:\windows\system32\cxstakjn.ini
c:\windows\system32\daotmyog.ini
c:\windows\system32\dbxcixsn.ini
c:\windows\system32\dewjhbnt.ini
c:\windows\system32\dfqfvlyq.ini
c:\windows\system32\dlsfhijm.ini
c:\windows\system32\dNWxayay.ini
c:\windows\system32\dNWxayay.ini2
c:\windows\system32\dordxsyb.ini
c:\windows\system32\dteiwvjj.ini
c:\windows\system32\dtrfysvl.ini
c:\windows\system32\dulifpoi.ini
c:\windows\system32\dwplblvr.ini
c:\windows\system32\dyktpfse.ini
c:\windows\system32\echgcqfe.ini
c:\windows\system32\ednvbvig.ini
c:\windows\system32\eeoyckok.ini
c:\windows\system32\efcaXnnl.dll
c:\windows\system32\EOpWDfii.ini
c:\windows\system32\EOpWDfii.ini2
c:\windows\system32\ewnbvcoi.ini
c:\windows\system32\eyrtbrkj.ini
c:\windows\system32\faceikyt.ini
c:\windows\system32\fbwsslgs.ini
c:\windows\system32\fcmpnoxy.ini
c:\windows\system32\fdnjasbt.ini
c:\windows\system32\ferqfxtj.ini
c:\windows\system32\ffiovtxy.ini
c:\windows\system32\ffyhwiwi.ini
c:\windows\system32\fiRuEfhk.ini
c:\windows\system32\fiRuEfhk.ini2
c:\windows\system32\fjebpwus.ini
c:\windows\system32\fkksmbvj.ini
c:\windows\system32\fnokgots.ini
c:\windows\system32\fpsrgefx.ini
c:\windows\system32\fqikmder.ini
c:\windows\system32\fsvorqwm.ini
c:\windows\system32\gbwwxlsr.ini
c:\windows\system32\ggalmqtt.ini
c:\windows\system32\gjxifjwc.ini
c:\windows\system32\gkydxphr.ini
c:\windows\system32\gnuscrbd.ini
c:\windows\system32\gpaiondv.ini
c:\windows\system32\gpldqajc.ini
c:\windows\system32\gprnaaap.ini
c:\windows\system32\gptcpwby.ini
c:\windows\system32\gqdcncqf.ini
c:\windows\system32\gtqbupsl.ini
c:\windows\system32\gwdibsxn.ini
c:\windows\system32\gyytukai.ini
c:\windows\system32\habbfgbw.ini
c:\windows\system32\hagwcvmf.ini
c:\windows\system32\haqkealm.ini
c:\windows\system32\hbugriok.ini
c:\windows\system32\hfocbhcu.ini
c:\windows\system32\hkpxbxwb.ini
c:\windows\system32\hnayvngc.ini
c:\windows\system32\hnrnscco.ini
c:\windows\system32\hpiyepbt.ini
c:\windows\system32\hrpjrvgj.ini
c:\windows\system32\hykecnwr.ini
c:\windows\system32\iexp_log.txt
c:\windows\system32\iifgfgdC.dll
c:\windows\system32\inopyioo.ini
c:\windows\system32\isjnvrti.ini
c:\windows\system32\itpyxwkb.ini
c:\windows\system32\ixodpaeq.ini
c:\windows\system32\ixometcu.ini
c:\windows\system32\jdfdchgb.ini
c:\windows\system32\jenkqirb.ini
c:\windows\system32\jfrjwkfr.ini
c:\windows\system32\jjdpxryv.ini
c:\windows\system32\jklnqlga.ini
c:\windows\system32\jlmqwtyg.ini
c:\windows\system32\jlweimvn.ini
c:\windows\system32\jmdjmljr.ini
c:\windows\system32\jmxmljcy.ini
c:\windows\system32\jnhxtjdq.ini
c:\windows\system32\jsgwhusu.ini
c:\windows\system32\kapfglav.ini
c:\windows\system32\kaxtipda.ini
c:\windows\system32\kbjkvstb.ini
c:\windows\system32\kdjbmnoh.ini
c:\windows\system32\kespqbcx.ini
c:\windows\system32\kfrjpmcv.ini
c:\windows\system32\kggqvrnh.ini
c:\windows\system32\khfEuRif.dll
c:\windows\system32\kjftfssx.ini
c:\windows\system32\kjpawvwe.ini
c:\windows\system32\klnVutwa.ini
c:\windows\system32\klnVutwa.ini2
c:\windows\system32\lcnrtwvo.ini
c:\windows\system32\liotdnmg.ini
c:\windows\system32\lmllm.bak1
c:\windows\system32\lmllm.bak2
c:\windows\system32\lmllm.ini
c:\windows\system32\lmllm.ini2
c:\windows\system32\lmllm.tmp2
c:\windows\system32\lngpqaej.ini
c:\windows\system32\lnnXacfe.ini
c:\windows\system32\lnnXacfe.ini2
c:\windows\system32\lophofin.ini
c:\windows\system32\lraafxal.ini
c:\windows\system32\lrjgdlvx.ini
c:\windows\system32\lrnfhtoq.ini
c:\windows\system32\lsckfmbg.ini
c:\windows\system32\ludncyog.ini
c:\windows\system32\lvtocvag.ini
c:\windows\system32\mcaljbmk.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\mdiootqq.ini
c:\windows\system32\meihaqre.ini
c:\windows\system32\mhiyoljf.ini
c:\windows\system32\mhwfyybu.ini
c:\windows\system32\mnlwummt.ini
c:\windows\system32\mtsispmw.ini
c:\windows\system32\mwfsiybd.ini
c:\windows\system32\nbfkemrp.ini
c:\windows\system32\nbwvyfan.ini
c:\windows\system32\nckjxrtx.ini
c:\windows\system32\nfghgkac.ini
c:\windows\system32\niyivpxq.ini
c:\windows\system32\nohwcprg.ini
c:\windows\system32\NooqYcfe.ini
c:\windows\system32\NooqYcfe.ini2
c:\windows\system32\nukoduib.ini
