Msn problem

1

Msn problem

offline
  • Pridružio: 20 Sep 2010
  • Poruke: 31

Izgleda da mi je neko hakovao nalog msn prijavljuje mi da sam ulogovan na dva mesta. Ja se izlogujem promenim sifru posle nekog vremena opet prijavljuje da sam ulogovan na dva mesta. Stizu mi mejlovi sa registracijom sa nekih foruma gde nisam bio a kad hocu da se registrujem na neki sajt kaze mi da je moj mejl vec u upotrebi. Skenirao sam avastom i nista. Sad sam promenio treci put.



.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by mihajlo at 19:15:17 on 2012-10-06
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.895.52 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Windows\ZSSnp211.exe
C:\Windows\Domino.exe
C:\Program Files\Searchqu Toolbar\Datamngr\datamngrUI.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\HiSuite\HiSuite.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\Users\mihajlo\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Windows\system32\crypserv.exe
C:\Windows\System32\ezSharedSvcHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Users\mihajlo\AppData\Local\HiSuite\userdata\ADB\adb.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Windows\system32\svchost.exe -k imgsvc
D:\TECDOC_CD\1_2011\db\tbmux32.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchnu.com/406
uURLSearchHooks: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\ytd toolbar\ie\6.3\ytdToolbarIE.dll
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: H - No File
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTor.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AC-Pro: {0fb6a909-6086-458f-bd92-1f8ee10042a0} - c:\program files\autocompletepro\AutocompletePro.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\search~2\datamngr\toolbar\searchqudtx.dll
BHO: DataMngr: {9d717f81-9148-4f12-8568-69135f087db0} - c:\progra~1\search~2\datamngr\BROWSE~1.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTor.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\ytd toolbar\ie\6.3\ytdToolbarIE.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTor.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\search~2\datamngr\toolbar\searchqudtx.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\alwil software\avast5\aswWebRepIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: YTD Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\ytd toolbar\ie\6.3\ytdToolbarIE.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [<NO NAME>]
uRun: [Mobile Partner] c:\program files\hisuite\HiSuite.exe -s
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [ZSSnp211] c:\windows\ZSSnp211.exe
mRun: [Domino] c:\windows\Domino.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [DATAMNGR] c:\progra~1\search~2\datamngr\DATAMN~1.EXE
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [avast] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [HTC Sync Loader] "c:\program files\htc\htc sync 3.0\htcUPCTLoader.exe" -startup
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [<NO NAME>]
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
StartupFolder: c:\users\mihajlo\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\mihajlo\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\mihajlo\appdata\roaming\micros~1\windows\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-f400-7760-000000000003}\_SC_Acrobat.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wg111v~1.lnk - c:\program files\netgear\wg111v2 configuration utility\RtlWake.exe
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\mihajlo\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{495A19CE-5DC8-4739-BCDE-8B38A13CFB21} : DhcpNameServer = 192.168.42.129
TCP: Interfaces\{ACD7EECD-4B8A-480E-9831-1E540F629435} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{B22D5E5A-314E-45A6-9E9B-0B14321B0869} : DhcpNameServer = 192.168.42.129
TCP: Interfaces\{B524BB53-2495-4A8A-B053-502C0DB1B3D9} : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
AppInit_DLLs: c:\progra~1\search~2\datamngr\datamngr.dll c:\progra~1\search~2\datamngr\iebho.dll c:\progra~1\search~1\search~1\datamngr.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - c:\windows\system32\EZUPBH~1.DLL
SEH: UPB:{B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No File
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\mihajlo\appdata\roaming\mozilla\firefox\profiles\wkq6ydpp.default\
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://www.searchnu.com/406
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=390&systemid=406&sr=0&q=
FF - prefs.js: network.proxy.ftp - 137.110.190.156
FF - prefs.js: network.proxy.ftp_port - 9415
FF - prefs.js: network.proxy.http - 137.110.190.156
FF - prefs.js: network.proxy.http_port - 9415
FF - prefs.js: network.proxy.socks - 137.110.190.156
FF - prefs.js: network.proxy.socks_port - 9415
FF - prefs.js: network.proxy.ssl - 137.110.190.156
FF - prefs.js: network.proxy.ssl_port - 9415
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\mihajlo\appdata\local\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_265.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
============= SERVICES / DRIVERS ===============
.
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2012-6-19 24408]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-3-31 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-7-11 355632]
R1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-9-19 795072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-7-11 21256]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-7-11 58680]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2012-9-2 44808]
R2 ezSharedSvc;Easybits Services for Windows;c:\windows\system32\ezSharedSvcHost.exe [2010-10-8 514232]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
R2 HuaweiHiSuiteService.exe;HuaweiHiSuiteService.exe;c:\programdata\handsetservice\HuaweiHiSuiteService.exe [2012-9-5 161120]
R2 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2010-3-25 490280]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\htc\internet pass-through\PassThruSvr.exe [2012-3-23 87040]
R2 Transbase TECDOC CD 1_2011 Service;Transbase TECDOC CD 1_2011 Service;d:\tecdoc_cd\1_2011\db\tbmux32.exe [2010-10-25 356352]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2010\TuneUpUtilitiesService32.exe [2009-10-30 1021256]
