Problem oko PC i Graficke ...

1

Problem oko PC i Graficke ...

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

Napisano: 20 Apr 2012 18:03

Od kad sam skinuo neki (zabranjeno) program nzn tacno uvezi cega sam skinuo bzv nesto
(ja kreten sve me zanima )

tad je krenulo sve nizbrdo ,,,

Obrisao sve BackUP failove ubacio mi tonu virusa ( ali mislim da sam sve viruse obrisao ali da su ostale posledice jos od toga )

i od tad pocinje pc da mi mnogo laguje , primecujem veliku razliku ali nzn kokretno sta je u pitanju ,,,,
Ako bi bio neko ljubazan da mi da neki savet sta da proverim ....

Graficka mi nekako losije radi ... ( jer igram WOW i LOL i po tome primecujem da je 80% slabije nego pre )

i pc nekako mnogo spor ...

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.3244 BrowserJavaVersion: 1.6.0_31
Run by Marko at 17:59:20 on 2012-04-20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.363 [GMT 2:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\program files\common files\spigot\search settings\searchsettings.exe
svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
mDefault_Page_URL = [Link mogu videti samo ulogovani korisnici]
mDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
mSearch Page = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
mSearch Bar = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = proxy.vektor.net:8080
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\5.4\iobitToolbarIE.dll
uURLSearchHooks: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\5.4\youtubedownloaderToolbarIE.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\5.4\iobitToolbarIE.dll
BHO: SWEETIE: {1a0aadcd-3a72-4b5f-900f-e3bb5a838e2a} - SWEETIE Class
BHO: Winamp Toolbar BHO: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\5.4\youtubedownloaderToolbarIE.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} -
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\5.4\youtubedownloaderToolbarIE.dll
TB: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\5.4\iobitToolbarIE.dll
TB: {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [Google Update] "c:\documents and settings\marko\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [<NO NAME>]
mRun: [SearchSettings] c:\program files\common files\spigot\search settings\searchsettings.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
LSP: mswsock.dll
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{6B9952E5-896F-4F20-9427-C0111EBFFD15} : DhcpNameServer = 89.216.1.30 89.216.1.50
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: TPSvc - TPSvc.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\marko\application data\mozilla\firefox\profiles\8ugh0x66.default\
FF - prefs.js: browser.search.defaulturl - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: browser.search.selectedEngine - Speedbit Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: network.proxy.ftp - proxy.vektor.net
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - proxy.vektor.net
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.vektor.net
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.vektor.net
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\marko\local settings\application data\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_233.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-11-30 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-11-30 337880]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2012-2-29 279552]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2012-3-29 490840]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-4-12 784792]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-11-30 20696]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-11-30 44768]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2012-2-29 25984]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [2008-5-19 4096]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys --> c:\windows\system32\drivers\epfwtdir.sys [?]
S1 GhPciScan;GhostPciScanner;\??\c:\program files\symantec\norton ghost 2003\ghpciscan.sys --> c:\program files\symantec\norton ghost 2003\ghpciscan.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-11-28 2253120]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-2 253088]
S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver; [x]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\drivers\genericmount.sys --> c:\windows\system32\drivers\GenericMount.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\x:\ntglm7x.sys --> x:\NTGLM7X.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-04-20 15:34:58 -------- d-----w- c:\program files\Trend Micro
2012-04-20 07:36:57 1409 ----a-w- c:\windows\QTFont.for
2012-04-19 12:01:45 -------- d-----w- c:\documents and settings\marko\local settings\application data\ApplicationHistory
2012-04-13 23:14:53 -------- d-----w- c:\program files\IObit Toolbar
2012-04-13 23:11:20 -------- d-----w- c:\program files\YouTube Downloader Toolbar
2012-04-10 08:12:29 -------- d-----w- C:\Download
2012-04-07 08:24:05 -------- d-----w- c:\documents and settings\marko\local settings\application data\Adobe
2012-04-04 14:37:26 -------- d-----w- c:\documents and settings\marko\application data\uTorrent
2012-04-04 08:25:36 -------- d-----w- c:\windows\NV39962096.TMP
2012-04-04 08:25:00 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
2012-04-04 08:12:18 16062464 ------r- c:\windows\RTHDCPL.exe
2012-04-04 08:09:47 69632 ------r- c:\windows\Alcmtr.exe
2012-04-04 08:09:10 315392 ----a-w- c:\windows\HideWin.exe
2012-04-03 21:36:36 602432 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2012-04-03 21:21:11 -------- d-----w- c:\windows\nview
2012-04-02 20:26:48 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 09:01:47 -------- d-----w- c:\program files\common files\SpeedBit
2012-04-02 09:01:45 84480 ----a-w- c:\windows\system32\EasyHook32.dll
2012-04-02 09:01:45 102912 ----a-w- c:\windows\system32\EasyHook64.dll
2012-04-02 09:01:36 -------- d-----w- c:\documents and settings\marko\application data\Toolbar4
2012-04-02 09:01:33 -------- d-----w- c:\documents and settings\all users\application data\SpeedBit
2012-04-02 09:01:32 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2012-04-01 23:32:24 -------- d-----w- c:\documents and settings\all users\application data\YTD YouTube Downloader & Converter
2012-03-31 17:17:32 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-28 17:06:42 -------- d-----w- c:\windows\system32\AGEIA
2012-03-28 17:05:43 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2012-03-28 16:53:23 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-03-28 16:53:23 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-03-28 16:53:08 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2012-03-28 16:53:08 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-03-27 12:12:36 -------- d-----w- C:\$WIN_NT$.~BT
2012-03-27 12:09:27 -------- d-----w- c:\windows\setup.pss
2012-03-27 12:01:58 -------- d-----w- c:\program files\Alcohol Soft
2012-03-26 09:28:38 -------- d-----w- c:\documents and settings\all users\application data\DivX
2012-03-25 20:48:25 -------- d-----w- c:\program files\CCleaner
.
==================== Find3M ====================
.
2012-04-14 20:20:37 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-03 21:36:24 285788 ----a-w- c:\windows\system32\nvdrsdb0.bin
2012-04-03 21:36:24 1 ----a-w- c:\windows\system32\nvdrssel.bin
2012-04-03 21:36:18 285788 ----a-w- c:\windows\system32\nvdrsdb1.bin
2012-03-31 17:16:54 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-27 11:59:04 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-03-07 00:15:19 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:03:51 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
.
============= FINISH: 18:02:01.53 ===============

