NOD32 problem

1

NOD32 problem

offline
  • Pridruio: 26 Avg 2008
  • Poruke: 48

Stalno mi se javlja kada instaliram NOD 32 neki trojanac, dole desno i ne moze da nestane..stalno kaze obrisi ga, a nemam gde ili posle restarta ce nestati to..stalno treperi i ne mogu da ga se resim..molim vas pomozite kako da ga se resim??

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master uitelj
  • Pridruio: 27 Avg 2005
  • Poruke: 8519
  • Gde ivi: Novi Beograd

Postupi kako se ovde kaze:

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

i neko ce ti pomoci.

offline
  • Pridruio: 26 Avg 2008
  • Poruke: 48

evo HIJACTHIS...imam nod 32 i stalno mi iskace u donjem desnom uglu neki prozor koji prijavljuje trojana i stalno treperi i nevidljiv postaje..ne znam sta da radim evo log file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:27:29 AM, on 11/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\WINDOWS\vsnp2uvc.exe
C:\WINDOWS\tsnp2uvc.exe
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Kvik\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [snp2uvc] C:\WINDOWS\vsnp2uvc.exe
O4 - HKLM\..\Run: [tsnp2uvc] C:\WINDOWS\tsnp2uvc.exe
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINCINEMAMGR] "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\kamsoft.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Gadwin PrintScreen Pro] C:\Program Files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe /nosplash
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6813 bytes

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridruio: 15 Jun 2007
  • Poruke: 5572

Pozdrav.. Ja cu preuzeti tvoj slucaj Wink

Uradi sledece :


1.
Privremeno iskljuci Nod32



2.

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridruio: 26 Avg 2008
  • Poruke: 48

ComboFix 08-11-24.01 - Kvik 2008-11-25 9:28:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2460 [GMT 1:00]
Running from: c:\documents and settings\Kvik\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\abk.bat
C:\autorun.inf
c:\documents and settings\Kvik\Desktop\predmeti\CS111\cs111\4. nedelja\filmovi\Desktop_.ini
C:\ij.bat
c:\windows\system32\gasretyw0.dll
c:\windows\system32\kamsoft.exe
D:\abk.bat
D:\Autorun.inf
D:\ij.bat

.
((((((((((((((((((((((((( Files Created from 2008-10-25 to 2008-11-25 )))))))))))))))))))))))))))))))
.

2008-11-25 00:33 . 2008-11-25 00:33 <DIR> d-------- c:\program files\Yahoo!
2008-11-25 00:33 . 2008-11-25 00:33 <DIR> d-------- c:\program files\CCleaner
2008-11-24 18:50 . 2008-11-24 18:50 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-24 18:40 . 2008-03-03 14:25 5,702 --ah----- c:\windows\nod32restoretemdono.reg
2008-11-24 18:40 . 2008-03-03 18:21 568 --ah----- c:\windows\nod32fixtemdono.reg
2008-11-24 18:40 . 2008-11-24 18:40 268 --ah----- C:\sqmdata01.sqm
2008-11-24 18:40 . 2008-11-24 18:40 244 --ah----- C:\sqmnoopt01.sqm
2008-11-24 15:49 . 2008-11-24 15:49 <DIR> d-------- c:\program files\ESET
2008-11-24 14:33 . 2008-11-24 14:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-23 11:34 . 2008-11-23 11:34 <DIR> d---s---- c:\documents and settings\Kvik\UserData
2008-11-23 11:19 . 2008-11-23 11:19 <DIR> d-------- c:\documents and settings\Kvik\.netbeans-registration
2008-11-23 11:18 . 2008-11-23 11:19 <DIR> d-------- c:\program files\glassfish-v2ur2
2008-11-23 11:16 . 2008-11-23 11:19 <DIR> d-------- c:\program files\NetBeans 6.1
2008-11-23 11:15 . 2008-11-23 11:15 <DIR> d-------- c:\documents and settings\Kvik\.nbi
2008-11-23 11:13 . 2002-02-24 20:30 260,096 --------- c:\windows\system32\RICHTX32.OCX
2008-11-23 11:13 . 2000-05-22 00:00 140,488 --------- c:\windows\system32\COMDLG32.OCX
2008-11-23 11:12 . 2008-11-23 11:12 <DIR> d-------- c:\program files\Sybase
2008-11-23 11:12 . 2008-11-23 11:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\PowerDesigner 12
2008-11-23 11:02 . 2008-11-23 11:02 <DIR> d-------- c:\program files\Bonjour
2008-11-23 10:57 . 2008-11-23 10:57 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-11-23 10:56 . 2008-11-23 10:56 <DIR> d-------- c:\documents and settings\Kvik\Application Data\Logitech
2008-11-23 10:56 . 2008-11-23 10:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\LogiShrd
2008-11-23 10:55 . 2008-11-23 10:55 <DIR> d-------- c:\program files\Logitech
2008-11-23 10:55 . 2008-11-23 10:55 <DIR> d-------- c:\program files\Common Files\Logishrd
2008-11-23 10:55 . 2008-11-23 10:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\Logitech
2008-11-23 10:55 . 2007-11-15 10:06 301,656 --a------ c:\windows\system32\BtCoreIf.dll
2008-11-23 10:55 . 2007-11-15 10:07 170,512 --a------ c:\windows\system32\kemutb.dll
2008-11-23 10:55 . 2007-11-15 10:07 141,840 --a------ c:\windows\system32\KemUtil.dll
2008-11-23 10:55 . 2007-11-15 10:07 117,264 --a------ c:\windows\system32\KemWnd.dll
2008-11-23 10:55 . 2007-11-15 10:07 76,304 --a------ c:\windows\system32\KemXML.dll
2008-11-23 10:55 . 2008-11-23 10:55 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-23 10:55 . 2008-11-23 10:55 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-11-23 10:55 . 2008-11-23 10:55 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-11-22 19:46 . 2008-11-22 19:46 <DIR> d-------- c:\documents and settings\Kvik\Application Data\2K Sports
2008-11-22 19:37 . 2008-11-22 19:45 <DIR> d-------- c:\program files\NBA 2K9
2008-11-22 19:24 . 2008-11-22 19:32 <DIR> d-------- c:\program files\nba
2008-11-22 15:48 . 2008-11-22 18:45 <DIR> d-------- c:\documents and settings\Kvik\Contacts
2008-11-22 14:44 . 2008-11-22 14:44 <DIR> d-------- c:\documents and settings\Kvik\Application Data\Media Player Classic
2008-11-22 14:37 . 2008-11-25 09:22 <DIR> d-------- c:\documents and settings\Kvik\Application Data\skypePM
2008-11-22 14:37 . 2008-11-22 14:37 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-11-22 14:11 . 2004-08-04 02:07 221,184 --a------ c:\windows\system32\wmpns.dll
2008-11-22 14:08 . 2008-11-22 14:08 268 --ah----- C:\sqmdata00.sqm
2008-11-22 14:08 . 2008-11-22 14:08 244 --ah----- C:\sqmnoopt00.sqm
2008-11-22 14:07 . 2008-11-22 14:07 <DIR> d-------- c:\program files\MSBuild
2008-11-22 14:07 . 2008-11-22 14:07 <DIR> d-------- c:\program files\Microsoft Works
2008-11-22 14:07 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-11-22 14:04 . 2008-11-22 14:04 <DIR> d-------- c:\windows\SHELLNEW
2008-11-22 14:04 . 2008-11-22 14:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-22 14:03 . 2008-11-22 14:03 <DIR> dr-h----- C:\MSOCache
2008-11-22 14:02 . 2008-11-22 14:02 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-11-22 14:02 . 2008-11-22 14:02 <DIR> d-------- c:\program files\Gadwin Systems
2008-11-22 14:00 . 2008-11-22 14:00 107,888 --a------ c:\windows\system32\CmdLineExt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 08:23 --------- d-----w c:\documents and settings\Kvik\Application Data\Skype
2008-11-25 08:22 85,504 --sh--r c:\windows\system32\gasretyw1.dll
2008-11-24 17:50 --------- d-----w c:\program files\Java
2008-11-23 22:47 --------- d-----w c:\documents and settings\Kvik\Application Data\LimeWire
2008-11-23 10:12 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-23 10:01 --------- d-----w c:\program files\Common Files\Adobe
2008-11-22 14:44 --------- d-----w c:\documents and settings\All Users\Application Data\InterVideo
2008-11-22 12:38 --------- d-----w c:\program files\Winamp
2008-11-22 12:36 --------- d-----w c:\program files\VideoLAN
2008-11-22 12:36 --------- d-----w c:\documents and settings\Kvik\Application Data\vlc
2008-11-22 12:35 --------- d-----w c:\program files\Sun
2008-11-22 12:35 --------- d-----w c:\program files\Skype
2008-11-22 12:35 --------- d-----w c:\program files\LimeWire
2008-11-22 12:35 --------- d-----w c:\program files\Common Files\Skype
2008-11-22 12:35 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-22 12:34 --------- d-----w c:\program files\Common Files\Java
2008-11-22 12:32 --------- d-----w c:\program files\MSN Messenger
2008-11-22 12:27 --------- d-----w c:\program files\DAEMON Tools Lite
2008-11-22 12:24 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-11-22 12:24 --------- d-----w c:\documents and settings\Kvik\Application Data\DAEMON Tools
2008-11-22 12:23 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-11-22 12:22 --------- d-----w c:\program files\CyberLink
2008-11-22 12:21 --------- d-----w c:\program files\InterVideo
2008-11-22 12:21 --------- d-----w c:\program files\Common Files\InterVideo
2008-11-22 12:21 --------- d-----w c:\documents and settings\Kvik\Application Data\Intervideo
2008-11-22 12:19 --------- d-----w c:\program files\MSI
2008-11-22 12:19 --------- d-----w c:\program files\Common Files\SNP2UVC
2008-11-22 12:19 --------- d-----w c:\documents and settings\Kvik\Application Data\InstallShield
2008-11-22 12:17 --------- d-----w c:\program files\Samsung ML-2010 Series
2008-11-22 12:17 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-22 12:13 --------- d-----w c:\program files\My Company Name
2008-11-22 12:04 315,392 ----a-w c:\windows\HideWin.exe
2008-11-22 12:04 --------- d-----w c:\program files\Realtek
2008-11-22 11:59 --------- d-----w c:\program files\microsoft frontpage
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-08-12 21741864]
"Gadwin PrintScreen Pro"="c:\program files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" [2008-09-05 516096]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-25 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-25 86016]
"Samsung Common SM"="c:\windows\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 372736]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2007-05-15 675840]
"tsnp2uvc"="c:\windows\tsnp2uvc.exe" [2007-04-24 237568]
"Home Theater SchSvr"="c:\program files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2004-09-29 106496]
"WINCINEMAMGR"="c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe" [2004-09-29 192512]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-24 136600]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-05-14 35328]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 1447168]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-06-25 c:\windows\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 c:\windows\KHALMNPR.Exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-23 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 10:10 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_03\\bin\\java.exe"=
"c:\\Program Files\\MSI\\MyGuard Live\\MyGuard Live.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-08-18 34312]
R3 Cap713x;Cap713x Video Capture;c:\windows\system32\DRIVERS\Cap713x.sys [2008-11-22 751104]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\l1e51x86.sys [2008-11-22 36864]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe /s c:\windows\nod32fixtemdono.reg [2004-08-04 3584]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8cc6ce82-b88f-11dd-89b1-00221591a466}]
\Shell\AutoRun\command - F:\abk.bat
\Shell\explore\Command - F:\abk.bat
\Shell\open\Command - F:\abk.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb4118a0-b896-11dd-bab8-806d6172696f}]
\Shell\AutoRun\command - F:\abk.bat
\Shell\explore\Command - F:\abk.bat
\Shell\open\Command - F:\abk.bat