c:\windows\system32\nwetbuii.ini
c:\windows\system32\njwduers.ini
c:\windows\system32\oavokbge.ini
c:\windows\system32\obsxficy.ini
c:\windows\system32\oisllapf.ini
c:\windows\system32\ojjfovvj.ini
c:\windows\system32\ojlvbgsd.ini
c:\windows\system32\osmrhyos.ini
c:\windows\system32\oticqlgr.ini
c:\windows\system32\oubovrei.ini
c:\windows\system32\ougrvqoj.ini
c:\windows\system32\ovdexebh.ini
c:\windows\system32\ovybliti.ini
c:\windows\system32\owdevdkj.ini
c:\windows\system32\oxqofffa.ini
c:\windows\system32\oyrjotog.ini
c:\windows\system32\paiwcnai.ini
c:\windows\system32\pcqhnxcb.ini
c:\windows\system32\pefydpdj.ini
c:\windows\system32\peqfqqry.ini
c:\windows\system32\pigfujha.ini
c:\windows\system32\pjnpicmg.ini
c:\windows\system32\pklcnmgi.ini
c:\windows\system32\pmavjuma.ini
c:\windows\system32\ppbcvxmg.ini
c:\windows\system32\puchfurq.ini
c:\windows\system32\pugpcxyp.ini
c:\windows\system32\puhcspos.ini
c:\windows\system32\qfhlkhcs.ini
c:\windows\system32\qgioholv.ini
c:\windows\system32\qiogcgeo.ini
c:\windows\system32\qmiucpdj.ini
c:\windows\system32\qpkqgwlp.ini
c:\windows\system32\qubcxpnt.ini
c:\windows\system32\qxgxwknq.ini
c:\windows\system32\qxvtwwln.ini
c:\windows\system32\qynsmeao.ini
c:\windows\system32\qyrbocnf.ini
c:\windows\system32\rcxjfrom.ini
c:\windows\system32\rhouxljl.ini
c:\windows\system32\rijsyhnc.ini
c:\windows\system32\rrdhwmku.ini
c:\windows\system32\rsoexfgs.ini
c:\windows\system32\ruvshjej.ini
c:\windows\system32\ryxqlslt.ini
c:\windows\system32\ryydyosm.ini
c:\windows\system32\sbdcdbhc.ini
c:\windows\system32\sdpuxtlh.ini
c:\windows\system32\sfcrtmal.ini
c:\windows\system32\sglkdxfi.ini
c:\windows\system32\shquppsk.ini
c:\windows\system32\sjaiyqgn.ini
c:\windows\system32\srwbsynp.ini
c:\windows\system32\stftfaus.ini
c:\windows\system32\suevjghu.ini
c:\windows\system32\svsbxxpp.ini
c:\windows\system32\swdcenat.ini
c:\windows\system32\sxklrkks.ini
c:\windows\system32\tgpxehis.ini
c:\windows\system32\tmlmftpr.ini
c:\windows\system32\tmnsssax.ini
c:\windows\system32\tmurveks.ini
c:\windows\system32\torjsynp.ini
c:\windows\system32\tqhmagvk.ini
c:\windows\system32\tqnvcphb.ini
c:\windows\system32\tutpvfrl.ini
c:\windows\system32\tuvWnMGy.dll
c:\windows\system32\tvftbgut.ini
c:\windows\system32\tvwdmncl.ini
c:\windows\system32\twubxntn.ini
c:\windows\system32\ubbobxiy.ini
c:\windows\system32\uepeoset.ini
c:\windows\system32\ugcceqvw.ini
c:\windows\system32\uikyactj.ini
c:\windows\system32\ukgpuhxk.ini
c:\windows\system32\uldntpdj.ini
c:\windows\system32\unnapuai.ini
c:\windows\system32\uotienml.ini
c:\windows\system32\upwscktt.ini
c:\windows\system32\urnppkfa.ini
c:\windows\system32\urxjifle.ini
c:\windows\system32\usuluqgt.ini
c:\windows\system32\utjmcelx.ini
c:\windows\system32\utldsknu.ini
c:\windows\system32\uwajaoyu.ini
c:\windows\system32\uynpnqkl.ini
c:\windows\system32\uyxxekxr.ini
c:\windows\system32\vaiarfgq.ini
c:\windows\system32\vcqioofl.ini
c:\windows\system32\vgcycpug.ini
c:\windows\system32\vgtnxjdl.ini
c:\windows\system32\vgxhfhft.ini
c:\windows\system32\viruvhli.ini
c:\windows\system32\vlckniwj.ini
c:\windows\system32\voxwnjqy.ini
c:\windows\system32\vrarumrc.ini
c:\windows\system32\vrpqiemm.ini
c:\windows\system32\vtbyvjre.ini
c:\windows\system32\vuvibuhs.ini
c:\windows\system32\vypleuwg.ini
c:\windows\system32\vyrtpxqw.ini
c:\windows\system32\wcveeprr.ini
c:\windows\system32\weinbpjy.ini
c:\windows\system32\wgiduftr.ini
c:\windows\system32\whmeawjs.ini
c:\windows\system32\whtltosf.ini
c:\windows\system32\wpohwbtq.ini
c:\windows\system32\wpxfktgl.ini
c:\windows\system32\wxrrkwax.ini
c:\windows\system32\xcjlbkfl.ini
c:\windows\system32\xeqqmbup.ini
c:\windows\system32\xfhuwumy.ini
c:\windows\system32\xkccvnnx.ini
c:\windows\system32\xqhwidhq.ini
c:\windows\system32\xscrceyq.ini
c:\windows\system32\xvshcmka.ini
c:\windows\system32\xvsjxwiw.ini
c:\windows\system32\xvygfjvd.ini
c:\windows\system32\yayaxWNd.dll
c:\windows\system32\ydficcjk.ini
c:\windows\system32\yiiuousj.ini
c:\windows\system32\yrwkdosg.ini
c:\windows\system32\yvgtfnkr.ini
c:\windows\system32\yxbdtnoi.ini
c:\windows\system32\yyqsvswd.ini
c:\windows\Tasks\ggvmdutx.job
c:\windows\wr.txt