Dopuna: 20 Apr 2012 18:42

I ako neko moze da mi kaze sta da mi bude ukljuceno u StartUP



offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

@MareBatice

Pozdrav i dobrodosao na forum. Wink

Nisi ispratio Korak#3 iz uputstva.

Pokreni Gmer po uputstvu ( ili RootRepeal ukoliko imas problema sa pokretanjem Gmer-a) i postavi nam dobijene izvestaje.

Takodje, koristis dva aktivna AntiVirus programa:
-Lavasoft Ad-Watch Live! Anti-Virus
-avast! Antivirus

Opredeli se za jedan AV a drugi deinstlairaj.



offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

Napisano: 20 Apr 2012 22:13

evo sad zavrsavam .... GMER

kad sam skinuo taj program ubacio mi neke viruse kad unistaliram neki program ostajali su mi PRAZNI

failovi koje nisam mogo da obrisem i jos su mi u folderu .....

a taj anti virus mi nije u progress samo mi u folderu stoji i nemogu da ga obrisem zbog tih nekih praznih failova ....

Dopuna: 20 Apr 2012 22:19



zbog toga ne mogu da obrisem ... wtf

Dopuna: 20 Apr 2012 22:32

[Link mogu videti samo ulogovani korisnici]



[Link mogu videti samo ulogovani korisnici]



[Link mogu videti samo ulogovani korisnici]

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Mare, ja tebe gore slabo sta da sam razumeo. Moraces biti jasniji i moraces pratiti moja uputstva.