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fed40b85-b890-11dd-89b2-00221591a466}]
\Shell\AutoRun\command - F:\abk.bat
\Shell\explore\Command - F:\abk.bat
\Shell\open\Command - F:\abk.bat

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Kvik\Application Data\Mozilla\Firefox\Profiles\zqvlkfz7.default\
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-11-25 09:29:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(768-)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2008-11-25 9:30:01
ComboFix-quarantined-files.txt 2008-11-25 08:29:58

Pre-Run: 47,373,795,328 bytes free
Post-Run: 47,393,177,600 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

224





-Nisam upalio nod 32, da upalim??

Dopuna: 25 Nov 2008 9:40

Diarno uspeo sam..ne javlja se nisa:))..jel mozes da mi objasnis sta je to u stvari bilo??? Hvala ti puno, puno..

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridruio: 15 Jun 2007
  • Poruke: 5572

Jos nismo zavrsili. Zarazio si se preko nekog USB uredjaja koji ti vidis kao drive F.
Moramo pocistiti ostatak malware-a i srediti USB.
Zato, uradi sledece korake:

1.

Otvoriti Notepad i iskopirati sledeci tekst:

File::
c:\windows\system32\gasretyw1.dll

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fed40b85-b890-11dd-89b2-00221591a466}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb4118a0-b896-11dd-bab8-806d6172696f}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8cc6ce82-b88f-11dd-89b1-00221591a466}]


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.


2.

Skini sledeci program - http://amf.mycity.rs/personal/bobby/USB_blocker/usb_blocker.exe
- startuj ga i odaberi opciju Auto block
- ubaci USB stick u komp i sacekaj koji sekund (recimo 5-10 sekundi)
- program je sada uradio analizu sticka (vidi se u donjem delu programa, u logu)
- gore levo klikni duplo na slovo koje oznacava particiju, tj. tvoj USB stick
- dole kraj sata ce se pojaviti poruka da smes da izvadis USB stick iz kompa
- ne gasi program, vec ubaci sledeci USB stick i za njega isto sacekaj par sekundi, i tako redom za sve stickove, MP3 plejere, mobilni
- zapamti kojim redom su ubacivani stickovi

Kada sve to zavrsis, log u donjem delu programa ce sadrzati sve podatke koji su meni potrebni da bih video koji stick je zarazen.
Klikni desnim dugmetom misa na log/izvestaj i odaberi Save log.
Automatski ce se otvoriti Notepad i u njemu izvestaj.
Iskopiraj mi taj izvestaj ovde na forum.

offline
  • Pridruio: 26 Avg 2008
  • Poruke: 48

ovo je resenje prvog zadatka:

ComboFix 08-11-24.01 - Kvik 2008-11-25 23:30:15.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1714 [GMT 1:00]
Running from: c:\documents and settings\Kvik\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kvik\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


FILE ::
c:\windows\system32\gasretyw1.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\gasretyw1.dll

.
((((((((((((((((((((((((( Files Created from 2008-10-25 to 2008-11-25 )))))))))))))))))))))))))))))))
.

2008-11-25 09:56 . 2008-11-25 09:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-25 00:33 . 2008-11-25 00:33 <DIR> d-------- c:\program files\Yahoo!
2008-11-25 00:33 . 2008-11-25 00:33 <DIR> d-------- c:\program files\CCleaner
2008-11-24 18:50 . 2008-11-24 18:50 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-24 18:40 . 2008-03-03 14:25 5,702 --ah----- c:\windows\nod32restoretemdono.reg
2008-11-24 18:40 . 2008-03-03 18:21 568 --ah----- c:\windows\nod32fixtemdono.reg
2008-11-24 18:40 . 2008-11-24 18:40 268 --ah----- C:\sqmdata01.sqm
2008-11-24 18:40 . 2008-11-24 18:40 244 --ah----- C:\sqmnoopt01.sqm
2008-11-24 15:49 . 2008-11-24 15:49 <DIR> d-------- c:\program files\ESET
2008-11-24 14:33 . 2008-11-24 14:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-23 11:34 . 2008-11-23 11:34 <DIR> d---s---- c:\documents and settings\Kvik\UserData
2008-11-23 11:19 . 2008-11-23 11:19 <DIR> d-------- c:\documents and settings\Kvik\.netbeans-registration
2008-11-23 11:18 . 2008-11-23 11:19 <DIR> d-------- c:\program files\glassfish-v2ur2
2008-11-23 11:16 . 2008-11-23 11:19 <DIR> d-------- c:\program files\NetBeans 6.1
2008-11-23 11:15 . 2008-11-23 11:15 <DIR> d-------- c:\documents and settings\Kvik\.nbi
2008-11-23 11:13 . 2002-02-24 20:30 260,096 --------- c:\windows\system32\RICHTX32.OCX
2008-11-23 11:13 . 2000-05-22 00:00 140,488 --------- c:\windows\system32\COMDLG32.OCX
2008-11-23 11:12 . 2008-11-23 11:12 <DIR> d-------- c:\program files\Sybase
2008-11-23 11:12 . 2008-11-23 11:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\PowerDesigner 12
2008-11-23 11:02 . 2008-11-23 11:02 <DIR> d-------- c:\program files\Bonjour
2008-11-23 10:57 . 2008-11-23 10:57 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-11-23 10:56 . 2008-11-23 10:56 <DIR> d-------- c:\documents and settings\Kvik\Application Data\Logitech
2008-11-23 10:56 . 2008-11-23 10:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\LogiShrd
2008-11-23 10:55 . 2008-11-23 10:55 <DIR> d-------- c:\program files\Logitech
2008-11-23 10:55 . 2008-11-23 10:55 <DIR> d-------- c:\program files\Common Files\Logishrd
2008-11-23 10:55 . 2008-11-23 10:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\Logitech
2008-11-23 10:55 . 2007-11-15 10:06 301,656 --a------ c:\windows\system32\BtCoreIf.dll
2008-11-23 10:55 . 2007-11-15 10:07 170,512 --a------ c:\windows\system32\kemutb.dll
2008-11-23 10:55 . 2007-11-15 10:07 141,840 --a------ c:\windows\system32\KemUtil.dll
2008-11-23 10:55 . 2007-11-15 10:07 117,264 --a------ c:\windows\system32\KemWnd.dll
2008-11-23 10:55 . 2007-11-15 10:07 76,304 --a------ c:\windows\system32\KemXML.dll
2008-11-23 10:55 . 2008-11-23 10:55 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-23 10:55 . 2008-11-23 10:55 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-11-23 10:55 . 2008-11-23 10:55 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-11-22 19:46 . 2008-11-22 19:46 <DIR> d-------- c:\documents and settings\Kvik\Application Data\2K Sports
2008-11-22 19:37 . 2008-11-22 19:45 <DIR> d-------- c:\program files\NBA 2K9
2008-11-22 19:24 . 2008-11-22 19:32 <DIR> d-------- c:\program files\nba
2008-11-22 15:48 . 2008-11-22 18:45 <DIR> d-------- c:\documents and settings\Kvik\Contacts
2008-11-22 14:44 . 2008-11-22 14:44 <DIR> d-------- c:\documents and settings\Kvik\Application Data\Media Player Classic
2008-11-22 14:37 . 2008-11-25 16:01 <DIR> d-------- c:\documents and settings\Kvik\Application Data\skypePM
2008-11-22 14:37 . 2008-11-22 14:37 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-11-22 14:11 . 2004-08-04 02:07 221,184 --a------ c:\windows\system32\wmpns.dll
2008-11-22 14:08 . 2008-11-22 14:08 268 --ah----- C:\sqmdata00.sqm
2008-11-22 14:08 . 2008-11-22 14:08 244 --ah----- C:\sqmnoopt00.sqm
2008-11-22 14:07 . 2008-11-22 14:07 <DIR> d-------- c:\program files\MSBuild
2008-11-22 14:07 . 2008-11-22 14:07 <DIR> d-------- c:\program files\Microsoft Works
2008-11-22 14:07 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-11-22 14:04 . 2008-11-22 14:04 <DIR> d-------- c:\windows\SHELLNEW
2008-11-22 14:04 . 2008-11-22 14:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-22 14:03 . 2008-11-22 14:03 <DIR> dr-h----- C:\MSOCache
2008-11-22 14:02 . 2008-11-22 14:02 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-11-22 14:02 . 2008-11-22 14:02 <DIR> d-------- c:\program files\Gadwin Systems
2008-11-22 14:00 . 2008-11-22 14:00 107,888 --a------ c:\windows\system32\CmdLineExt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 22:22 --------- d-----w c:\documents and settings\Kvik\Application Data\Skype
2008-11-24 17:50 --------- d-----w c:\program files\Java
2008-11-23 22:47 --------- d-----w c:\documents and settings\Kvik\Application Data\LimeWire
2008-11-23 10:12 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-23 10:01 --------- d-----w c:\program files\Common Files\Adobe
2008-11-22 14:44 --------- d-----w c:\documents and settings\All Users\Application Data\InterVideo
2008-11-22 12:38 --------- d-----w c:\program files\Winamp
2008-11-22 12:36 --------- d-----w c:\program files\VideoLAN
2008-11-22 12:36 --------- d-----w c:\documents and settings\Kvik\Application Data\vlc
2008-11-22 12:35 --------- d-----w c:\program files\Sun
2008-11-22 12:35 --------- d-----w c:\program files\Skype
2008-11-22 12:35 --------- d-----w c:\program files\LimeWire
2008-11-22 12:35 --------- d-----w c:\program files\Common Files\Skype
2008-11-22 12:35 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-22 12:34 --------- d-----w c:\program files\Common Files\Java
2008-11-22 12:32 --------- d-----w c:\program files\MSN Messenger
2008-11-22 12:27 --------- d-----w c:\program files\DAEMON Tools Lite
2008-11-22 12:24 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-11-22 12:24 --------- d-----w c:\documents and settings\Kvik\Application Data\DAEMON Tools
2008-11-22 12:23 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-11-22 12:22 --------- d-----w c:\program files\CyberLink
2008-11-22 12:21 --------- d-----w c:\program files\InterVideo
2008-11-22 12:21 --------- d-----w c:\program files\Common Files\InterVideo
2008-11-22 12:21 --------- d-----w c:\documents and settings\Kvik\Application Data\Intervideo
2008-11-22 12:19 --------- d-----w c:\program files\MSI
2008-11-22 12:19 --------- d-----w c:\program files\Common Files\SNP2UVC
2008-11-22 12:19 --------- d-----w c:\documents and settings\Kvik\Application Data\InstallShield
2008-11-22 12:17 --------- d-----w c:\program files\Samsung ML-2010 Series
2008-11-22 12:17 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-22 12:13 --------- d-----w c:\program files\My Company Name
2008-11-22 12:04 315,392 ----a-w c:\windows\HideWin.exe
2008-11-22 12:04 --------- d-----w c:\program files\Realtek
2008-11-22 11:59 --------- d-----w c:\program files\microsoft frontpage
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-08-12 21741864]
"Gadwin PrintScreen Pro"="c:\program files\Gadwin Systems\PrintScreenPro\PrintScreenPro.exe" [2008-09-05 516096]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-25 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-25 86016]
"Samsung Common SM"="c:\windows\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 372736]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2007-05-15 675840]
"tsnp2uvc"="c:\windows\tsnp2uvc.exe" [2007-04-24 237568]
"Home Theater SchSvr"="c:\program files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2004-09-29 106496]
"WINCINEMAMGR"="c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe" [2004-09-29 192512]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-24 136600]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2007-05-14 35328]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 1447168]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-06-25 c:\windows\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 c:\windows\KHALMNPR.Exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-23 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 10:10 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_03\\bin\\java.exe"=
"c:\\Program Files\\MSI\\MyGuard Live\\MyGuard Live.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-08-18 34312]
R3 Cap713x;Cap713x Video Capture;c:\windows\system32\DRIVERS\Cap713x.sys [2008-11-22 751104]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\l1e51x86.sys [2008-11-22 36864]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe /s c:\windows\nod32fixtemdono.reg [2004-08-04 3584]