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BDGUARD
-------\Legacy_DOMAINSERVICE
-------\Legacy_fci
-------\Legacy_ONESTEP_SEARCH_SERVICE
-------\Legacy_SECONDARY_LOGON_(SECLOGON)_
-------\Service_DomainService
-------\Service_FCI


((((((((((((((((((((((((( Files Created from 2009-02-11 to 2009-03-11 )))))))))))))))))))))))))))))))
.

2009-03-11 16:45 . 2009-03-11 16:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-03-11 03:38 . 2009-03-11 03:38 <DIR> d-------- c:\documents and settings\aaaaaa\Application Data\Media Player Classic
2009-03-11 03:38 . 2009-03-11 03:38 <DIR> d-------- c:\documents and settings\aaaaaa\Application Data\GRETECH
2009-03-11 03:38 . 2009-03-11 03:38 <DIR> d-------- c:\documents and settings\aaaaaa\Application Data\DivX
2009-03-10 22:16 . 2009-03-10 22:16 <DIR> d-------- c:\documents and settings\aaaaaa\DoctorWeb
2009-03-10 21:52 . 2009-03-10 21:52 <DIR> d-------- c:\documents and settings\Administrator
2009-03-10 21:16 . 2009-03-10 21:17 <DIR> d-------- C:\32788R22FWJFW.0.tmp
2009-03-10 20:16 . 2009-03-10 22:59 <DIR> d-------- c:\documents and settings\aaaaaa\Contacts
2009-03-10 16:19 . 2009-03-10 16:19 <DIR> d-------- c:\documents and settings\new puki\Contacts
2009-03-10 16:16 . 2009-03-10 16:16 <DIR> d-------- c:\documents and settings\new puki\Application Data\MEGAUPLOADTOOLBAR
2009-03-10 15:06 . 2009-03-10 15:06 <DIR> d-------- c:\windows\system32\NtmsData
2009-03-10 14:20 . 2009-03-10 14:20 <DIR> d-------- c:\documents and settings\aaaaaa\Application Data\MEGAUPLOADTOOLBAR
2009-03-10 14:16 . 2009-03-10 22:16 <DIR> d-------- c:\documents and settings\aaaaaa
2009-03-10 12:33 . 2009-03-10 16:19 <DIR> d-------- c:\documents and settings\new puki
2009-03-09 17:59 . 2009-03-09 17:59 <DIR> d-------- c:\program files\Alwil Software
2009-03-09 17:22 . 2009-03-09 17:43 <DIR> d-------- c:\program files\ElcomSoft
2009-03-09 17:22 . 2009-03-09 17:24 789 --a------ c:\windows\ARPR.INI
2009-03-09 17:21 . 2009-03-09 17:21 1,313,104 --a------ c:\documents and settings\vinko\Application Data\setup.exe
2009-03-09 16:36 . 2009-03-10 12:23 19,968 --------- C:\xcgugvn.exe
2009-03-09 16:20 . 2009-03-11 18:15 100,846 --a------ c:\windows\system32\drivers\86ba83b4.sys
2009-03-09 16:09 . 2009-03-09 16:09 <DIR> d-------- c:\program files\Appwalk.com Technologies Canada
2009-03-09 15:39 . 2009-03-09 15:39 <DIR> d-------- c:\program files\MSBuild
2009-03-09 15:38 . 2009-03-09 15:57 <DIR> d-------- c:\windows\system32\XPSViewer
2009-03-09 15:38 . 2009-03-09 15:38 <DIR> d-------- c:\program files\Reference Assemblies
2009-03-09 15:37 . 2009-03-09 15:37 <DIR> d-------- c:\program files\MSXML 6.0
2009-03-09 15:37 . 2006-06-29 13:07 14,048 --a------ c:\windows\system32\spmsg2.dll
2009-03-09 15:32 . 2009-03-11 18:15 115,310 --a------ c:\windows\system32\drivers\d42368c4.sys
2009-03-09 15:32 . 2009-03-09 16:20 33,280 --a------ c:\windows\vgjacakh1.tmp
2009-03-09 15:32 . 2009-03-09 16:28 33,280 --a------ c:\windows\vgjacakh.dll
2009-03-09 14:55 . 2009-03-09 14:56 <DIR> d-------- c:\windows\system32\Adobe
2009-03-06 16:48 . 2009-03-06 16:48 <DIR> d-------- c:\program files\DVDVideoSoft
2009-03-06 16:48 . 2009-03-06 16:49 <DIR> d-------- c:\program files\Common Files\DVDVideoSoft
2009-03-06 16:29 . 2009-03-06 16:29 <DIR> d-------- C:\Mp3 Output
2009-03-06 16:29 . 2007-02-25 15:36 383,238 --a------ c:\windows\system32\libmp3lame-0.dll
2009-03-05 14:21 . 2009-03-05 14:21 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{017115B5-2F29-4ECD-8FD6-329F9F107B86}
2009-02-28 20:44 . 2009-02-28 20:44 <DIR> d-------- c:\program files\ImTOO
2009-02-28 17:01 . 2009-02-28 17:01 <DIR> d-------- C:\movies
2009-02-28 17:00 . 2009-02-28 17:01 67 --a------ c:\windows\Power Video Converter.INI
2009-02-28 16:59 . 2009-02-28 16:59 <DIR> d-------- c:\program files\Power Video Converter
2009-02-28 16:26 . 2004-08-04 00:56 159,232 --a------ c:\windows\system32\ptpusd.dll
2009-02-28 16:26 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-02-28 16:26 . 2004-08-03 22:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-02-28 16:26 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2009-02-17 18:47 . 2009-02-17 18:47 <DIR> d-------- c:\program files\Plus!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-11 16:28 --------- d-----w c:\documents and settings\vinko\Application Data\Deepnet Explorer
2009-03-11 15:54 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-11 15:53 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-10 21:44 --------- d-----w c:\documents and settings\All Users\Application Data\eq rect plus copy
2009-03-10 15:16 --------- d-----w c:\program files\Kaspersky Lab
2009-03-10 15:16 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-10 09:55 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-09 15:05 --------- d-----w c:\program files\DNA