Arrow Deinstaliraj Spigot.

Arrow Mozes imati samo jedan aktivan Antivirus. Drugi deinstaliraj.

Arrow Takodje ti preporucujem da deinstaliras i sve te Toolbarove koje imas jer ti ne koriste mnogo cemu a znaju da uspore sistem.


Arrow Kada sve to odradis, ponovo pokreni DDS i kopiraj/okaci mi oba loga koja dobijes:

1. DDS.txt
2. Attach.txt

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.3244 BrowserJavaVersion: 1.6.0_31
Run by Marko at 23:47:45 on 2012-04-20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.625 [GMT 2:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webteh\BSplayer\bsplayer.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASC.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
C:\WINDOWS\system32\msiexec.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
mDefault_Page_URL = [Link mogu videti samo ulogovani korisnici]
mDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
mSearch Page = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
mSearch Bar = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = proxy.vektor.net:8080
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SWEETIE: {1a0aadcd-3a72-4b5f-900f-e3bb5a838e2a} - SWEETIE Class
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} -
TB: {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [Google Update] "c:\documents and settings\marko\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
uRun: [MCShield Monitor] c:\program files\mcshield\mcshieldrtm.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [<NO NAME>]
mRun: [SearchSettings] c:\program files\common files\spigot\search settings\searchsettings.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
LSP: mswsock.dll
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{6B9952E5-896F-4F20-9427-C0111EBFFD15} : DhcpNameServer = 89.216.1.30 89.216.1.50
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: TPSvc - TPSvc.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\marko\application data\mozilla\firefox\profiles\8ugh0x66.default\
FF - prefs.js: browser.search.defaulturl - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: browser.search.selectedEngine - Speedbit Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: network.proxy.ftp - proxy.vektor.net
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - proxy.vektor.net
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.vektor.net
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.vektor.net
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\marko\local settings\application data\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_233.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-11-30 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-11-30 337880]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2012-2-29 279552]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2012-3-29 490840]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-4-12 784792]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-11-30 20696]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-11-30 44768]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-4-20 2348352]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2012-2-29 25984]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [2008-5-19 4096]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys --> c:\windows\system32\drivers\epfwtdir.sys [?]
S1 GhPciScan;GhostPciScanner;\??\c:\program files\symantec\norton ghost 2003\ghpciscan.sys --> c:\program files\symantec\norton ghost 2003\ghpciscan.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-2 253088]
S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver; [x]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\drivers\genericmount.sys --> c:\windows\system32\drivers\GenericMount.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\x:\ntglm7x.sys --> x:\NTGLM7X.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-04-20 21:42:42 -------- d-----w- c:\documents and settings\marko\application data\IObit
2012-04-20 16:51:18 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-04-20 16:51:18 15494464 ----a-w- c:\windows\system32\nvcpl.dll