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-11-25 23:31:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(768-)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2008-11-25 23:32:15
ComboFix-quarantined-files.txt 2008-11-25 22:32:14
ComboFix2.txt 2008-11-25 08:30:01

Pre-Run: 47,611,314,176 bytes free
Post-Run: 47,595,851,776 bytes free

191

Dopuna: 25 Nov 2008 23:40

a evo i za usb..u ovom prvom mi se nalazi ta instalacija nodA, a na ovom drugom su mi instalacije za komp..eto..


USB_blocker by bobby

Started at 11/25/2008 11:34:28 PM

Scanning for connected USB Mass storage...
========================================
========================================
Scanning for other storage...
========================================
C: 2a99b7d3-b891-11dd-b533-806d6172696f
D: 2a99b7d4-b891-11dd-b533-806d6172696f
========================================

Scanning fixed storage for autorun.inf files...
========================================
========================================



New device connected at 11/25/2008 11:34:46 PM

Scanning for connected USB Mass storage...
========================================
F: fed40b85-b890-11dd-89b2-00221591a466
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================
Sanitizing Shell Menu...
No key for GUID: fed40b85-b890-11dd-89b2-00221591a466
========================================


New device connected at 11/25/2008 11:35:52 PM

Scanning for connected USB Mass storage...
========================================
F: 8cc6ce82-b88f-11dd-89b1-00221591a466
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================

autorun.inf found on F:
File F:\autorun.inf renamed successfully
Sanitizing Shell Menu...
No key for GUID: 8cc6ce82-b88f-11dd-89b1-00221591a466
========================================

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridruio: 15 Jun 2007
  • Poruke: 5572

OK... Ovde vise nema malware-a i ostaje nam samo da proverimo nesto i obrisemo Combofix.

1.
Prikljuci USB uredjaj koji tvoj Komp vidi kao drive F.

Otvori Notepad u njegovom meniju izaberi File pa Open Zatim u liniju za unos texta pod imenom File name

upisi sledece F:\abk.bat i klikni open
.

Iskopiraj ovde sadrzaj koji ti se otvori;


2.

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Saekaj da se proces deinstalacije zavri

Gornja procedura e:
Obrisati sledee:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podeavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore


Zatim ukoliko to vec nisi uradio, ukljuci NOD32.

offline
  • Pridruio: 26 Avg 2008
  • Poruke: 48

MZ   ÿÿ @ 8 º !L!This program cannot be run in DOS mode.

$  ªSNùSNùSNùSOùÙæNùèùPNùèùRNùèùRNùèAùVNùèùNùè.ùWNùèùRNùRichSNù 13P]OP]OP]OP\OÃP]OONOP]OòsVOP]O3V[OõP]ORichP]O PE L ¼:I à    p  à   @             P
 z 0 pN .text    à.data   ` à.rdata     ` à.rsrc    œ @ À.reloc F 0 Q  @ À D%K'ÊsJÕ]]ÿ vì;£2GÏ¡=¡0Ùx gÛ¡dxÈSàQ[FÆGe9tz( Àð+Q²¾¿:XÙ8æÕ¾EWq@¢½\ƒLDºevðzGO¾(øf¿!åøÿ% ƒsj̍uœày˜¢09òy"ÌO7 QmX/y|ų£-D¯p*W! WK!c¡ð/pzvÒÀ)W?g=øsìn>R2u@-[+ÈðDÈÊv+EÀŒ 4ÆÕfþèCºQæU
b4sÞvñBcĊÿûÑûmúW7cu
=
¡*TÊk1xy=nì1XcuñR|=K>ƒcòxrið0uˆ¹@>Ì.\Kˆ.ޝæ !KŒ[òffø¢²¾#Ïð Œ݆iÛ\ø Ìÿ1z%a,;ÐãEg=2À7³ï{þsFt ~FõºÕF=Ðà c%2cBxåܧïÆn6ªø'¡f̪M!H(ï¥l= º/%ò5^õjï,ƒ"A)Ê`òÅC¡.ÐòÆ)û>!=(YI\i;ÒùPMõY½ñbyu[Œmiæ?rœÕœ~o#èIˆ]q+z*³JØʳD{2 \ÕÀvj£$<FCÿZ¡ê½_ìBÌ(ºJ%Ìe{tkÞ˜$fãFoŸ¿{økoܓ#²"LR8F}Ù~ê7ÊWTàk&~<Ã%Ø ÒƒE£Ăn&h0_~|Ì/³æi4048èÐBÊ¿/`!Ÿ
HºGeøŸHOŒÌÿ.Ѓ|eã åDŽYŸÿNÀæ%hڑ[<)H7$}Ħ@gïÞQp ~gU~²òû0cZK¼¿v,yMZ7-!4q>ê
0ã{Qï*,Æ. 'ŸUaV¥ÐN!6<åÕàÀ&Qb¥øåùm5
qq: àe0Õ Rƒb\yvø˜F<-A:
FIÑ~>t@Ø֕ê %{n²%ãA¼)Ê׊SÛæì6_Õ ð=œk,À n¼{ºX;£+¾½>CJLr#
Qè1bøÊŒ¾Ÿ!œBæ3PI\DŽ/.]lètª_¹>ïKEuÛԶ hÅ4Un~:W¾˜'Hhrag)3ªò²(²M¹k-;[nï²Iã¾ÆÞø=Æk¯ G½Y`(}1YXq5% $Xi ¾øþaM^S'DJÆpºþjcW
C?ˆÅ4Õ"G² .zZŪh4òu %¢aCv!FdipøGznV{x6Œ(27{³V
¯={DVkdvrÅB½"7KP(=(=òõj DMæe+BS)qœ`ÿ²aÈtñ$y8Œ7pNïŒÀ¼1jmª89ðR
\&ÑÏ¢?:à å u>;-aõ<ìiœï¼&ØÏx²(:Vf8Èêt38GÌKÅTþOòBiSÙvïƒA8he0ڱƒ
}r_σ
[fõñæœsÒkQJ¹Õ|س`ŒXˆLVw¿0æ&¯b!rIjŸb£5¾bæ¹]`jÞw½.Ÿ
j~b¾,(ã=ññì¾+BåìòsŒ]}ÈÃΚÞ³ÒyNqjþþKӒVÙÃ/cǻ`
Ø:À&Ûì Y:w*ïåïº}ÒïðXˆNª;åªæ8ðMÊi-èùq{!/X8%#Y
<xð!º)=GŒ rk¼tf¥˅~ Zh¡Ro,¾%ðÈ$ï¹QÏTY~˙¡HÊ3&¾A 9ò~{ 1V-St'1Aæ' ñòÿcå'mgSytr US^0iïco+ӊñ x¯NOd9
C~Pρ[c;;yàZcÛ;4Y¹¯I˜þ³ê²Þ˜:'&ÈjûptrEåºA¿ù Иfq 2yݖ£_ÛM퀤tpQߙP@Xÿ5n;0DêÞz$ðÿ+ݮtnv^p+bÊhnêJWf
ùXRùÃÿ* >¿\z1¾ÊEe:K7èÕd{Aw=~ÿûcbŒ&Ã숍ˆ#ÒÿGU½1w³ºõ¼ܵ?AÏɛ²|d8X£ñK½ix^0Vi/qƒÞ¹mj&A¥;? Ò|RغXÒ9Ò vSsNÕ]ø15œ àûƒ%L)3zæqz|æ¹7
æøŸÊŸ ¯|à˜9tÏ
Db
ÿs)Ê
øÐtÃGٍèeMaª$ƒÆ%ˆbÒ>oPùjAþå C5iõà ¼³*=zï\ E}Hb~à*%êã;>N¹VD(¼ù¼@=0jdI1@¡^þƒ¼²û¡F;Z£ƒ K¾ÈUtsø³¯4ÊiÌÊÛõKBB¯QþFÅ£8sн,à`Ì
&Z¡1ŒedÌñʼ-y˜õùAÙ4Û6ûeRbLeBñ ƒÊÒ&\tÅPþdÛãrq)rˆ[Ñ}?ƹæÀ¯gìt!Q'Pð9Ύ¥qÆO%¹þ(YþF:lXnæV[ ؁X'œ?Nڵˆû\Æv?ã~WB+.;b7JÿÒŒsÒTē˜ åû
ÌÑ)zH` 65gh˜þp
ÒMg"ډ0ÅÈ3t¹Jÿ|g˜