R3 adatadrv;Autodata Protection Service;c:\windows\system32\drivers\adatadrv.sys [2010-7-12 762112]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
R3 rt61x86;RT61 Extensible Wireless Driver;c:\windows\system32\drivers\netr61.sys [2010-4-7 376160]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-6-23 275048]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
R3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2010-7-11 480128]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
R3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [2010-7-11 1472000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-5-5 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-7 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-10 250288]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-4-1 183560]
S3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\drivers\BthAvrcp.sys [2009-8-13 22528]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-8-21 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-8-21 8456]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-6-25 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-5-5 136176]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2009-10-26 25088]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-23 23040]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2011-2-25 112384]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-5-13 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-5-13 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-5-13 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2011-5-13 114280]
S3 wxpSvc;webcamXP Service;c:\program files\webcamxp 5\wService.exe [2011-7-27 5023744]
.
=============== Created Last 30 ================
.
2012-10-06 10:09:57 -------- d-----w- c:\users\mihajlo\appdata\local\{BFBD0118-8006-46EE-AA38-D4F29BDF98ED}
2012-10-05 14:00:15 -------- d-----w- c:\users\mihajlo\appdata\local\{52B2237F-99F4-45AD-8EE9-0218373CE859}
2012-10-04 14:08:17 -------- d-----w- c:\users\mihajlo\appdata\local\{E49F2230-C37A-44B4-B297-51970569EE4C}
2012-10-03 14:47:56 -------- d-----w- c:\users\mihajlo\appdata\local\{36664DA0-067B-49A0-800B-240FED322E1E}
2012-10-02 12:59:00 -------- d-----w- c:\users\mihajlo\appdata\local\{E3279217-5463-4A5D-A7DA-183B03D7B7A4}
2012-10-01 09:02:10 -------- d-----w- c:\users\mihajlo\appdata\local\{AF20003B-2705-42F1-AAE6-DD4A689F7F1B}
2012-09-30 10:20:23 -------- d-----w- c:\users\mihajlo\appdata\local\{FE373380-D060-492C-9489-B0158C21F942}
2012-09-28 15:48:50 -------- d-----w- c:\users\mihajlo\appdata\local\{97D5CAE9-2E59-4449-9507-1F9BE149592B}
2012-09-27 13:15:05 -------- d-----w- c:\users\mihajlo\appdata\local\{4D4468FB-BEFD-4F3A-953D-63D0B2340346}
2012-09-26 17:18:42 -------- d-----w- c:\program files\Application Updater
2012-09-26 17:18:41 -------- d-----w- c:\program files\YTD Toolbar
2012-09-26 17:18:41 -------- d-----w- c:\program files\common files\Spigot
2012-09-26 15:23:18 -------- d-----w- c:\users\mihajlo\appdata\local\{E4BD4CC9-53D8-4B3E-B7F0-697A8298C36B}
2012-09-25 17:15:25 -------- d-----w- c:\users\mihajlo\appdata\local\{7CF0F6C2-16BE-488B-A039-94B57E3BABEA}
2012-09-24 05:53:23 -------- d-----w- c:\users\mihajlo\appdata\local\{0031094F-C544-4315-8C76-E17B93C4EA97}
2012-09-23 10:45:55 -------- d-----w- c:\users\mihajlo\appdata\local\{7845A586-C094-4A55-A9D5-25E4B1113604}
2012-09-22 08:57:42 -------- d-----w- c:\users\mihajlo\appdata\local\{E48B1B01-ACAC-4E69-BE5D-C2C4D14A8D9B}
2012-09-21 20:57:12 -------- d-----w- c:\users\mihajlo\appdata\local\{CCF4D672-3FF7-4081-B458-86AF75D1BB41}
2012-09-21 10:44:58 -------- d-----w- c:\programdata\YTD Video Downloader
2012-09-21 10:44:10 -------- d-----w- c:\program files\GreenTree Applications
2012-09-21 08:55:48 -------- d-----w- c:\users\mihajlo\appdata\local\{215EA106-3F74-4F82-BAF0-A6393604A963}
2012-09-20 07:03:58 -------- d-----w- c:\users\mihajlo\appdata\local\{84BE3874-19AD-4BF0-847E-2A0BB4D845BE}
2012-09-18 06:59:45 -------- d-----w- c:\users\mihajlo\appdata\local\{8A4F4955-2D7A-4FE4-B21B-6B88CA0B66EE}
2012-09-17 18:59:18 -------- d-----w- c:\users\mihajlo\appdata\local\{AE390089-0670-4C53-9816-66A504C0C406}
2012-09-17 06:59:03 -------- d-----w- c:\users\mihajlo\appdata\local\{C4008FA5-61B8-47AA-92C0-0BC0EE66C647}
2012-09-16 06:58:20 -------- d-----w- c:\users\mihajlo\appdata\local\{BC9EF097-45DC-47CF-965F-547E1330E6FE}
2012-09-15 18:57:58 -------- d-----w- c:\users\mihajlo\appdata\local\{7B18F2CF-36D0-4787-9886-A1F535041667}
2012-09-15 06:57:41 -------- d-----w- c:\users\mihajlo\appdata\local\{72EC3885-769A-4281-A103-143A1DFB034B}
2012-09-14 17:45:20 -------- d-----w- c:\users\mihajlo\appdata\local\{59F59434-D57C-4F47-8E1A-4BCE0C06E615}
2012-09-14 05:45:07 -------- d-----w- c:\users\mihajlo\appdata\local\{832280F9-1965-46E4-8910-6D167BE2DAE8}
2012-09-13 05:44:17 -------- d-----w- c:\users\mihajlo\appdata\local\{6AF004F5-72A6-4DFB-9CD9-73C0C2CF16B8}
2012-09-12 10:02:53 -------- d-----w- c:\users\mihajlo\appdata\local\{CB7E4424-2BC6-45E5-A0C5-486E15D5A011}
2012-09-11 09:22:10 -------- d-----w- c:\users\mihajlo\appdata\local\{0FCE1040-1E46-4F11-B668-524A6AB80C72}
2012-09-10 13:27:16 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-10 13:08:42 -------- d-----w- c:\users\mihajlo\appdata\local\{C5302228-B6CB-4168-9F9F-99B82858D738}
2012-09-09 06:25:36 -------- d-----w- c:\users\mihajlo\appdata\local\{BFC221E9-A9B6-4A12-AC0C-A2EE37CDF0CC}
2012-09-08 07:04:31 -------- d-----w- c:\users\mihajlo\appdata\local\{5E810DF2-2951-43BA-B016-4D6C19DE97D3}
2012-09-07 07:04:06 -------- d-----w- c:\users\mihajlo\appdata\local\{1ED91A53-FB81-40B1-8A68-A94EFED66650}
2012-09-06 18:32:07 -------- d-----w- c:\users\mihajlo\appdata\local\{E7CE3BB1-69A2-40ED-8DA0-C065AF2751A7}
.
==================== Find3M ====================
.
2012-09-21 09:39:13 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-21 09:39:12 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-10 13:26:59 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-10 13:26:59 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13:14 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13:14 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
.
============= FINISH: 19:16:21.67 ===============