2009-03-09 15:05 --------- d-----w c:\documents and settings\vinko\Application Data\DNA
2009-03-07 01:33 --------- d-----w c:\documents and settings\vinko\Application Data\FrostWire
2009-03-06 16:30 --------- d-----w c:\program files\Deepnet Explorer
2009-03-06 15:48 --------- d-----w c:\program files\Smallvideosoft
2009-02-28 19:45 --------- d-----w c:\documents and settings\vinko\Application Data\ImTOO Software Studio
2009-02-28 15:57 --------- d-----w c:\documents and settings\vinko\Application Data\Any Video Converter
2009-02-10 23:36 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-09 15:41 --------- d-----w c:\program files\SweetIM
2009-02-09 15:41 --------- d-----w c:\documents and settings\All Users\Application Data\SweetIM
2009-02-07 02:12 --------- d-----w c:\program files\Reganam
2009-02-04 13:27 --------- d-----w c:\program files\FrostWire
2009-02-03 09:25 --------- d-----w c:\documents and settings\vinko\Application Data\DAPE
2009-02-01 12:58 --------- d-----w c:\documents and settings\vinko\Application Data\uTorrent
2009-01-30 16:44 --------- d-----w c:\program files\Common Files\Adobe
2009-01-30 11:21 --------- d-----w c:\program files\LunaPlayer
2009-01-29 11:25 --------- d-----w c:\program files\uTorrent
2009-01-27 13:19 --------- d-----w c:\program files\VideoLAN
2009-01-27 13:18 --------- d-----w c:\program files\Graboid
2009-01-26 14:48 --------- d-----w c:\documents and settings\admin.VINKO.000\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 14:38 --------- d-----w c:\documents and settings\admin.VINKO.000\Application Data\MozillaControl
2009-01-26 14:36 --------- d-----w c:\documents and settings\admin.VINKO.000\Application Data\grim htm
2009-01-26 14:09 --------- d-----w c:\documents and settings\admin.VINKO\Application Data\vlc
2009-01-26 13:53 --------- d-----w c:\documents and settings\admin.VINKO\Application Data\MozillaControl
2009-01-26 13:52 --------- d-----w c:\documents and settings\admin.VINKO\Application Data\grim htm
2009-01-26 13:51 --------- d-----w c:\documents and settings\admin.VINKO\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 13:29 --------- d-----w c:\documents and settings\admin\Application Data\grim htm
2009-01-26 13:27 --------- d-----w c:\documents and settings\admin\Application Data\Deepnet Explorer
2009-01-26 13:27 --------- d-----w c:\documents and settings\admin\Application Data\DAPE
2009-01-26 13:25 --------- d-----w c:\documents and settings\admin\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 13:10 --------- d-----w c:\documents and settings\pukšec\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 12:41 --------- d-----w c:\documents and settings\Guest\Application Data\MEGAUPLOADTOOLBAR
2009-01-26 11:19 --------- d-----w c:\documents and settings\All Users\Application Data\Launcher
2009-01-25 23:11 --------- d-----w c:\documents and settings\All Users\Application Data\Graboid Inc
2009-01-25 10:43 --------- d-----w c:\program files\Java
2009-01-24 22:20 --------- d-----w c:\program files\Microsoft Works
2009-01-24 22:17 --------- d-----w c:\program files\Microsoft.NET
2009-01-24 11:28 --------- d-----w c:\program files\Word Recovery Toolbox
2009-01-23 10:18 --------- d-----w c:\documents and settings\vinko\Application Data\BitTorrent
2009-01-23 10:05 --------- d-----w c:\program files\BitTorrent
2009-01-23 10:04 --------- d-----w c:\program files\AskBarDis
2009-01-16 22:37 --------- d-----w c:\program files\Realtek Sound Manager
2009-01-16 22:37 --------- d-----w c:\program files\Realtek AC97
2009-01-16 22:37 --------- d-----w c:\program files\AvRack
2009-01-16 16:05 --------- d-----w c:\program files\Lavalys
2009-01-15 16:30 --------- d-----w c:\program files\Motorama
2009-01-15 16:19 --------- d-----w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-01-15 11:09 --------- d-----w c:\program files\Folder Lock 6
2009-01-15 10:45 --------- d-----w c:\program files\FDN
2009-01-15 10:12 --------- d-----w c:\program files\Folder Lock
2009-01-13 20:22 --------- d-----w c:\documents and settings\vinko\Application Data\MSN6
2009-01-12 20:44 --------- d-----w c:\documents and settings\vinko\Application Data\Skype
2008-12-27 20:23 16,896 --sh--r c:\program files\captcha5.dll
2007-01-25 02:52 65,536 ----a-w c:\program files\Common Files\NMSAccessU.exe
2008-07-17 17:46 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-07-17 17:46 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-07-17 17:46 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-07-17 17:46 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-07-17 17:46 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{db9d7a78-a76c-4bf2-97c6-258925ee1542}"= "c:\program files\Reganam\tbReg1.dll" [2009-03-02 1883672]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-10-08 173368]