Èà˜Gïyqþj5VěŸ*ŒûÏÑ-
+k"UŸڗu5$2xÃÙØÊd>¥D) 41åd~AE4|rGŒû5Oû`[F£æñÊXºÙ~DmòÿF?È=nÊ2sI\Ò ñ}Å
ã43rmæìðr%g˜Å@Û#B²Ñ- WKXW^òˆaI-_A¿ò=9Z¯n[³Ê-¼k ¡1iæB}\ÿLb"&À Y^|ig¹~:pÊÃw*¢ê~fÙf <ˆðaå@/YfÞÒ
QèyŒ uZVCD8EêÌBsûŒPsñfª²!ûãùÙ¯Gà+i˜Õu8Ooq
@[ÈSÕ@7'Ÿ¿s˜'KUo\fN QVƒh ÿÃdVVL$ƒ WWL$ƒ ÿv SV/)¾Af0^[ RHFèhxÆ<B¡Nb|Vu,¾hØœVûg,þ˜ÅÈÏ¿@ÒuÙ¢+ܬ:²n¾Y7%Ðdi
S¹ ¿vàï{øb'y.ìi5&£EC¾Zñ7yGmJaˮYãå³_Sÿðù]Þ˜1%h{mnø˜~ª¿.Ï*Km|(ðPrÏ0¼mt}=åñˆÒI'I¥i)³-Ԏ¯²Ñ<[~0/S{ÆÅhû¡u# ¡y2vùyªª;Ê㪠/ïÅÑiw¥i, Œ}VNLÞÅ"Ù¹_\ å ŒdÅjÙÅ$D<\UÆH:Hq¯8¯õJ2¼œr{¡ê¥|Møbw¢yøMoT¢fdõl &dªøˆò ;ÌUo 7ìÿ^1cE͠0ÿÐ"|-]Û£è&ÅUI6%vHK"þŸè,ÛŸv££¢&.9Ì
& ¹*ÊjØmQ9Õbf4]j_ìD)œDæCHBaEÙ]3¿NùÿÑlRª%W6 >SmMo ¢øuœGÆ£W3C6IXgã1, ˆ|cC 2+iÒ<¥]Oêywh""
-¹qè3Lgkԙ<qÒ|XZ,ƒÐ¹] }4Vì¹yõxDÅ.Ò1pV¡a
ÌÆz¢1èÌ^Xèpì¥iœ[Ÿ"èQ
ø
V˜œè ¯¹l¾$=6
¿[èEõ>(&(U_S³X:7A7c<<ԴUL£ª6ÞñÿM)ÀFc4Sefi?}/ÑŸÕ?ˆs5r1à ¼%iy"ˆõ¿1Òø#Ϲ(êù)(/hi;½72 Þ³¥NB;yJgvsOyòÒtu@狷eÿ+lðaÀ$æ õˆΚ{b_ZÏs#¿Ò=¡ÆLõxi&#kT*bPs8)¥r/YO_³{õvï^;r
|Pè
t¹7St8&Èwd
GªŒJ 79
øIYΰ+.l)iSQ;-TÑĄ"S>㍽ս¼[ÊÆu6³)xÒÈ jƒǴæѐ¿Ïê$!zoÈu  patÛrƒsÀuz-ƁtHxB;C"BÆʁð ؏t`Y92[¹EÃN¿0^þÀNzÞèÌYg#z=Y5ì_1¢HŸh„[<h% ZTð¯å0ÀConfusedþ;ÆÒ 1bWÿêWhÒÿz;9SS:uƲIVJ k3³$%%õ(A¿¯AWãùå]¹[fè_]ŒMQÙºûNS¥ŸðÀÕ-32K9$g^?*qÐ,dDӉ>Ù#qcx{¼ˆˆD>¡Ãr¢o˜.pR=òFÀn8[õ<PJY\\lC¾¾˜}BïÙ7f! b@7ÙÀDÅjºiWïr5B£bsz"è]wPiSV%¢&(ð#FEy³uò<+hL$È¿nØå¹OS SӧEָœ܄Ĕ2Mû#7R&u¿&Mi¿e¥Q1EæS\g`u) XP¥2%5LŸ=M`bpc8?l|@%  hTV~YÑʘÕrMlwr; xã4ù@~:n
ûso{ Ÿh^jœûA¢4uJÌ]gC?i¾H7SF³dÏ
$Æ2£ÛX-aP-*wÿY=:˜ìVð <a1ªUãø5ìxLN">ˆ £¼²Lb;+&&Ãl%ׄJr ^ m
~˜9al½£G1³ ñùVõ@%ƒÏR!ò+yfplcŸ<y3såZm% ³f;ï7
X`,Ÿ!Ã!LI/Òiñ!4ÕZÞ͕ãvùYɑr_zd'¡Œ4su^æþx-½ØÆŸœA
mJ˜Ã@^qZQ+6¾ ïÐ2@ŒRs¥ozƒ y+s æï:S =ï4¢cgkpñ\8¥½¢T!ùp%Å3æ ;ð_ùþ¼\ì;QèÃ$jœÊOZ4|ðV 4¾dº~ړ4NZH$@֖½ƒDu\ÀsÃLÅÈO%eSa]`ÕKÃ|\2Þo¥R6Ûð4 0ÐåŸmVxåø]CkŒrÀÛ¾q¹ɊpuˆõgIa˜_[͑
þˆcr`Ñ.KÙ߬j]poÅ¡W¯govhœÛÑ OtP&Y*"3ݠ Tbïwm7X¯Y[o0L\!ÞPdXØP̯'%
0½P}P69ZjÊ|{p <?iÕ7à3N<{_V6gñ*0c£À^ÀÆŒï
ÿxã.ÑzǠÌ,Sò>þñ!35?Dsܑ{¿¢Ê\8ˆVÅB-ÊIN½PPVwʃ(J7ºø#"G6"ºk-`£!Z{g8Øê6mÊQºZUþlù³!+4½%ìèn¾ҐÅÕ#È=Z?Þwiùÿ5Û7s1È<\ªƒàOŸåIðrKºV%Œ½ÏACL!]@Æ~ֶèÙ=[Uܦ>WzhÀ]ݫWPn#KhΰjðZD׵A`GMrbì|ÙTcɇ{fzQWtªv|F
Ã
Œca þ¢ˆnՏ0815c4}/ÈXÏ"RØ/m¹˜֚"PJù}L!¿r=iDZ1fI+l6
#;ø
[ˆ¾%ƒ^aº '3½>û3u.LC_$%å%À£p^ñ¹ÃfOñŸÞÊ%ãfÊÆ¥ ððY]Ujhi(Hù#T¾~f¿1[gcð;(Êÿ5øcWWck4ƒSÛ4`F-
ùêÛKS¼{
vºøK >xsÃ4ŸFEÊ
Ï£`œÊ/QÞYD{˜½ ø`plÆ¥,A¿þSª¿7ÒWv݇N=fƒÒD{@£ð %P³Kd¾o&Ò$b}Å/nïRÆ -¾ Hùœ
yèJ Jux!œejq
ss?)UFÅ@'P"êÞÞòh#ÃyþWÛ¼BuL\ãagÙ>½rÒÈ<CK¢+R5>A
@æà˜`ˆ¯bÊih7²}ñ˜4j<QbÅ 4êʁÈ|(%MHIVèù X3Ñ7OˆøNþ
?à"Ã$èdÆ|'[uùܙÐdUXb6{ÿHƒ ¿(@RÏtQOÌ'3òNÐd[OU¼uØ#£IŒð˜.ì<#mt0'²òÑŸ,æ¢@Þ%Àp|¢à:ns£(ÆK^åò<;?N}Ù¼]+ZExM¥pèunqœ`E%û=AÞFBYˆåBƒÅÛÐbzKT/å`:0ºÐ¯.Ðy[^ºêQ½(*Åò˜cò:+'õøùåm\¯$XÅCFà*g ñ"ºUTY¹£a=å9a0¥G$p╋Ïo6#}Wãn6 0s/¡º>Ì8P¾ <2$Ûÿ1@-EÌOè^xóƒ
ã_ޝ.,õ+mzÃ|È=o¾²'[vFÀgR)ãm['.J@øØ&0bɠY˒³oÀ=^j9Þûp²5Oz7:ì)ª¯Ã ÞyÀ*¿.ÿK|4¹mò߉|ŒÒõ"WœC{*œ"ÙmeŒtTpÙœD,?ÅfӆÃG=7¾5Õìòف̝)EñÕ{¡GlñnM6]1p%J¾øze>rþ¢0j@#ÕkY¢r5Rw½F¹ D]Õ?_g+IJ¹Ø¥KÒf|YNA%ÙGL=²&X jɞ<nÈc?iêt*7õ-ò&}5Ñå7þx
¥vè¥UpeæÐE1J߂J㟾Mù4=[4r9z:$fO¿XO31UFWZAԛÛ?Ù¿ ûtÌ1Y*³uA¹Ï$oiXè|êX#ÅŸ Xxwˆ?ÏÕÃqn`;:¡,`8 à M à èWàpÒì1~
û\Ù<{ǮeLª,;TÏãv$! {pÒxºKT6Ÿ};mi{H[ yt¼ÞVŒd ˜B>
ofZŒR5ñÛÏJø5hz6¥ÈªcÆUÈzÛÈ _æê ֩RrÐ8gsÙÛйù{?e|!¡rG|ïðc)ûR¹'eÛbVñÕw)û#Ԗ;¥Pþ8_F1¥Õð"_ˆ w_æز³ˆxFEràÈõ{QIÞÆ2ˆlAøoPÙ{?uwÅm"}}Þn׭lÀ$<àù> H˜yLŸ8¥ ªÈ
Õ&ûãMfn3>Qø7ÏhR^aJ}8¡¥zŸ\(HòjN4j²QD;˜W-ŒLÌEleÞIèo ãUeNdy 9œ!¼IyV %q_PÞ'1yI-3w¿sò"eª [ŃàÃwf7(1¡
þY-p68E7²ÿC,¡NÅêEo¹vÊÒׄ"f¯Cˆ¡ˋUì?RH
]PÕ'At¯q6¯£8¡V¾JDdÆ
UaAiÞXrðƒ!aH'~ àtÞ¼-u?)X oñòõJqÐC &kj%ìZOÏò9<'+jf67NJ{/Z)L!Ûӊ3³7C!ðœ>œN Ñz6¿ãJ6(Ø2'oC7ÃBì8_ûºc_?ŸRøE 1<å/ÛŸz-4DŸ `fUYg"Ãh/Ø/dIE/pì-^~֨æÊ2ÞwA½Narf KÞÛʲŒS ¹/þ82*"/'Kd/ˆÊ9{;Y
d
SUaaˎnøfӋ 'Õ ¯Ò¯Mõ_G?Ì¥syÿà<$ ¡Z¯K;דT^3 2ŸVÕn&%$è*k&n¯zpyaÃù¢9Ùøc"gv}¥\t<:Fz_œ¡v>mw+1k|j+Ïæym7|7>Ù#^"_ å˜?45^= Æ0,&³n²øUjºæ#ÃI¿eKB
>ÒûMX\'fDEnø44³VXÊvaRvÃ5Dþz0õe
Ñxe>Lρ²=#Å\¯æS¹aYJågPÞFñLÆzõ7ÐQÕð8£¥\lER$'~ Xjgf
mæYsèuȯ {ÊQ?¿EðE½rUQ³UZn*ˆ2Õ5`FæºÛ˜AìLè<pùQA%òB¯AP=ƒ,u9Dn-SÊÀùˆ/ùÿÞLÆþ4}yþ 0¼wS3cZ½Ӯ ΉÏbæpLå"!dZt I1NÒ¡"E-k{51GMÈÌ]]ÞUw¼ħ]tssGVŸÞ¼LB\'=¼3Œ¼lWv<Ue< èòKÅñHXĊ/7Ø¡8˜òœÆ¥r`õ7w¡2Ø]¿
mN>ÆWÅ2/yÛÅO²²)"KûŸÑê}ab4æ0ƒK¹Ã˜&En? ¹ 4XÑWa#~i6ì9[(*ÒɠZ=fxw%F/
W¯ÒFEvã)C¯êm¼!¹|ã3}õ0 ÏÒTÒ/œgGÕ:\ ùV¥ù}ÅH`j)^ ,ê<Œ_Øke¿ÈÊ[ï³ÒÆxÞ4Æت_$Ï\'Ÿ³ I?Q@V¹³mIÿ^þã :~ï
sd8v?{"ûÌOÕ˜¥ªt2Û+ŒÑÆq˜ÕÆY!.ÞIH!œ(LœqSRhØUXZ ºRÆÛ|¯½hæH[ìygòKè9aˆºBÞY;M
[ÅWñðÅ[d²nE,Àèþðõ¡vˆd(0{Õ=6 ª&6¡A+œ¾æSurprisedÙÌÒØ(ÌÕ&hÿ
4@;7û¢À²û&wa8ᒖh<Z̾SvìOÛãb8/Xra2*¹/ ¾tq¡DÕT4>r(ìÏm˻YNz}ÿKsþw|q³r.Bø
9N!ÛX6&ååO H
ãñÅ+Hìz7Sæ,,0RÐõ NÑml¯õk¢-¯l'ׂ!-¾-vè`W"N'¢Û9o "å/ûsxd@ê³2ñŸØ!ã׎Z ¾'¥DÕVtF.ª7iDòDõœø-Òq_ÿKżð_8ÿ^/>FH-:OwAo|ø/3|¿o/%>ÆÃF(Å+vˆrñQà]i!å.Œ8S¼nJl\qXÃ,OU$tzqèBÅŒïïÐuÿØg¥ ÙÒºÅå˜ÿòùEzì1ïÞÊïÆêybø$ňyÅ¢£<mºÕÊÕŸNgֻMƒ)%{˜eê;Ÿ¡i?;t5_1˜h7õDnId5Ìg6ÿ@3o o,ldE >þ*Jï-²ƒ9t
|²0,ê>Q0;Ù g,:6à])Ÿ.+cn gs¡r:6߆W+&ø¿>XYÆ'r$-XòÊZlA_û}nIH^ŒRÀ\TœñgØw0eLaÒ¾À _ìn¥4 R¾ÙGoqUÙQZznhÕviÙ io"ø6{œy!6HI]~Ac2ÊXBÙÈPÏêùÞK/dOˆ".MWQÁrà3(ah èW@"òˆZ8Û¥ ÈEoz_R.f¹qvA*¹c˜HmQvŒ:ˆRRZTS¾¹fA4[݄åÕA¥zÌ _HÑIIÙñÙZO RÕõÕI¹-+vZRRe¹ PìeœfºSN ³IºRd\[fÙPŒÆdAº<R²sògK\Xaf)øiðH/Ÿ'ØE[Uj_eÙ=þ"Ûf$¯õñÞhÛVù;S 3v8R[ߔŠR@Û;ÙA n!ÛVSÞœÞIÙӔNÙÛ¡R