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

offline
  • Més que un club
  • Glavni vokal @ Harpun
  • Pridružio: 27 Feb 2009
  • Poruke: 3896
  • Gde živiš: Novi Sad,Klisa

Pozdrav,goranzeljic





U toku resavanja slucaja, zamolio bih te da se pridrzavas sledeceg:
Detaljno citati moja uputstva ( ili uputstva kolega koji ce me zamenjivati) i raditi iskljucivo po njima;
Ne traziti istovremeno pomoc na drugom mestu;
Nemoj koristiti druge programe za uklanjanje malware-a, osim onih za koje budes dobio uputstvo;
U toku intervencije ne koristiti USB memorijske uredjaje, dok to ne budem zatrazio;
Ukoliko ne odgovorim u roku od 48h, osvezi temu novim post-om;
Ukoliko se ne javis u roku od 5 dana, zatvoricemo slucaj.

Za vise informacija o pravilima Ambulante MyCity foruma: LINK

-------------------------------------------------------------------------------------





Arrow Korak 1
Idi na Start->Control panel-> Programs and Feauters i deinstaliraj sledeće stavke ukoliko ih ne koristiš:

Ask Toolbar
iLivid
Searchqu Toolbar
uTorrentBar Toolbar
YTD Toolbar v6.3






Arrow

Korak 2
Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 20 Sep 2010
  • Poruke: 31