2012-04-20 16:51:18 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-04-20 16:51:18 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-04-20 16:51:04 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-04-20 16:46:01 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-04-20 16:45:44 17534976 ----a-w- c:\windows\system32\nvcompiler.dll
2012-04-20 16:08:34 -------- d-----w- c:\documents and settings\all users\application data\MCShield
2012-04-20 16:08:33 -------- d-----w- c:\program files\MCShield
2012-04-20 15:34:58 -------- d-----w- c:\program files\Trend Micro
2012-04-20 07:36:57 1409 ----a-w- c:\windows\QTFont.for
2012-04-19 12:01:45 -------- d-----w- c:\documents and settings\marko\local settings\application data\ApplicationHistory
2012-04-10 08:12:29 -------- d-----w- C:\Download
2012-04-07 08:24:05 -------- d-----w- c:\documents and settings\marko\local settings\application data\Adobe
2012-04-04 14:37:26 -------- d-----w- c:\documents and settings\marko\application data\uTorrent
2012-04-04 08:25:00 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
2012-04-04 08:12:18 16062464 ------r- c:\windows\RTHDCPL.exe
2012-04-04 08:09:47 69632 ------r- c:\windows\Alcmtr.exe
2012-04-04 08:09:10 315392 ----a-w- c:\windows\HideWin.exe
2012-04-03 21:21:11 -------- d-----w- c:\windows\nview
2012-04-02 20:26:48 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 09:01:47 -------- d-----w- c:\program files\common files\SpeedBit
2012-04-02 09:01:45 84480 ----a-w- c:\windows\system32\EasyHook32.dll
2012-04-02 09:01:45 102912 ----a-w- c:\windows\system32\EasyHook64.dll
2012-04-02 09:01:36 -------- d-----w- c:\documents and settings\marko\application data\Toolbar4
2012-04-02 09:01:33 -------- d-----w- c:\documents and settings\all users\application data\SpeedBit
2012-04-02 09:01:32 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2012-04-01 23:32:24 -------- d-----w- c:\documents and settings\all users\application data\YTD YouTube Downloader & Converter
2012-03-31 17:17:32 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-28 17:06:42 -------- d-----w- c:\windows\system32\AGEIA
2012-03-28 17:05:43 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2012-03-28 16:53:23 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-03-28 16:53:23 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-03-28 16:53:08 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2012-03-28 16:53:08 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-03-27 12:12:36 -------- d-----w- C:\$WIN_NT$.~BT
2012-03-27 12:09:27 -------- d-----w- c:\windows\setup.pss
2012-03-27 12:01:58 -------- d-----w- c:\program files\Alcohol Soft
2012-03-26 09:28:38 -------- d-----w- c:\documents and settings\all users\application data\DivX
2012-03-25 20:48:25 -------- d-----w- c:\program files\CCleaner
.
==================== Find3M ====================
.
2012-04-20 16:59:09 294604 ----a-w- c:\windows\system32\nvdrsdb1.bin
2012-04-20 16:59:09 294604 ----a-w- c:\windows\system32\nvdrsdb0.bin
2012-04-20 16:59:09 1 ----a-w- c:\windows\system32\nvdrssel.bin
2012-04-14 20:20:37 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-31 17:16:54 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-27 11:59:04 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-03-07 00:15:19 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:03:51 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-02-29 23:58:00 881984 ----a-w- c:\windows\system32\nvgenco32.dll
2012-02-29 23:58:00 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-29 23:58:00 5918720 ----a-w- c:\windows\system32\nvcuda.dll
2012-02-29 23:58:00 4309760 ----a-w- c:\windows\system32\nv4_disp.dll
2012-02-29 23:58:00 2522944 ----a-w- c:\windows\system32\nvcuvid.dll
2012-02-29 23:58:00 2291712 ----a-w- c:\windows\system32\nvapi.dll
2012-02-29 23:58:00 18624512 ----a-w- c:\windows\system32\nvoglnt.dll
2012-02-29 23:58:00 13417632 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-02-29 23:58:00 1000256 ----a-w- c:\windows\system32\nvdispco32.dll
.
============= FINISH: 23:50:25.17 ===============