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-29 17:24 325000 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]
2009-03-02 17:56 1883672 --a------ c:\program files\Reganam\tbReg1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 12:22 1172792 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{db9d7a78-a76c-4bf2-97c6-258925ee1542}"= "c:\program files\Reganam\tbReg1.dll" [2009-03-02 1883672]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{DB9D7A78-A76C-4BF2-97C6-258925EE1542}"= "c:\program files\Reganam\tbReg1.dll" [2009-03-02 1883672]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"userfaultcheck"="c:\windows\system32\dumprep 0 -u" [X]
"8367"="C:\xcgugvn.exe" [2009-03-10 19968]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-19 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\program files\TGTSoft\StyleXP\Logon\CurrentLogon.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.3iv2"= c:\progra~1\K-LITE~1\codecs\3IVXVF~1.DLL
"VIDC.VP60"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP61"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP62"= c:\progra~1\K-LITE~1\codecs\vp6vfw.dll
"VIDC.VP70"= c:\progra~1\K-LITE~1\codecs\vp7vfw.dll
"VIDC.VP31"= c:\progra~1\K-LITE~1\codecs\vp31vfw.dll
"VIDC.FFDS"= c:\progra~1\K-LITE~1\ffdshow\ff_vfw.dll
"msacm.l3fhg"= c:\progra~1\K-LITE~1\codecs\l3codecp.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C *\0aswBoot.exe /M:2bed903d

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winfi24.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Avant Browser\\avant.exe"=
"c:\\Program Files\\Deepnet Explorer\\Deepnet.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\OFFICE\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=

R0 tihlayxx;tihlayxx;c:\windows\system32\drivers\tihlayxx.sys [2001-08-23 23424]
S0 Winfi24;Winfi24;c:\windows\system32\Drivers\Winfi24.sys --> c:\windows\system32\Drivers\Winfi24.sys [?]
S2 JBouvoaqcji;JBouvoaqcji;c:\windows\System32\svchost.exe -k netsvcs [2001-08-23 14336]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2001-08-23 3584]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [2009-01-16 23152]
S3 usb2vcom;DKU-5 Connectivity Adapter Cable;c:\windows\system32\drivers\usb2vcom.sys [2008-06-02 28704]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
JBouvoaqcji

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-03-11 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]

2009-03-11 c:\windows\Tasks\User_Feed_Synchronization-{2D66750F-BFE6-4E89-AC8F-9B92B15CD980}.job
- c:\windows\system32\msfeedssync.exe [2009-01-15 02:01]
.
- - - - ORPHANS REMOVED - - - -

BHO-{00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
BHO-{05C56B17-5A02-4F18-A9D2-E4CF4A8F6645} - (no file)
BHO-{07B18EA1-A523-4961-B6BB-170DE4475CCA} - (no file)
BHO-{100EB1FD-D03E-47FD-81F3-EE91287F9465} - (no file)
BHO-{13807400-768B-4791-A5A6-1A95462E8944} - c:\documents and settings\vinko\Local Settings\Temporary Internet Files\Content.IE5\R3DRZVKQ\silent.dll[1].bak
BHO-{1D0B1B2F-4D44-48DC-AE5A-F4BBBAE2A83F} - (no file)
BHO-{2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
BHO-{3A6D079E-4234-4CFC-9180-DB4462ABEF9A} - (no file)
BHO-{508ad95d-5798-4eda-a928-a72a921fb43f} - c:\windows\system32\khfEuRif.dll
BHO-{5953598F-83BD-44A0-8F5F-38912B03AA05} - (no file)
BHO-{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\tuvWnMGy.dll
BHO-{8DE62E58-BA3D-40D3-AD5A-2BA5FD6E5A90} - c:\windows\system32\iifDWpOE.dll
BHO-{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - (no file)
BHO-{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - (no file)
BHO-{E9BD0828-1FD9-410C-A50F-43EBE65D310F} - (no file)
BHO-{F1E96EDC-E0C8-BE98-1F15-C29DBED83B53} - (no file)
Toolbar-{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
Toolbar-{07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
WebBrowser-{89FDCC4B-8D91-49B0-81A6-18BCFF582735} - (no file)
WebBrowser-{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
ShellExecuteHooks-{E9BD0828-1FD9-410C-A50F-43EBE65D310F} - (no file)
ShellExecuteHooks-{1D0B1B2F-4D44-48DC-AE5A-F4BBBAE2A83F} - (no file)
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\tuvWnMGy.dll
Notify-cbXOfdcA - (no file)
Notify-urqnmmk - (no file)
Notify-winjpq32 - (no file)