ComboFix 12-10-04.02 - mihajlo 10/06/2012 22:35:44.1.1 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.895.140 [GMT 2:00]
Running from: c:\users\mihajlo\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\AutocompletePro
c:\program files\AutocompletePro\AcRemoteUpdate.exe
c:\program files\AutocompletePro\AutocompletePro.dll
c:\program files\AutocompletePro\InstTracker.exe
c:\program files\AutocompletePro\support@predictad.com\chrome.manifest
c:\program files\AutocompletePro\support@predictad.com\chrome\content\browserOverlay.xul
c:\program files\AutocompletePro\support@predictad.com\chrome\content\options.js
c:\program files\AutocompletePro\support@predictad.com\chrome\content\options.xul
c:\program files\AutocompletePro\support@predictad.com\chrome\content\utils.js
c:\program files\AutocompletePro\support@predictad.com\defaults\preferences\predictad.js
c:\program files\AutocompletePro\support@predictad.com\install.rdf
c:\program files\AutocompletePro\TaskScheduler.dll
c:\program files\AutocompletePro\unins000.dat
c:\program files\AutocompletePro\unins000.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-09-06 to 2012-10-06 )))))))))))))))))))))))))))))))
.
.
2012-10-06 20:51 . 2012-10-06 20:51 -------- d-----w- c:\users\mihajlo\AppData\Local\temp
2012-10-06 20:51 . 2012-10-06 20:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-26 17:18 . 2012-10-06 20:23 -------- d-----w- c:\program files\Common Files\Spigot
2012-09-21 10:44 . 2012-09-21 10:44 -------- d-----w- c:\programdata\YTD Video Downloader
2012-09-21 10:44 . 2012-09-21 10:44 -------- d-----w- c:\program files\GreenTree Applications
2012-09-10 13:27 . 2012-09-10 13:27 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-06 17:38 . 2012-05-10 16:10 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-06 17:38 . 2011-06-08 17:13 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-10 13:26 . 2012-08-08 21:06 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-10 13:26 . 2011-08-13 21:25 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13 . 2011-03-31 15:08 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2010-07-11 13:04 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2010-07-11 13:04 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2012-05-05 19:11 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-08-21 09:13 . 2010-07-11 13:04 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2010-07-11 13:04 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2010-07-11 13:13 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2010-07-11 13:03 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-08-18 20:48 . 2012-06-07 10:24 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{57779A9C-2B9D-47E5-84A7-9B9B23AC3D91}\offreg.dll
2011-04-14 16:26 . 2011-05-02 19:38 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\mihajlo\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\mihajlo\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\mihajlo\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mobile Partner"="c:\program files\HiSuite\HiSuite.exe" [2012-08-25 552328]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344]
"Domino"="c:\windows\Domino.exe" [2006-08-18 49152]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-08-21 4282728]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2012-04-17 651264]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"removeSearchqudatamngr"="RD" [X]
"removeSearchqutoolbar"="RD" [X]
.
c:\users\mihajlo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\mihajlo\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-25 26909544]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2010-7-11 295606]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-1-27 805392]
WG111v2 Smart Wizard Wireless Setting.lnk - c:\program files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2011-2-25 745472]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\SEARCH~1\SEARCH~1\datamngr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
"Google Update"="c:\users\mihajlo\AppData\Local\Google\Update\GoogleUpdate.exe" /c
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"Domino"=c:\windows\Domino.exe
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"Windows Mobile Device Center"=%windir%\WindowsMobile\wmdc.exe
"ZSSnp211"=c:\windows\ZSSnp211.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 HuaweiHiSuiteService.exe;HuaweiHiSuiteService.exe;c:\programdata\HandSetService\HuaweiHiSuiteService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [x]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [x]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [x]
R3 FXDrv32;FXDrv32;E:\FXDrv32.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [x]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
R3 wxpSvc;webcamXP Service;c:\program files\webcamXP 5\wService.exe [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe [x]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [x]
S2 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [x]
S2 Transbase TECDOC CD 1_2011 Service;Transbase TECDOC CD 1_2011 Service;d:\tecdoc_cd\1_2011\db\tbmux32.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [x]
S3 adatadrv;Autodata Protection Service;c:\windows\system32\DRIVERS\adatadrv.sys [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
S3 rt61x86;RT61 Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr61.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [x]
S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [x]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\Drivers\ZS211.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - AWTIIFOW
*Deregistered* - awtiifow
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-10 09:39]
.
2012-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-05-05 20:52]
.
2012-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-05-05 20:52]
.
2012-09-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-185401805-2569957762-567075351-1001Core.job
- c:\users\mihajlo\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 20:52]
.
2012-10-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-185401805-2569957762-567075351-1001UA.job
- c:\users\mihajlo\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-25 20:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.searchnu.com/406
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\users\mihajlo\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\mihajlo\AppData\Roaming\Mozilla\Firefox\Profiles\wkq6ydpp.default\
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://www.searchnu.com/406
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=390&systemid=406&sr=0&q=
FF - prefs.js: network.proxy.ftp - 137.110.190.156
FF - prefs.js: network.proxy.ftp_port - 9415
FF - prefs.js: network.proxy.http - 137.110.190.156
FF - prefs.js: network.proxy.http_port - 9415
FF - prefs.js: network.proxy.socks - 137.110.190.156
FF - prefs.js: network.proxy.socks_port - 9415
FF - prefs.js: network.proxy.ssl - 137.110.190.156
FF - prefs.js: network.proxy.ssl_port - 9415
FF - prefs.js: network.proxy.type - 1
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
Toolbar-10 - (no file)
Toolbar-!{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
WebBrowser-{88C7F2AA-F93F-432C-8F0E-B7D85967A527} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-AutocompletePro2_is1 - c:\program files\AutocompletePro\unins000.exe
AddRemove-Kalender - c:\windows\Uninstall_tkexe -kalender
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wxpSvc]
"ImagePath"="c:\program files\webcamXP 5\wService.exe /startedbyscm:5053B757-40E35B3B-webcamSRV"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-185401805-2569957762-567075351-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D1DBED89-FE49-C068-6733-0AEA381012F3}*]
"haoaeigimlflmdmo"=hex:65,61,63,63,66,6b,6a,6f,6d,6a,00,00
"iakpgdeaeigpmgiggf"=hex:6a,61,6f,6d,62,68,69,67,68,68,64,6b,6a,66,63,6d,68,63,
6b,67,00,00
"haaaijjmlaojocph"=hex:6a,61,6f,6d,62,68,69,67,68,68,64,6b,6a,66,63,6d,68,63,
6b,67,00,00
"haoaeigikkllphpd"=hex:65,61,63,63,66,6b,6a,6f,6d,6a,00,00
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-10-06 22:56:42
ComboFix-quarantined-files.txt 2012-10-06 20:56
.
Pre-Run: 25,151,168,512 bytes free
Post-Run: 26,346,942,464 bytes free
.
- - End Of File - - 6396BE4528CF954B2580967A7EE6D6EC