¯7ÃÒ kS%w)à ìRyû,ÞnT &Ÿg@ÃÙÛVV6Z¡¹ñ~,; TRӖa;Ñœkvù ñw ¼4Ãc.kvùÛIÛ9JÙ:wZ
;
ò[w)àÙ1œdRyûì6eT^ RìŸ5-rVÏÛVñ;Rå R@{9@‰;T Œºœcvùœ,eg?{@½LLÌfe0
'Þw`PV¡7}K\Å3VOÐ#=$q\ªòkÈÿ^rYsEE#7þãÏ a(ò'`AE/ÙÏ|Z[ i5hCoŸƒ.Z߆o(ÒBÈ4¡¢&^}xG6Û¼ã(0ÿ=_ñØrûb)º*ˆ/ÿÞ˜^³£Å~¿<b5p3=LåÌs¢³Ø7ÞV,#?Ì`ò%uGAg]a²Ã AìHdÒVe8
z¼oè}p¿ãàq¯s ÕJÆZML^qē
z¢æ|"`R=œ&0œÏHbsJtM E¹24)QKj¯º!ɮi(.WfÞ1/ ;œ³ì#rŒ} ð<¯¡˜x
¾ªD"ï9<Ut9þÙTj|CÌ?ӋÆ
r$8¼œݒVmsÞ
2sv:_28AC)Ût¹pz7 ~yAA<%uoVÆÃ}(Ÿ| õz2Å(Òû<!ºrÿD
o1JºZ^:d¼W:9È\ܑvº{e; ׬¾-Fin¡$Ès?Ã_}.<1M,m,~ñRZ 0S;¯G:pJÊ~²à+0¿bN- -ÿVÏø3 DøTHLûj8쏌ûÌSÞÿ ºÑrx6w%NƒÌj'¿èdh91c gÆ%AJÀBòhP<uï'I0d(C³˜_þ@<n³:m *½Êõw\&&¯yet)ù,V¥ÛÏ&:'O;O!{gå}\zÕC!mCðïêoï@Ø:YæbÏy_˜ӖWñ6V¼IþWtÌf¡1Å0&
/£r~:¯ò-%5Q=-3Bky ªƒx~_6-YS#Sà'_¾?ˆÀk(^DBtºpĂxlB@ò
"9YŒ¼zõ7ÛÏkCÞ7ZÌ/o_þÐ!ïB ¿P¿ÌJ:7Ÿ4sÏ&ÒïAMvw8iXJ6º¯Õ
ºœæ{c kµf¹il8 ðàì.ÈùNS£R¼^Ivhã2KæZCŸ8&!!_Xvjs-ê³ùS7òDl.cA0ÐxÏ4nDÅ
rKƒæNêY`ZJ!&s7
H*HmJ^ԫ41¡Õ%EAqbQ¾=y³¹q
@~
¹¥#DQoQeÃLb3
~8I)ԑqȹkŸw"ÕƒìêTYBtm.1Z $ºåzø5%l$cR¹GС- @Tþ!E-c]Ⱥ õ: *ÙV`]xM~vx鬶òÃU=XûÛƒJ2è}я p^Y{MÛ0ì !e+oœ*¥þh G+mREKªq༃Õ"[T Ñ#`¹[?rށ,}¼Z[q)ZlCùr,y˜-k7¡ÿuŒCH³ªycRAñì/1P/1mÊh òƒŸ(JºfìPŸˆOÕ>'jPÆ 9e?w¢ڭÕ£¥Trï&Ÿ[p__²þuì&<\/Û%Fz@ÀyùªÈ4ÊWRxEO4` aE˜r5s³Ðê¯MoƒKn¾,Usjn X<#WGÞÌæ¡E0Û$nòÃ%bC\~ vA3À.û½ã\ãDûW9SºØIðàwd.dM9dTÈŸò<è1jТSurprisedYÙmtM¾L {Ñ'ï#)ù%UÈSŒg²Þ¥GñDb*+ã`B7u!ÒԬÀÈÆŸ8ù>vݸK|WåbrºhIÏYæø=½Ø06!jÕ_tˆÃï²]øQx68ðlS
.(нÆlD ˜r!ªXIæsèK¥fU&ƒÅ;¹.dA-{¢[AÅà¼Ï¿[^v2Ilh`œ ;&²
yû@~6ŒiVõAº|Q3Ò1Å?q,V)ˆ¯g£Nœº
ŒQ '+L>^Êjtqi¢<ØÃõFñL,åïzG~#¡ðqøa/
º!v ӛ¼N[ AVòvKS¾wkùìÐ)ÑY˜ÃAõѼpCpÞÀaM(=˜ŒøTTgsÙ3þà]`ѽ*:iĄÏle%È¥ºJfFiªW=bÌJ m¡AufÑãML#ŒÐ^dqvˆŒZÒ.=ݔ|ƒ8¹BS"ÙõÙ  E½ ûØt7¾6 Òd%,zmò:è7RuH#><K]Pt^Å7õ$uè~Y}"v )ÌՏedåKUWÕzZ^qºwsøQsØ]ڀ(\SûºV¾lw˜_þÒÀ r6ˆdhh.:z¢QÕø2ºz'ùo (þ˜³{)BÀ7$ã¯<"O"Tœuù皱ÆŸV^K߱rxjIˆû ^ X1XSSþcÿØR³ê"raA&Ø¢yHÛx}%a8ãbAz¼ܙxyÞûߦFˆbdeæ݉-VÕã-¼ÊO1mÙpØJ¥Û%4ˆøØxðPG#L1qê,a¥ïÅ+H6sìm#yGs|y#דÒð½!9œÕ`/ò-dM0"BmŒ \yìãèuQ
&ÏW¯jX*oò\hðX^j&=H<r¾^fQêˆhÏFD)SìYÏ?m¹yÆÒ+6.³>-Gc ºæìŸ>1y
£@º.òoð%P+bdøg¢$$/n1Ð{¥’/æ˜'¡B 4Û3Ÿ ]Còƒõñ<1Ÿõc;ùºwÌ%A ÌG?¢cMEuˆà6'Œ{KÑaœ1$ ª
rƒtŸ¿>À|R% ÃXÃU£?¹ÆI¿QL R]d¿[OK*/=Cœÿ;Ì¡܋x`PÿĆCÛab_è¿þÅ& @º ZÊŒ FjgÆWÞÐÈ+%4*͒<Œ¡!t½Pû0i'ìùPFN¾Z¥k2g8@.Tû<i"1ððÃ)¾D'F :¾{õåUˆ0UŒf¿3ÐyLwCûwÒØfŸ#%,³ÑÒØœ{¯êUbR?b} Ìòkz0dU?~Nã!à½hPQHãŸLˆ`D
Iið0qw,*GÛ1kÒïE|ÏCuYè²Næ0u Nϼ2¾¾=sKB>ÐÙzþïO$ûhÛΎ.¥¯%PÕA>Aæ;tPr86TÈcAψÙºÅ{kS1L¾
W^vT:¡dd|jÆ;Ja*<p"ŸTsOHRk4vFì3Å7t
2¿d¯³rE\Y:¥1N,~Ù9%Q| E D#Ðmtޝ¢2c/ðiؾ/NÅ3!L6nMC]þ;¡{ñ õÞ5_˜-$ÀoGqԻHrÏXã¿À²ܸ¥ÊþàMKû fw}P:JìÛZQ 1J~PœåWQQ¯r)ÿ¿ÙKÛœKA9ŸWðD!L2ºgHà.¥ÅMnÅM:¯@mL O{H²o~OQ0ÿ2$06Y'LTƒæþd'2|ª.òZ¡$oɦKR¿#Rj{y¡v59a¡_D!VgWr?_˜ÆÅP݇A/òæb³s
Û-£Q >¿Dð`;ø¹NŸ`GWj:_1ã3ˆ˷LCÞ!*=Qb/mgNÛx-6ì #,:ÑKr²xØÐINj#Uvè4dÿd!òÑ(WɕÃÈï"\;¾eûò76ãH%ÊԒ1Y¾EG¢^Ǭ#)%a'}Nj¯&Fˆ5åÛÑ¿hïnɉÒ<ìÊ&Ûte.eO<{3¥ Bêv}œð¿eàÅRLÅÈ¡E4!ÛMQ+Zœò³T0VƒÕ£ƒ^ØØÒOyoò3¢Wfx0$L"I¥GCÏ(wiºŸQ7#ŸŒqGrMÑA+3EØ-䦵a¾ÒwR¢4ðÌÞнÈy+NO"Ù=lNÛÃà4)èH(JU ª7û¢¥¡Œ.
!  +£HÆÈ3œðEJą˜ˬnB¡oW)Qûtmñ,&M²p$Cì^:4u9>Ûj5}Dvbù0àõ*¾Cu{ÑAuuoÿÛð5gõ_¥hEFv_}Ã聲R„X ƒ#
,*³GE*8(ǵjø*wƒ¡ (ª]2(õN}trjŸ*^j<m_2P-EqæŸ\ÈU<tˆòÈLÏ|ïq¾KY¢M
¼¿øai¾º@L>¹Ø `CªsJ[BYRÏjPɻ½Lè.!#0Jf,æ+?Åø!ʍ¹<+שÊI¹jpÒ=9Û;æelw!ӻN À( @(ª³urImœjJVªoN õ^ ˆh \AÞ{ßÿo&å!ï1FÏŸ!k
ˆ½i<PSìÌ4ºcà˜Ï<ki¢ΙrʼpGf0RKˆ²p¹Tpœ½H*$yz
ðª$ZT&£xˆRfOf£`V)*¯þ(¢? ½þ8Ã6zd:Eh4jãFþDp{Hþ {zrıg()å5p`$S?^;D¢F`£=yþc<.GÒKAD]|ïU(þ5Å7ð`ka
1!J;2bN»xLu|ã<]ÊIœÏìTª
KÑ
Ña puÞ`okB\JA\õïÅþùÌq]Æq Ï!õ¾~nàcìKÙkk:{Òœ8
ƒÈ½UHxGÀiWd6ǗñQѾãiè¥ ˜)¿jT o?,P#PY{Ãiw3yJ^à¥D$A
..-²L Fã8WhÛ@TœV!4JSʺþY¹Ky\_¼z]d2ÑþdÿÙV(ƒòð Vk:z493ƒ+'/dz;FYÞ$SadõM{èu¿E-mA£ åRjês³_wc˜O¢Ӷ`2¾²A²V8j4 Ÿœ{*Û*_! ¯ÅD 1ZŒwàùYW¢4>LˆÌ<Bx$,Êìe7Êï_Òi*́`W¼˜cQØOÑB½]ˆ))KSi¯ZGX
6EXhUB+2OŒ||D
˜ñ7!¾&#S/SH~4åeIˆv
)¼(G.6KãÙŒVΓxHDã#¼ÈÐCQåÈF8-ûJT.ƒCQ¢5G-¯å¾¹ùŒ~0èOàQÕ%ÕÛ¡ÑÊPI(r?ÒãfW¢7*ØnX{XI(¥Iv¹Iÿãk6º|U>rÅ`?ê}ÑQÕõrA ÀQÙwº
£66¿Œõ9þøMr[dñ;Ÿø\¼ WH%ûC¡R8AòqFÐ XcoÊ¡øàyÀgòy¾ D û `vĖI%bÙqª}==[\/"bT%³߆4ØSÆJ]þum#ãèò7
"/Pq&Ñ1fÈZ8Ï£NFêñÆè g3%¡¿TeÅcÞªŸsÑr¾U("dÛVÏ8avœ
WN)åÈàŒe*F9jo?p
ˆat#_mEz 3Y~¥st=ãsz¿c7tKVØ _aÊiæړÿ¹>]å>,2+@:n¯¾bKÊ<1ÃhrÕ,NZ¥5Uimui^C!}FÞe²*ãxk[6W#aNàۏÕ^q œ³!¢y9."ñ%g/`y)Ñ-06N¥i
[^ÛkJ¬qÅG:g¿:¯åÐiì0Õ!HIØ:bСxZ@ ¿Tc_h0\ªa½¯Pkچà<=_d!ɨ
ïFIK½œÙeleÙ=4ãFJuœx³)"¹u%ecp|òÐÒWÆkMZo8ÃæÏE>freÒu"I;I{~ÏÌuc'½M5¾ ;:#@(È`uDAD K&ïPxޏzzÃ11 ùxÞXûUn¥ûHðm714Þ֧Ã}!¥{ ¿)(}FÅC0£û8gÈ!ª B85<z~šPJW¹9Qº~¡,P%w3.WV5ð;bðSE%>¿².ÃnaQ_tª5eIœ˜Ow<zCòb~r(x?18/ˆVÏ4ƒ 8¶¡<ºrð )åø£vÑèZøÕÛ¹~<ay+"'r֦èp(¾=m"Y¯È³FKˆûˆªSC0ð?iB1p¢ Ø`ߊuÛY
EdÌÏÊ @£Bz¥x˜Cl@#2¼ùûA[ùÀp8àQ.Œ0*ï-£'H`mtb4—Nÿ£ZœĻQcSVho` ǬMæ ¼å`¥*!9ӻhæpgªpPŒyÏW;9¿6£ŸÕÞTõÊR¡L|J}hòr³ocÛÞ̪¹màBr
s³ŸÀE<05ÿWXþbæ%‰gñF!NCP0ÿ= ¯³þÅ,;$v:ùXz3vHïæBz-o=Q,?þ³~F³s!à1Ƴ\ÿ6aE$4howæH)Cò¥@ÀS'ø½ÈLOÞ ÿ<N(@j 9^ˆ\LS`ƒþS[\]¾)LÊ7e-<f>ã3H Û!E%PYÌõÈh/ҍ߸˴bdtò.ØÃY¿4æ¢ÕêqN²[7c!}fnù|zE&Jo*ºUƒ2# :h\ò}v+_ˆIkrsøþðê1OBWÿˆ@}²*F}/<ù¾ª¾ØVïz,$c3Ù"œ;¼^vÞñ¯mð{ngUÌÙ:åd¾wº_֚Àÿ(ÿprHÛfZj2/|kã%_¼¡hÒO$MH ½ÿÛ.¹0pD¯ÙFt/Ì5VwkLœ_YL|$¿v¿UõêA
P&2spNbS¹(ï ²zZ#¿Ðñd'þŸMH:{PÀ|Wh]-֋6fHNbZ¥a$GX.ÐS
ÏAzˆŸS5O,ZŸkY笫Z$ÿ~#ÆPïê$¢ÌÏD¡ÏG0&|6Razzd¾ƒBCva,ytœ
WJþˆ"eìê6y4+9~ÐNœ0ªj7^+êB@@eåqàTI
þBêðynùF ø~UZYÃœ6½Bò¯gT"ÞÆÑõ]lHÃ
u]¼]õzV$}x=a"¯QGG1æG`œm