.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
IE: Ispuni obrasce - [Link mogu videti samo ulogovani korisnici]\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Prilagodi izbornik - [Link mogu videti samo ulogovani korisnici]\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: RF Alatna traka - [Link mogu videti samo ulogovani korisnici]\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Spremi obrasce - [Link mogu videti samo ulogovani korisnici]\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{C5428486-50A0-4a02-9D20-520B59A9F9B2} - {C9CCBB35-D123-4a31-AFFC-9B2933132116} -
IE: {{C5428486-50A0-4a02-9D20-520B59A9F9B3} - {A16AD1E9-F69A-45af-9462-B1C286708842} -
TCP: {AE8C66A4-2AB9-4342-96A4-93E9821D3E2B} = 195.29.149.196,195.29.149.197
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - [Link mogu videti samo ulogovani korisnici]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-03-11 18:14:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\docume~1\vinko\LOCALS~1\Temp\PrePict.htm 770 bytes
c:\docume~1\vinko\LOCALS~1\Temp\quadra000 0 bytes
c:\docume~1\vinko\LOCALS~1\Temp\rip10.exe 72704 bytes executable
c:\docume~1\vinko\LOCALS~1\Temp\seneka000 0 bytes
c:\docume~1\vinko\LOCALS~1\Temp\setup.log 3374 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Sym4.tmp 186770 bytes
c:\docume~1\vinko\LOCALS~1\Temp\SymNRT 3-11-2009 16h44m53s.log 15361632 bytes
c:\docume~1\vinko\LOCALS~1\Temp\tdss000 0 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\0[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\1061030468_02[1].swf 23756 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\1[2].gif 364 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\local-fm[1].gif 1668 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\logo[1].gif 10154 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\logo[1].png 8788 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mail[1].txt 5508 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mail[2] 108 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mail[4] 113709 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\google-earth[1].gif 9771 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_bul_3[1].gif 50 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_mdl_bg[1].gif 157 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_nav_02[1].gif 350 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_search[1].gif 54 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\g_06_top_bg[1].jpg 11087 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\header_topline[1].png 47988 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\hig[1].css 31041 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\hig[2].css 31041 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\shareaza-turbo-accelerator[1].jpg 8781 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\shared[1].css 5364 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\shared[1].js 6902 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\show_ads[1].js 30022 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\sl[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\sma[1].png 728 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\camera[1] 14062 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\cat_10[1].jpg 644 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\cat_12[1].jpg 626 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\cat_17[1].jpg 884 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\p[1].gif 42 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\button1-bm[1].gif 637 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\desktop.ini 67 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\dnserrordiagoff_webOC[2] 6766 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\dnserror[1] 5947 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\download-kaspersky-virus-removal-tool[1].html 33142 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\downloads[1].txt 18323 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\ErrorPageTemplate[1] 2168 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\ES[2].gif 992 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\allPics[1].gif 58870 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\pfeil_zu[1].jpg 562 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\pixel-vfl73[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\javafunction[1].js 1253 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\K2ZO6CAUC8Z5LCAJ62BUDCAKW5ZXMCA1N7YU3CA2Y4FKICAFT5DDLCAG8JM9PCAYDDYDHCAOEG7QICALFZ2JICAO82AFOCAMQG1P4CA1CEXB4CAL05188CAZ7G3G0CAF83FOBCASOLWWZCA18BGD7CA69MI6YCA840FGVCAKRVVTP.txt 7611 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\Kaspersky-Anti-Virus[1].txt 34705 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\knights[1].gif 346 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\the-battle-for-wesnoth[1].gif 923 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tooltip-vfl56131[1].gif 531 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\top[1].gif 2289 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\nav_logo4[1].png 7121 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bearshare-turbo-accelerator[1].gif 1236 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\behavior[1].js 33954 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fl_logo_b[1].gif 890 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\folder_big[1].gif 612 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\folder_locked_big[1].gif 370 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\footer-croportal-icon[1].gif 347 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\footer_bg[1].jpg 13241 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\FormBG[1].gif 413 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\ga[1].js 22759 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStatCALQBB2D.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[1].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[2].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[3].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[4].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[5].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[6].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[7].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[8].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStat[9].dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\2817[1].png 9836 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\300299803[1].jpg 27189 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\3[1].gif 238 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\star1[1].gif 147 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\starbw[1].gif 137 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\UAHelp_Classic[1].css 339 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\urchin[1].js 22645 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\users32[1] 2238 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\VeriSignSeal_klein[1].gif 1856 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\search 425 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\searchBG[1].gif 555 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\search[10] 495 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\search[11] 429 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\search_bg_1[1].jpg 16925 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\launchhelp[1].js 2274 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\brand[1].txt 616 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\btnSmall[1].gif 699 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\favicon[4].ico 7078 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\favicon[5].ico 1150 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fdn[1].js 1475 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fdn[2].js 810 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\createpage[1] 705 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\croportal-logo[1].png 15397 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\dap[1].js 13249 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\rc[1].png 121 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\real-temp[1].gif 1747 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\stil2[1].css 7132 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\styles[2].css 5810 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\st[2] 4397 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\728x90_croportal_ver_6[1].swf 44563 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\aaa_lft[1].gif 571 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_30_tage_ohne_zusatz_en[2].jpg 13787 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\ProfilePhoto_UserTileSmall,Thumbnail[1].jpg 875 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\new_tabs_pas_bg[1].gif 152 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\new_tabs_sel[1].gif 426 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\nusrmgr[1] 1760 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\nusrmgr[2] 8119 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\n_2[1].gif 350 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\n_7[1].gif 344 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\n_9[1].gif 554 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mail[6] 122136 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStatCAAKGYM8.