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Izvini na čekanju, kolega je imao nekih obaveza pa ti nije mogao odgovoriti.


Arrow

Otvori Notepad i iskopiraj sljedeći tekst:

Folder::
c:\program files\Common Files\Spigot
C:\Program Files\Searchqu Toolbar

RegNull::
[HKEY_USERS\S-1-5-21-185401805-2569957762-567075351-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D1DBED89-FE49-C068-6733-0AEA381012F3}*]

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"removeSearchqudatamngr"=-
"removeSearchqutoolbar"=-


Snimi na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sljedećoj poruci log koji bude bio napravljen na kraju čišćenja/skeniranja.

offline
  • Pridružio: 20 Sep 2010
  • Poruke: 31

ComboFix 12-10-08.01 - MikiMoca 10/08/2012 10:11:47.1.1 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.895.350 [GMT 2:00]
Running from: c:\users\MikiMoca\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\MikiMoca\AppData\Roaming\vso_ts_preview.xml
.
.
((((((((((((((((((((((((( Files Created from 2012-09-08 to 2012-10-08 )))))))))))))))))))))))))))))))
.
.
2012-10-08 07:20 . 2009-09-02 10:44 102439 ----a-w- c:\windows\system32\sipr3260.dll
2012-10-08 07:20 . 2009-09-02 10:44 217127 ----a-w- c:\windows\system32\drv43260.dll
2012-10-08 07:20 . 2009-09-02 10:44 65602 ----a-w- c:\windows\system32\cook3260.dll
2012-10-08 07:20 . 2009-09-02 10:44 208935 ----a-w- c:\windows\system32\drv33260.dll
2012-10-08 07:20 . 2009-09-02 10:44 176165 ----a-w- c:\windows\system32\drv23260.dll
2012-10-08 07:20 . 2009-09-02 10:44 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2012-10-08 07:20 . 2009-09-02 10:44 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2012-10-08 07:20 . 2012-10-08 07:20 -------- d-----w- c:\program files\VSO
2012-10-07 23:15 . 2012-10-07 13:25 -------- d-----w- c:\windows\Panther
2012-10-07 23:15 . 2012-10-07 23:15 -------- d-----w- C:\Boot
2012-10-07 22:18 . 2012-10-07 22:18 0 ----a-w- c:\windows\ativpsrm.bin
2012-10-07 22:02 . 2012-10-07 22:02 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2012-10-07 22:02 . 2012-10-07 22:02 2876528 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2012-10-07 21:51 . 2012-10-07 21:51 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2012-10-07 21:51 . 2012-10-07 21:51 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-10-07 21:47 . 2012-10-08 07:18 -------- d-----w- c:\program files\Common Files\Real
2012-10-07 21:47 . 2012-10-07 21:47 -------- d-----w- c:\program files\Real
2012-10-07 20:19 . 2012-10-07 20:19 -------- d-----w- c:\programdata\RoboForm
2012-10-07 20:18 . 2012-10-07 20:18 -------- d-----w- c:\program files\Siber Systems
2012-10-07 20:18 . 2012-08-21 09:13 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-07 20:18 . 2012-08-21 09:13 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-07 20:17 . 2012-08-21 09:13 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-10-07 20:17 . 2012-08-21 09:13 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-07 20:17 . 2012-08-21 09:13 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-07 20:17 . 2012-08-21 09:13 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-07 20:16 . 2012-08-21 09:12 41224 ----a-w- c:\windows\avastSS.scr
2012-10-07 20:16 . 2012-08-21 09:12 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-10-07 19:55 . 2012-10-07 19:55 -------- d-----w- c:\windows\Sun
2012-10-07 19:54 . 2012-10-07 19:54 -------- d-----w- c:\program files\Common Files\Java
2012-10-07 19:53 . 2012-10-07 19:53 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-10-07 19:53 . 2012-10-07 19:53 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-10-07 19:53 . 2012-10-07 19:53 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-10-07 19:52 . 2012-10-07 19:52 -------- d-----w- c:\program files\Java
2012-10-07 19:24 . 2012-09-19 10:10 31584 ----a-w- c:\windows\system32\TURegOpt.exe
2012-10-07 19:24 . 2012-09-19 10:10 21344 ----a-w- c:\windows\system32\authuitu.dll
2012-10-07 19:23 . 2012-10-07 19:27 -------- d-----w- c:\program files\TuneUp Utilities 2013
2012-10-07 19:22 . 2012-10-07 19:23 -------- d-----w- c:\programdata\TuneUp Software
2012-10-07 19:22 . 2012-10-08 07:26 -------- d-sh--w- c:\programdata\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2012-10-07 19:22 . 2012-10-07 19:22 -------- d--h--w- c:\programdata\Common Files
2012-10-07 18:41 . 2012-10-07 18:41 -------- d-----w- c:\program files\PowerISO
2012-10-07 18:31 . 2012-10-07 18:31 -------- d-----w- c:\programdata\Nero