rÙYLFD,vkbˆPg->Yˆ]v'Gñ³Å}ã1.Õ? @¾J/=u þÙÑt˜lǂ¿)ð5Ï|Ïpï'yBqÑªr²{¹eOb.=¢ø݂+ÕþÅûˆ+þ!+¾ `à'yNŸ³ 
X³ ¾3w˜ønzy0)* ñ>8|jn/Àñ&Å!+p£Û'26P]? E@iÒ@ì¡L_-²@³AÊøΤþõO*ìs2 7ÀÐ8ˆ)#zÕŸs_ðŒ ÀYŒ$.-.ñ|6h]HŒSurprisedº!Agb(Y|¿0Q<x_|j¥=<è¢*VÿbìÍ 9CŸ#dì~¡¡&ïè`̳ð;Q"<(E[NR13!h4eiytÛ4MƒQ ÑñW4H¡ +]æAT9@Ÿd!]|~èãÑ98(iBe<n7&; 81]MÕå0U¿
£MÀ.àPêhT0is ÐõVyƒ݆Kbyè dÙ`ԙBN%pɆ>%Ÿ"ùV$D-_²u;dˆs%¥gN>SŒ';w¿fS92È0ùù;H³ø Þ1_ðWpãĆÊS8U¢ñ~=þT*NbÐOS¿Kê=@c²¹Ã%ÃŒ*lIoãZiGvoB*9tY ì¡`(FOFNlè%L˜ÆPû("a Õ~T?+|\XXIΩàºEþs+{2Àõ0
\ œ¯ F{L;-H
 ?- ŒÒoB=MSþ3$P(UʽhkÅà&¥²vO|¡si ?ÀfjØksK%,¹ÙLM" Hg`þX=/%
H²\n\£GY_ U¿ªì9êìa1ï_?èi#j!PŒJ ïMh¡\!$F=[V1Ê7~+1
ÒRÅ¢ÌKF"lƒNø`36|ш9`(òÈÿÌà½zù@ãpp\.;0ÈÌ-ŒØòòg ¢2ì³R Y=wÿœsPJ/Êæ.f|M/X6*õ9Ou|S {Œ/zˆìs35#¾[ySmåR³5&ƒ.V6?;԰_K[B nÞïDlo/LFZ( òû¢dWÒu¢0 ^6^ +VnÙEÅ7m`ÿÈݤjFrSc˜ûEa#êXÐ;BèÅEIåð bW$ ñ|_)p\3;-Ӡ[7ÿ\ F/ˆP|k&ð=tÿJÕvÀ*5ªÕØFê D~ùLÊȼ.Sõò"
pƒb<9bàEL%|b4ƒ¹­uiR)o4wSÀœh"¼r+NFÐq¢)ÏL_Gþ¯rÞ!¾õ¥'_ˆŸ²¾䴨S/Ì¥¿t$m˜ÕN*UÈ:jŸã2_dÒaê5Ùàa$:/@<êòªYZ9¹QWÅiŸøPԊi añì5GaàïUŸºkñ ¡{F¢ Æu@yûjec@F¯". @ ùþ¹¾k¢RJEÕIÛ ðñø½2R}ñRþk£pSzSpTÞIYÑNXñÕØ?A_U*ƒÌÊèê{}CÅAGV ŸÕ¡EHs@¯¾rj¼ L}w[ìÈ-¾ÑÿHÿ>¿"ÏsXNe½0Wõt5)Ÿ5{Kyï $h|Kì}ìœ.#³ÆD:½Õ&9xI=£K3CÏ[hy"F^OYHOA0-bbIÌþY1Êñ|¯à͓wB>rª*¡?"Piñ2,¡º˕&³}¯ò807ZƒÙ vTTFøQ.£õlѯ²º1t]tò8³=>l截IåY£Qu ÆR@6l#¿ªøzIì&Å>ñ1jøÙRv[½ sHEÞPa:^;eZW²Ròå+2xsZ/ÀìŒVTLOLjûñˆæ8õHQVãû~^d
4N&3¡LñÀ}1@ã=ʘ¿ À³ê%^
vª9ªãP6<¼w{£~b þê3ñ䙩7U5¿Þ ¾œܔº2,Ê\RBeõ$Æ5cKGYè~SQfwxø¿õ뎒F\{ìˆ,²9Œø½.ò?Ò,Xw˜ÿ Ñ<
X?²gblgªMÒœÛ ŒªÆ-bZ¹aêKWk¡bÀõtĂlì-ŸÏ5!-Þ?q ÅÕÆ!MM-cpGVY W(NU+x.ˆB64r>4³dˆÕ9ð¯ÅÏ(RÐ!̾à~lPÊ[-=˜uYRwSˇÆE ½kÞð¼
E6d SÆù£ÏS¢G˜¾Èڅ5Q,ÛÈ`Ù,W%à$ð5ÙI!pIiGNÆ!õu ïR zØ6A¢Gqg=£F¿dhI)²JQÏ/ŒºŸæs\Ln Æ-ÃàobwkØ;/Ð!^ùñגò 7Ê}-¹~Û7)SþVT0]c!ÙUòbVZðÀå7åGÏÿ
º{*¼@/A+F>\²CCÛXj+ð
z¼U"c¹•m¿˜Sïìu/o '6åq]ˆUŸq1hyp2¿£ 9¥0løÈrw#Œ# ñG¼jÕ¡Ã]Τ/½w¡å?,Q<{/cì ,Q9JÆû+2ò¯˜ l@i³ lÌêÊ>4<.l ?:@! LþÑ>ŸI:NìZ{Ÿ¹ (hÀåbBl?:MfqqZ=¥#h D~}lC_~#Æ:m
Ǖdzw¯£Å3ˀ)Y\Kiz%7e|³?ùimcV#Þ%ijiê"
æïhpÿ8 £:¹eO#ÿïP¼.ǧhõ7 ƒg-Tjþ^¹ø<¹fXhÛ I¹@ïS½Z
O+8¹;¹²?Cè$}õÌyuiª>.@x¢i$¾~¾)iPïJWØ£1/s Aù³sD^qW:*xñD2 KHtM>>s"NjûƒÞøÿTTaÃBŸ?Ñ6Þ6¾,ª$¾Uå}}mà.Ò9JxMÐ'þõ,ÏrBs`Ûï/]ÿ.xÐmˆzœ[TàvOæVPom8Lo,, cØ%Xb5|yG".eu˚f¿åÙÅÏ0K=-K]ZRB]ið¥¢ÿñXqBÞAjexCÀÐc$.ɚ/by  ˜øSs¼mg Ê}{"U2ef:b> ²ÑÙ(˜ nê@|àUØÞïsà&b¾,>6 6ØJ!¼ætpAÿÈH5ù¾8võÑå&D@FaàQvO¾ gL F5³JHt¢vàû¥Dm UàA¹æC_wt¡Ðì³ñìØ¿r8ÿãð`/X NÒ¼_fuo¡2a8<.nJªþi£#èW¾t¯Õ$„IŘÀmŸ?å!Ÿæ|,å²\!ºIÏfyk¾ tBϝI_LÆ5ƒ?¼RDgƒa£eŸ Z<U.dù$Ñ6ûÒê#êÌnÏz^Û$M2:Ր)jN{`yl˄È6reÐl!QW.Ÿ¯'¾ 0[\F0Zz~Tœƒ !ѯ¢pmk>åRu vrù9ÑfÏ..ŒãÈy״Ì[6ÿjÛÕ%#Ø<Fh$Û¼²S¯¹pØp¯bq!/8#8ÿ,èvPEì½
èApû(,æTê_Ùr\%øx GaþÏCv\#¾˜~'xJ&mpìh-HТ3O_¼|5ªWq";!q, ÀM&^²i¿Kø&Btïþ~¹[˜nêªàΖzm
Ï£~£ayDå`kÅ¢Rœ}*ðÙ ¿²ÒJÐ+@BïCZø)ðEr~ˆQ!iR }w¾à¡ÊpUK9ÐNMox@~aªÌõ؍1lmYðÊÌ-4k$ÅÆŒhAS=XbêÏL¾8ŸqÀƒT
(UAb
£-IÊ\C¯.tAå~Ã47vj/Þ(S0õÞ-퀰aKWÅq
]*)ã
|BÛÿK+¼y?MÀ$.Wl4:F'³o;cf3TNk \ìv0¡:YªÛØi¾qª(LÊ8tﲯàgCt?HrQþ6 H9CømÏ(bmzn
`CïK/êð³¢w]gduÒûCևC¹˙ÏÕyFjsGi¢Tn)8£9ˆT<T;h¯ÿJ ØÑxìZªL¾hT4S: /{;?sœÒ1TہÌZ¿²ºè6òP_àø}ÆvR4D~—)ùY<|u&wì £Ûq'鵄¥ߤ{uõg sc¼þºÌGå.þïKz/6.M;~+øoc\ÃêovªÙG3Vc;dï-cûA 'èøc4*^,êdM"f TvãbCak/J¼³ÈãFºGCÈ@º2UºèïØ:4Ϙ5#YìIƲsB]/Dè|½xŸ_H`R½ãþR/ì¢J_ºY£è}dfT]iìTt;ù/£ԄBv~;{`Õ9Ò 
Gÿðèdø81fyZÆ%2sï¯ګfãÆL\IP4y)KÕ à¿û}õ˜õc¿|AyŸ Y݄?Z5q-søÀÐò P`.²EŒ ñx¢'ã¯ÅgðÑ4degjÌE"ÿ-ULÙÆ£)/Ÿ#CÃY^jh!¹æ¼Û|wo5ãF`bªJ èpG^8_iWdƒÛvnŒ:àw:å9qa<ACˆ~ÀÿxŒÅƒìJ6å{)'àI鞦Ò5 J8ЁÃzº.¾)òyvÑaZ*¡ZþfˆïmZ1S}<oSã^تApÅEb+ñI½¹|dbYwI}
œxÞw]è|ÞÏ5Ws$ƒsX%@g¡cÒ\è7͆ŸÙà1tALqùÿ¹T[ùƒJnl"^d(ߖ
¡Zõì'Ï^Oh6vÀ;œõT
mt{¹¯!
þ}æNiJùT2-,³²X¯5<L ,V>+2Uùõ¡º 6 ^VAsG8dܮZõØrÌozC ê0IpFwOÑFL( kocd'ÛM>yÞ¡
½ºø £Œ¿ÿÒ=#xZg¾2Æ1ԭBŒC\˜NðÞԵžõõæ%$6[ys-¢OÆêf ¡%u[Ɩ@ØFÌ3DAÏ¿I
ºIþ`wD‹¾9'H3ïReyÒů%ZèœÊhaï9]sVºVoYÿ:ta½ͧ`',Þ gpre$%< ^àqïS#¾Èwå^½V¢$v:)h{¢`ïÛ%êŒvòXÅEwao:
¾iÆþ'Õ ªvLsØØùFèÏUJ+"òùtvJ
iFDPÀÿåÐ|}ØcÞùKd˜À~l0Z5£r¡LKè'Ù*bãc¡.ƒ˜ÐHÀ5ºånIªbrZR¥N¯e0
Ò¯Û¢E$dòOÌÃn3T%œmõ1¹@k7zZ2z9}£
½ŒC4:Y'E]oÐVS*³ÃÕAì/q.pjm~½^V&ùètãùzFd;Èw=ø[f`bz3˜pe=8wL^
~-o&U)t¢1_S#ª AV³;`$1ùtÿ] / ]£lAuC*P3ñNœ%ÿF<+}#hha¿|
ø=¢)6oCÐwYàŒÑɰH4Gkt\
q¼ ˆY$¼%_Iæ,
}-(G:R˜G{* #t1\TÒùR^èÀsK*X@V1¢kè3À@/£y:5JŸzo<Ð!FèiHœòM|ñ+LèÛ~n¯˜êXºKìãD<˜eõ¹À3NI˜
|#%vqƒ
¢cEm˜Ï8èï@A,rìLo-CuY/Ø(E1þƒ|E¢¡XpzÛ#]Ÿ;-U³E# *oÊÏÌ#`gDsуÈ;9@êHÿ;nyُŸ¿Ù±xùïk%!²SXU)õWF/*cR*'pc¾XJEê>ƒd¿1P"œ4ñ ²Ø³aÐI#\¡S£f õ- ðg*`¹n=LÈI1QD d{nã³ ~Õ]ZYJc։dÿBOjAUˆã` œ4yÆÑ2Ñ# <*FKõ &6 #ìÏXÏ'+sÆ_!bþ²eGùTKÊïïaxU:5ø!ã,G4 |w"œg;NP½.sà9œ¿4cæ\mq)5ÅÿPMªCi¯\ ñ eaE e½*,À cH8=þcŸ $ïÃõWnzR':Em¿ =àybŒ£1k5øº7*d(Me0Œ5#KøÆt{NE.|BãxÐ*Hñ1ÀUek.ðoJ
³xMè,qã¢1wå}567fêz¾lÕ>Ð ¾gz¾{¡Õ£ !^&ÀtBYŸxp>$ì|ÃþP/ºFY³yøòD+Ê6caÕŸt4ÕOa²9˜Qw³ðꏹÛ.T7rNnli ²ª"èIÙ&è\<W&ÀÅþ¡dB7Ûymò¢%A2Ñ\à(v¿E^sÀ˜ûœ;RDHJyg¾ɷ8àV"õXMèd3ÌŸÒ½qX3èwi¯m:Nm& ŒA¾+øÑÊiã#UFVŒF}ŒåºÞ6ðñ#-.+dBaæu È߻Æ~V?ùMu¼k£K[Ùb<ÛMÏ8{æìvÿ35i\RS{ˆòÆïì0_:;Ï`Sn
½KÐ(
êJq!a¯X(åsNJfUYÌê½.CA¿!{Z^ ˄ÆÿÒÿÒè=!6I7|c{gÀ¹XU@}64;{_³æ[?/DMÒ[<¼}ï-ßV#lh'
s]?͙:Ñ܄ãñZJÃH,4u(kbÀbK¹/Q4kÀGÛ 2æ,Ê) ÅWº¹q5qdA{PMo'Ì͒¥ØЃ
2h,˜TTp'¢Œo馮'ØM!]ì)¼Ð^*ÃwhŒ¿ûE Dst(Ê=¹FΊ£²¾'go?1A3õ?<Ùyõ#êZ5Y ùʪ;˜òR7ûև1¿u¢oY ³wÒ RZñF'|/ªøàm( ²TCzJG}ñˆ/þ'7eÆ-HeÈc£=ÌBkVMÞ1_hkþB=x<ØìÛìz9PP݆Wê 
6E+ 2ò*ߧhGpÑû