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_30_tage_ohne_zusatz_en[1].jpg 13787 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\hover[1].js 509 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\http_404_webOC[1] 6381 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\icon_friend[1].gif 1035 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\icon_members[1].gif 1067 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\icon_search[1].gif 1131 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mojtv[1].gif 1513 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\motion_log[1].php 0 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\whosonline[1].gif 842 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\widget02[1].css 4337 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bad[1].txt 394 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\6158[1].htm 2513 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\trazi[1].gif 1560 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tv-listing-bottom[1].gif 235 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tv-raspored[1].txt 78003 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\repltx[2].aspx 25 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\rpics[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\switch2_ua[1].gif 3136 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tab-hover-left[1].gif 1455 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\tab-link-left[1].gif 1455 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\table_header_gradient[1].png 132 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\taskbullet[1] 995 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bind[1].txt 661 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\borderBottom[1].gif 191 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bottomCorner[1].gif 125 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStatCA5TBIVG.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\PlayToyStatCA8AFUMV.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\test_domain[1].js 54 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\www-core-vfl82316[1].css 69302 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\chg_common[2] 2666 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\cleardot[1].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\demoreg[2].html 45789 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\mainpage[1] 3291 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\main[1].js 3347 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\menu07[1].js 12604 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\safari[1].jpg 3753 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\script[1].aspx 2072 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\bgLeft[1].gif 364 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\portable-miranda-im[1].gif 1170 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_2_paybycall[1].jpg 3187 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_2_paybycall[2].jpg 3187 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_2_reseller[1].jpg 2934 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\preisschild_2_reseller[2].jpg 2934 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfoicon_fileactivity[1].gif 594 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfoicon_website[1].gif 589 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo[1].css 7552 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo_aliasimage[1].gif 3247 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo_fileactivityimage[1].gif 2706 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo_headerbg[1].gif 264 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\fileinfo_malwareimage[1].gif 3336 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\file_linktothispage_cro[1].gif 501 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\0XNAXATJ\file_tab1[1].gif 727 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\button-login[1].gif 2004 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0000000001_000000000000000163039[1].jpg 5453 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0000000001_000000000000000301317[1].jpg 9756 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0[1].gif 57934 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0[1].jpg 94182 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\0[2].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\swfobject[1].js 6880 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\s_code_50105[1].js 22039 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\newplaytoy[1].htm 3773 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\newzfind_com[1].htm 88202 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\n_1[1].gif 341 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\n_3[1].gif 348 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ads[11].txt 6869 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\301[2].gif 2683 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\vghd_768x245_youporn[1].swf 36299 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\search[10] 497 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\search[2].txt 10422 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\download-kaspersky-anti-virus[1].html 33138 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\downloadit[1].gif 506 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\down[1] 3414 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\preisschild_365_tage_ohne_zusatz_en[1].jpg 15649 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\preisschild_3_leer[1].jpg 1290 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\preisschild_3_leer[2].jpg 1290 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\k1VYXjgOIbk[1].js 20472 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\Kasp[2].rar 39230252 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\kis_09_eng_90_120[1].png 19936 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\tv-listing-top[1].gif 271 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfoicon_arrow[1].gif 298 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfoicon_registry[1].gif 587 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_behaviourimage[1].gif 3738 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_headerimageblue[1].gif 2899 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_logo[1].gif 3086 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_networkimage[1].gif 3621 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\fileinfo_vendorimage[1].gif 3207 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g[2].png 193 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g_06_btm_line[1].gif 1393 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g_06_nav_01_sel[1].gif 155 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g_06_nav_02[1].gif 350 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\g_06_search[1].gif 54 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\sortArr[1].gif 57 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\button[1].gif 1405 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\bysoft-free-bmi-calculator[1].gif 1322 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_11[1].jpg 900 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_13[1].jpg 916 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_14[1].jpg 948 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_3[1].jpg 805 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cat_6[1].jpg 936 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ads.txt 6721 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ADSAdClient31[3].txt 5082 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ads[10].txt 4379 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\menu_header_1[1].gif 1352 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\menu_off[1].gif 356 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\miracles[1].gif 1387 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\links[1].htm 214 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\logo_small[1].gif 826 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\UAHelp[1] 597 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\users[1] 25214 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\vbulletin_md5[1].js 9661 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\vbulletin_md5[2].js 5464 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\icon_report[1].gif 585 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\9DI8NCA6DRL17CAF53RNBCA23EEULCAKPI5JRCAAZFMRJCAU2U8YACA2D7K1ACAKD8WB5CAAJM82QCA73R0RTCABQLEFDCABEAOGJCAUKVR9OCA70J3GJCAK2V75RCAZ4B0UMCAA16TY6CA8A5BFFCAK4ZB64CA8XT8H6CAIQ8EKN.txt 4678 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\abg-en-100c-000000[1].png 1006 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\abg-hr-100c-000000[1].png 951 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\AccountPage[1] 3379 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\accountpage[2] 1088 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\acct_common[2] 1505 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\AC_RunActiveContent[1].js 8321 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\e5_main[1].js 514 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\rslogo[1].gif 3913 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\PicturePage[1] 3243 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\picturepage[2] 6744 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\pinnacle-videospin[1].gif 1433 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\top[1].png 2470 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\ChangePage[1] 1582 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cleardot[2].gif 43 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\Common[1].js 3159 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\Common[2].js 3159 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\cpwebvw[1] 3611 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\Default[1].aspx 7806 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\desktop.ini 67 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\divider-archive-to-footerlinks[1].png 2934 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\divider-copyright-top[1].png 2849 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\PlayToyStatCADZ0PZO.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\PlayToyStatCAOK8QIL.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\PlayToyStatCAWXBADG.dat 58 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\preisschild_1_paypal[1].jpg 2853 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\2KFTNCAQC6UWSCABVYKG0CAUUI217CA4640UCCANZHX8ACA22QQMBCA0KWD8LCARB3Y2ZCA6Z76CACAEB9CDXCAM1JAX9CA5IPOI8CAJ5BW6TCAUE7ZJ4CA6BUK6DCA6KJI7UCAA4AT3ECAX7OAU1CAOLNCX6CAOXZQG0CAYXH2ZK.txt 11429 bytes
c:\docume~1\vinko\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\C3R6B1MA\sizer-bg[1].gif 23925 bytes
c:\docume~1\vinko\L