2012-10-07 18:30 . 2012-10-07 18:31 -------- d-----w- c:\program files\Common Files\Nero
2012-10-07 18:30 . 2012-10-07 18:30 -------- d-----w- c:\program files\Nero
2012-10-07 18:19 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2012-10-07 18:18 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2012-10-07 18:17 . 2008-10-15 04:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2012-10-07 18:17 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2012-10-07 18:16 . 2007-05-16 14:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2012-10-07 17:24 . 2012-10-07 17:24 -------- d-----w- c:\program files\Common Files\Adobe
2012-10-07 16:55 . 2009-07-01 20:43 762112 ----a-w- c:\windows\system32\drivers\adatadrv.sys
2012-10-07 16:49 . 2012-10-07 17:14 -------- d-----w- C:\ADCDA2
2012-10-07 16:44 . 2012-10-07 16:44 -------- d-----w- C:\ADCDTEMP
2012-10-07 16:44 . 2012-10-07 16:44 -------- d-----w- C:\ADSecurity
2012-10-07 16:44 . 2007-04-20 01:05 660384 ----a-w- c:\windows\system32\ChilkatUtil.dll
2012-10-07 16:44 . 2007-04-20 01:04 926624 ----a-w- c:\windows\system32\ChilkatCrypt2.dll
2012-10-07 16:44 . 2007-04-20 01:04 856992 ----a-w- c:\windows\system32\ChilkatCert.dll
2012-10-07 16:44 . 2007-10-09 16:11 436736 ----a-w- c:\windows\system32\Autoserv.exe
2012-10-07 16:44 . 2012-10-07 16:44 -------- d-----w- c:\program files\Common Files\SafeNet Sentinel
2012-10-07 16:43 . 2012-10-07 16:43 -------- d-----w- c:\windows\Downloaded Installations
2012-10-07 16:34 . 2009-05-05 18:21 100352 ----a-w- c:\windows\system32\ToleCom2.dll
2012-10-07 16:31 . 2012-10-07 16:37 -------- d-----w- c:\program files\Tolerance Data
2012-10-07 16:07 . 2012-10-07 21:57 -------- d-----w- c:\program files\Webteh
2012-10-07 16:03 . 2012-10-07 16:03 -------- d-----w- c:\program files\Conduit
2012-10-07 16:02 . 2012-10-07 16:02 -------- d-----w- c:\program files\BitTorrent
2012-10-07 15:44 . 2012-10-07 15:44 -------- d-----w- c:\programdata\ATI
2012-10-07 15:27 . 2012-10-07 15:27 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-10-07 15:26 . 2012-10-07 15:26 -------- d-----w- c:\program files\Microsoft Sync Framework
2012-10-07 15:26 . 2012-10-07 15:26 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-10-07 15:26 . 2012-10-07 15:26 -------- d-----w- c:\program files\ATI
2012-10-07 15:25 . 2012-10-07 15:43 -------- d-----w- c:\program files\ATI Technologies
2012-10-07 15:24 . 2012-10-07 15:24 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-10-07 15:22 . 2012-10-07 15:22 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-10-07 15:22 . 2012-10-07 16:28 -------- d-----w- c:\programdata\Microsoft Help
2012-10-07 15:20 . 2012-10-07 15:20 -------- d-----r- C:\MSOCache
2012-10-07 15:07 . 2012-10-07 15:07 -------- d-----w- c:\program files\Common Files\Skype
2012-10-07 15:07 . 2012-10-07 15:07 -------- d-----r- c:\program files\Skype
2012-10-07 15:06 . 2012-10-07 15:07 -------- d-----w- c:\programdata\Skype
2012-10-07 15:01 . 2012-10-07 15:01 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-07 15:01 . 2012-10-07 15:01 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-07 14:54 . 2012-10-07 14:54 -------- d-----w- c:\windows\system32\Macromed
2012-10-07 14:28 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-10-07 14:28 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-10-07 14:28 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-10-07 14:28 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-10-07 14:27 . 2012-06-02 13:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-10-07 14:27 . 2012-06-02 13:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-10-07 14:20 . 2012-10-07 14:20 -------- d-----w- c:\windows\PCHEALTH
2012-10-07 14:20 . 2012-10-07 14:21 -------- d-----w- c:\program files\Windows Live
2012-10-07 14:16 . 2012-10-07 15:26 -------- d-----w- c:\program files\Microsoft.NET
2012-10-07 14:16 . 2009-11-25 19:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-10-07 14:16 . 2009-11-25 19:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-10-07 14:16 . 2009-11-25 19:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-10-07 14:16 . 2009-11-25 19:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-10-07 14:16 . 2009-11-25 19:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-10-07 14:13 . 2010-05-23 10:11 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2012-10-07 14:13 . 2010-05-23 10:11 3181568 ----a-w- c:\windows\system32\mf.dll
2012-10-07 14:13 . 2010-05-23 10:15 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2012-10-07 14:09 . 2012-10-07 14:09 -------- d-----w- c:\program files\Common Files\Windows Live