9iF{VLïàSÐrDcXn!ZêjܓǸÈv"T;ˆ¡5Cu`La:%ŒûDºMUrˆ4JKTÙ"]Db^ØåVרs)È96U²õ#TÃyº]ùhÅo(ijAånĨÛ~DÀ¹¿I&Å_]iC<?j~ÿ %D"þÌ4ïP{0þ(41dsf:}å4w¢½ÆŒ¯ÒŒ\ t*Ñ¡Þi¢À84 
1ÞFVw>)%2.Lñ¥EȏèAÙV{ìÐ?ì=Nê+M'ø'}_jêþ £(¾vmÌõªÀðlÞ%èUòø¾Ì\=à?m2\vF4¡ùÙƒÏiðì¢3m!!ì|*Ïà5È1à¯ø7Bgœ0ÿª.e˜u+K2gu¾ø<¯Þª
sÿ%,ZNZ¡~J9"ñ# ³Õ¿ê yøhÒ{tkJY²S)?joc¹¥2`K]ƒVq)Ì3aIðùRèL<vj[9hènxÅ^ùø]àìxol¾ Lx¾#t%@¢˜Ùè
xZ
³È.¹o%MDy¡;Uk³õ˜;o ¹Þþ@]Fxªè-!xa׻Œ#¡I_æœÆ^NJûÕÃJoFlw'øº׬U¼ªã=cG,Ñ