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

[Link mogu videti samo ulogovani korisnici]

Dopuna: 11 Mar 2009 18:36

skužih.. Smile

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8652
  • Gde živiš: Novi Beograd

OK.

Trebace mi dosta vremena dok sve pregledam i napisem sta da se brise.

Citamo se kasnije....

Ne brini, popravicemo.

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

ne steka mi zasad nista... ,svaka ti cast..

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8652
  • Gde živiš: Novi Beograd

Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\xcgugvn.exe
c:\windows\system32\drivers\86ba83b4.sys
c:\windows\system32\drivers\d42368c4.sys
c:\windows\vgjacakh1.tmp
c:\windows\vgjacakh.dll
c:\windows\system32\drivers\tihlayxx.sys
c:\windows\system32\Drivers\Winfi24.sys
c:\program files\captcha5.dll

Folder::
c:\documents and settings\All Users\Application Data\eq rect plus copy
c:\documents and settings\admin.VINKO.000\Application Data\grim htm
c:\documents and settings\admin.VINKO\Application Data\grim htm
c:\documents and settings\admin\Application Data\grim htm
c:\program files\grim htm

Driver::
tihlayxx
Winfi24
JBouvoaqcji
86ba83b4
d42368c4

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"8367"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winfi24.sys]

NetSvc::
JBouvoaqcji


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

[Link mogu videti samo ulogovani korisnici]

javlja i ovu gresku: C:\$Mft is corrupt and unreadable. please run the chkdsk utilly.
mislim da je tu i glavni problem jer meni nije mogao zavrsiti checkdisk na c disku zapeo je negdje na stage 2.. nisam siguran , ali morao sam rucno restartati os i odbiti checkdisk da bi mi se windows "normalno" pokrenuo .. neka greska ne ja c disku

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8652
  • Gde živiš: Novi Beograd

Preuzmi gmer.zip sa ovog linka i sačuvaj na Desktopu.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde ta dva fajla koja smo malopre snimili.

offline
  • puki22 
  • Novi MyCity građanin
  • Pridružio: 10 Mar 2009
  • Poruke: 23

oprosti ali kako pokrenuti taj "autostart" tab ????

Ko je trenutno na forumu
 

Ukupno su 922 korisnika na forumu :: 67 registrovanih, 3 sakrivenih i 852 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 16.mabr, 357magnum, 8u47, A.R.Chafee.Jr., amstel, Banovo Brdo, Betty25, Bolencebl, boromir, BZ, Cicumile, Cirkon, Darth Wader, Dimitrise93, Djokovic, DM1994, drimer, Džekson, Gintoki, Gogi_avio, Ir, Istman, Ivoo, Jester, Jozo74, komsija1, kuntakinte, kybonacci, Laske, mercedesamg, micke83, mikelija, milenko crazy north, MiloradKomadic, milosdam, Mrav Obrad, mrkanidja, nebojsag, neko iz mase, nikoladim, Nomica, orfanel, ostoja, Otto Grunf, Pekman, Petarvu, Plavi Jadran, Podljub, proljece, RajkoB, ruma, samsung, Simonsen23, Sirius, Sonic, Stanislav1970, synergia, Tamna_strana_Meseca, tomigun, tooljan, troki1971, Tvrtko I, Vanderx, VanZan, VJ, Vrač, zokizemun