2012-10-07 14:08 . 2012-09-18 22:59 6980552 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{116E5899-C9FC-4CDA-AC75-99CEDE43F5AB}\mpengine.dll
2012-10-07 14:08 . 2012-05-31 10:25 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-10-07 14:00 . 2012-10-07 14:01 -------- d-----w- c:\program files\Google
2012-10-07 13:59 . 2012-10-07 20:17 -------- d-sh--w- c:\windows\Installer
2012-10-07 13:59 . 2012-10-07 20:16 -------- d-----w- c:\programdata\AVAST Software
2012-10-07 13:59 . 2012-10-07 20:16 -------- d-----w- c:\program files\AVAST Software
2012-10-07 13:53 . 2012-10-07 13:53 -------- d-----w- c:\program files\Opera
2012-10-07 13:48 . 2005-10-27 13:06 356096 ----a-w- c:\windows\system32\drivers\rt61.sys
2012-10-07 13:48 . 2005-08-26 21:38 8192 ----a-w- c:\windows\system32\drivers\RT2661.bin
2012-10-07 13:48 . 2005-08-26 21:38 8192 ----a-w- c:\windows\system32\drivers\RT2561s.bin
2012-10-07 13:48 . 2005-08-26 21:38 8192 ----a-w- c:\windows\system32\drivers\RT2561.bin
2012-10-07 13:48 . 2005-08-25 09:15 81920 ----a-w- c:\windows\system32\Install6x.dll
2012-10-07 13:48 . 2005-05-17 14:24 311296 ----a-w- c:\windows\system32\AegisI5.exe
2012-10-07 13:47 . 2012-10-07 13:47 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2012-10-07 13:47 . 2012-10-07 13:47 -------- d-----w- c:\program files\Gigabyte
2012-10-07 13:47 . 2012-10-07 13:47 -------- d-----w- c:\program files\Common Files\InstallShield
2012-10-07 13:30 . 2012-10-07 18:48 -------- d-----w- c:\windows\system32\wbem\Performance
2012-10-07 13:25 . 2012-10-07 14:27 -------- d-----w- c:\users\MikiMoca
2012-10-07 13:23 . 2012-10-07 13:23 -------- d-----w- C:\Recovery
2012-09-12 14:07 . 2012-09-12 14:07 58368 ----a-w- c:\windows\system32\sirenacm.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-26 17:08 . 2012-07-26 17:08 862664 ----a-w- c:\windows\system32\msvcr110.dll
2012-07-26 17:08 . 2012-07-26 17:08 534480 ----a-w- c:\windows\system32\msvcp110.dll
2012-07-26 17:08 . 2012-07-26 17:08 251864 ----a-w- c:\windows\system32\vccorlib110.dll
2012-07-26 17:08 . 2012-07-26 17:08 153536 ----a-w- c:\windows\system32\atl110.dll
2012-07-26 17:08 . 2012-07-26 17:08 115656 ----a-w- c:\windows\system32\vcomp110.dll
2012-07-17 12:49 . 2012-07-17 12:49 209648 ----a-w- c:\windows\system32\LIVESSP.DLL
2012-07-17 12:37 . 2012-07-17 12:37 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-10-07 20:18 . 2012-10-07 20:19 1597368 ----a-w- c:\program files\opera\program\plugins\rf-np-plugin.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\MikiMoca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\MikiMoca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\MikiMoca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\MikiMoca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2012-10-07 96056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344]
"Domino"="c:\windows\Domino.exe" [2006-08-18 49152]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
.
c:\users\MikiMoca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\MikiMoca\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-25 26909544]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GN-WP01GS Utility.lnk - c:\program files\Gigabyte\Gigabyte WP01GS Wireless PCI Adapter SoftAP\Installer\WINXP\RaUI.exe [2012-10-7 720896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 FXDrv32;FXDrv32;F:\FXDrv32.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [x]
S3 adatadrv;Autodata Protection Service;c:\windows\system32\DRIVERS\adatadrv.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [x]
S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [x]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\Drivers\ZS211.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-07 14:00]
.
2012-10-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-07 14:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3225826
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Show avast! EasyPass Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1414191598-815891449-962465364-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-1414191598-815891449-962465364-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(2888)
c:\users\MikiMoca\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Completion time: 2012-10-08 10:25:54 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-08 08:25
.
Pre-Run: 49,068,163,072 bytes free
Post-Run: 50,716,008,448 bytes free
.
- - End Of File - - 210A1C8F8B3958C1E065DC3E038537C8