^Q$ì(tŒˀƯÙS˜r¥hmÊ\Þ3ÊJû4Òã˜à~h Q<p¼.ñϘhMSèx£ì|(,²½74

# "S?W¿¡V0lØòÏ}]ʹ¡4åwa/~- ³ ÕÛùþb6à` jøÆ.j]ê£ rØZ¯U7ïhm|!sèÈÕi?ϳBRo?Ì{/f
'¿&GªV˜ê Hˆ, ˜(VUZÕxCæÐO"|A@dBRyAA ¢Y"ãwy:cWðW¾OE{Ï(R}Êj¯^øþªùÕ kƒݰ+þ?£5¾%}ڨ&¿5¯L Ǧï]0åLD+ò7jBR{ESèt)BÙ¯N6¾#Fa5¹>BNY,¼0È6sBØa~bèOC=˜æ9tKÕàCgù LJ%Zÿ\;GïÃk<ØqõLFZ1θÐè"¯²+`À05ƒÈø¹ 0Of2GYªæLðþo
Y¾fÊ È¹:3ÛŸƒÅÿ¹BB)hû=ªk
õM#=_ã3KWQk*]} Uoæ³røˆ
^
]_JÅsN/<S-uP74hò|ùZñ ¾Qp\tåò"I˓½
&ò/H-ûÒa¾gÕMk
i ](($:{̏[cd3ðAùQÕ.33ŸkgûyªÅ* È  Dþ½RÃÊeB9Û)œ,ͤ ÿ^òTÛ¼ùĬWU9æ
+|5d6W4$ø3nÆ3^.ÙGpÌ8[Ke;Møw~
¥o`ò &[|/²¢ùØCpà Ѝd Ù¿MM[3rÏtã`ܸ¯YLrjÊ Qkû2bd+¹UwƒØ/ÙÈÒÑz8$ œmCºìøGÙerΙ(ì|Ol¡XdÙû˜ûæPZ²_Y\>9;:@JÐõø Ûu¥ŸÌ\Ïsœ<_+¡Ïs5{Eƒ%h/ÌuVs/ǛÆÀ¿auRààÕ&˜³*
2iƒZìñ$²g/½£EIFºv-Z+À$sÑn=²Ðì5
¯à6gx²ìF˜Gm²G[Nãø3x7@?{A6 søyCA¥ÌXMT(4j=¹¯ԊPBø6`u
8qxÊY¢W:¯ÀF1!Èd".ɎtÊ\²~ìÃû/vIPGIæ²t7_oêù¹ñ½^nH=#w½^= G-ÕêñÃÕcwQƒMÙdùY¾8 S}Èè4ÅR RØÀàÑyE¢b_ñ(x³U¿ì
DuãZåvZb]vwùQY :Æ;æFRãì ãRW¿fl_ì aB[$(;.¢]²ªÀàþeʹhÙ,I4.Jœ¢ ðŒGRaÀ7@TÏnØKR ÙaÆ]kGÙ:#Q"^)}ȹ~+xUՐ¥ÏRWåãE4(,d,OUNœ¼ˆÊI|ZӚRÒrà6H*ÈnAºåŒR(Ș'QnsÊnjà¹Å%B%s/\T?ïdRLêð
~*9oèþI\½lÃrïlãj¼Aû>Ø¿æÌQ8K9V pÿ)+Ì8qiÊ065.¯S92¡Cø| gS[ À³ï¢Hwp<Øò 'Êòl+Bª-
P/b r5
ìlaÛH%Þ¢Ÿc øøqTÿŒ,oTòh`þõiǴÀÐÃtåÞWKuò_K(ŒPà ÃÞ^Ò<C£l?s ªn 1]7ÈÀt̍!ª-¿å<A¹ºP4Qy)]NðttG²g EFв¹7F(ÃQÏQÕè³²ÊBgèª0ue¿è+`ù$*P ³3HId&XÀ\¾QÕ1ÌCfN¹¡Æ%X.ÿ1;ìï66J[gg³f ÒÛqŒ ½ÃÀŒpº^{ÕØg}dÒ^˜Ê1 盀¼ê+d_@EŸæjŒ;TLQ֔T4 z ¥v; œI7 ñEFÕӖCY@IÙÑ܎UàO5:0Z¡UPÅ̏~ XNv
7ò¢lÏNj7ãAþ6ƒ9ï7ñIñÈAˆ/!*<˜ƒ³i{~^jÌSI7g þ7À¯Ãa~kê l[w(ÿna 8þ ¯õfå ½Ÿœ]¼tI?#rÑyûÉWÆkñ@ ² ԨqÊJñ
dŸ#x?¥X|
ªlÅ?^ì?8M#*G²ə¯Æ|Xhìk?sfÒGÞN UÛœÛÑÅRUåRGSGÙÛå~hDRV{ÛHÃND è-
[eRL;ZI½B
ª{GT4R^!FÛfÙœÛVÑ;W4] '`u$ej7V!ÛÑÅRUåRGSGV6~hN!DRSeRƒA¹dÑÏSÛܻ[JÒj-òþlM;ã.yv(Ûï` OhÀªê6Ñڅr&#

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridruio: 15 Jun 2007
  • Poruke: 5572

Udji na taj USB i obrisi fajl abk.bat. To bi bilo sve.

Ko je trenutno na forumu
 

Ukupno su 814 korisnika na forumu :: 31 registrovanih, 4 sakrivenih i 779 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najvie korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 8u47, ALBION101, aleksmajstor, AleksSE, awathorn, bladesu, branko7, cetka, darkangel, Deurni pod palubom, doklevise, draganl, DucicM, gomago, HrcAk47, Marko Markovi, mercedesamg, Mercury, milekNS, MiroslavD, Mixelotti, mkukoleca, nenad81, novator, pedja2506, pera12345, procesor, Rocker, Sirius, vathra, Vendox