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Da li si ComboFix skriptu pustio na Windows korisničkom nalogu Mihajlo ili MikiMoca?

Kakvo je sada stanje?


Arrow

Spakuj u ZIP, RAR ili 7Z arhivu sljedeći folder:

C:\Qoobox

i pošalji ga preko sljedećeg linka:

http://www.mycity.rs/ambulanta-upload.php


Javi kada to uradiš i sačekaj dalja uputstva.

offline
  • Pridružio: 20 Sep 2010
  • Poruke: 31

To je moj racunar samo je promenjeno ime, poslacu skriptu mogu tek veceras posle deset

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

goranzeljic ::To je moj racunar samo je promenjeno ime, poslacu skriptu mogu tek veceras posle deset

Jesi li uradio ono što sam ti sinoć rekao da uradiš? Ako jesi, samo zapakuj folder koji sam ti rekao i pošalji ga preko linka koji sam ti dao.

offline
  • Pridružio: 20 Sep 2010
  • Poruke: 31

Napisano: 08 Okt 2012 17:34

Jesam uradio sam poslacu ti veceras sada nisam pored racunara nisam kuci

Dopuna: 08 Okt 2012 22:21

Poslao sam. Evo ceo dan mi je aktivan mesenger i nijednom se nije izlogovao sto je bio cest slucaj, i u opcijama gde mogu da stikliram da mi prikazuje dali sam ulogovan sa vise mesta, sada moze to da se uradi nakon ispravke koju si mi poslao, dok je pre toga bilo sivo i nije se moglo ni stiklirati ni destiklirati. Sada cu pratiti situaciju nadam se da ce biti dobro

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10621
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

Arrow

Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti i 7 koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sljedeće:

ComboFix /Uninstall

Primjeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.



Arrow

Posjeti temu Testirajte da li vam je pretraživač ranjiv, pročitaj i isprati link koji stoji u njoj.



Arrow

Preporučujem ti da instaliraš Service Pack 1 za tvoj Windows 7 operativni sistem.
Možeš ga preuzeti sa ovog linka:

Windows 7 SP1 x86



Arrow

Preporučujem da za zaštitu USB memorijskih uređaja koristiš MCShield.
Nema nikakve veze sa antivirus-om tj. neće ometati njegov rad, a pokazao se kao jedan od najboljih vida zaštite od malware-a koji se prenosi putem USB mem. uređaja.


Home Page MCShield-a: http://amf.mycity.rs/mcshield/

Više o MCShield-u možeš saznati u ovoj temi: http://www.mycity.rs/MyCity-Laboratorija/MCShield-v2.html

Facebook stranica MCShield-a: http://www.facebook.com/MCShield



Pozdrav.

Ko je trenutno na forumu
 

Ukupno su 836 korisnika na forumu :: 44 registrovanih, 6 sakrivenih i 786 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Sale, A.R.Chafee.Jr., AF-1, alexa_pg, Apok, Bane san, Boris90, Cirkon, crnitrn, cvrle312, dankisha, dragon986, dragonserbia, Drug pukovnik, Duško, elenemste, goxsys, Hoegaarden, HrcAk47, ikan, ivan1973, Koridor 11, MarKhan, MB120mm, milimoj, mnn2, nenad81, pajkan, pavle_pzs, pedja63, pein, riva, RJ, rovac, Snorks, Srki94, StefanNBG90, Toni, Toper, vlvl, vobo, voja64, x9, zodiac94