[Link mogu videti samo ulogovani korisnici]




[Link mogu videti samo ulogovani korisnici]

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Odradi sledece:

Arrow Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

Napisano: 21 Apr 2012 0:50

ComboFix 12-04-20.03 - Marko 04/21/2012 0:29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.656 [GMT 2:00]
Running from: c:\documents and settings\Marko\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Marko\Application Data\Toolbar4
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\about SpeedBit Video Downloader.html
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\amazon_logo.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Ask-logo-16.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\basis.xml
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\cog.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Ebay-logo-16.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\empty.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\info.txt
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\localcopy.xml
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Mercado_Livre.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Mercado_Livre0.1.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\speedbit_icon0.2.bmp
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\speedbit_icon0.2.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\SpeedBitToolbar_icons.bmp
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\TbHelper2.exe
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Translate_webpage.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\uninstall.exe
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\update.exe
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\version.txt
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\video.png
c:\documents and settings\Marko\Application Data\vso_ts_preview.xml
c:\documents and settings\Marko\Templates\Temp.exe
c:\program files\MSNCS
c:\program files\MSNCS\data\emxfile001.dat
c:\program files\MSNCS\data\msnusr.ini
c:\program files\MSNCS\data\ps_demo_report.html
c:\program files\MSNCS\data\testftpok.html
c:\program files\MSNCS\help.chm
c:\program files\MSNCS\License.txt
c:\program files\MSNCS\logs\Log5192008124518.html
c:\program files\MSNCS\logs\Log5192008125053.html
c:\program files\MSNCS\logs\Log5192008125825.html
c:\program files\MSNCS\readme.txt
c:\program files\MSNCS\unins000.dat
c:\program files\MSNCS\unins000.exe
c:\windows\$NtUninstallKB14960$
c:\windows\$NtUninstallKB14960$\2136390361\@
c:\windows\$NtUninstallKB14960$\2136390361\L\tzweokge
c:\windows\$NtUninstallKB14960$\2136390361\loader.tlb
c:\windows\$NtUninstallKB14960$\2136390361\U\@00000001
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000c0
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000cb
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000cf
c:\windows\$NtUninstallKB14960$\2136390361\U\@80000000
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000c0
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000cb
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000cf
c:\windows\$NtUninstallKB14960$\3395889811
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\
c:\windows\system32\closeapp.exe
c:\windows\system32\mxpvct22.dat
c:\windows\system32\mxpvct25.dat
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2012-03-20 to 2012-04-20 )))))))))))))))))))))))))))))))
.
.
2012-04-20 21:42 . 2012-04-20 21:47 -------- d-----w- c:\documents and settings\Marko\Application Data\IObit
2012-04-20 16:52 . 2012-04-20 16:52 -------- d-----w- c:\documents and settings\UpdatusUser.MARKO-B6212365F
2012-04-20 16:51 . 2012-02-29 20:30 15494464 ----a-w- c:\windows\system32\nvcpl.dll
2012-04-20 16:51 . 2012-02-29 20:30 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-04-20 16:51 . 2012-02-29 20:30 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-04-20 16:51 . 2012-02-29 20:30 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-04-20 16:51 . 2012-02-29 20:30 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-04-20 16:46 . 2012-02-29 23:58 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-04-20 16:45 . 2012-02-29 23:58 17534976 ----a-w- c:\windows\system32\nvcompiler.dll
2012-04-20 16:08 . 2012-04-20 20:27 -------- d-----w- c:\documents and settings\All Users\Application Data\MCShield
2012-04-20 16:08 . 2012-04-20 16:08 -------- d-----w- c:\program files\MCShield
2012-04-20 15:34 . 2012-04-20 15:34 -------- d-----w- c:\program files\Trend Micro
2012-04-20 07:36 . 2012-04-20 07:36 1409 ----a-w- c:\windows\QTFont.for
2012-04-19 12:01 . 2012-04-19 12:01 -------- d-----w- c:\documents and settings\Marko\Local Settings\Application Data\ApplicationHistory
2012-04-10 08:12 . 2012-04-10 08:24 -------- d-----w- C:\Download
2012-04-07 08:24 . 2012-04-11 13:33 -------- d-----w- c:\documents and settings\Marko\Local Settings\Application Data\Adobe
2012-04-04 14:37 . 2012-04-06 12:23 -------- d-----w- c:\documents and settings\Marko\Application Data\uTorrent
2012-04-04 08:25 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2012-04-04 08:12 . 2006-12-19 03:12 16062464 ------r- c:\windows\RTHDCPL.exe
2012-04-04 08:09 . 2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
2012-04-04 08:09 . 2012-04-04 08:09 315392 ----a-w- c:\windows\HideWin.exe
2012-04-03 21:38 . 2012-04-03 21:38 -------- d-----w- c:\documents and settings\UpdatusUser\Searches
2012-04-03 21:27 . 2012-04-03 21:27 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2012-04-03 21:21 . 2012-04-03 21:57 -------- d-----w- c:\windows\nview
2012-04-02 20:26 . 2012-04-14 20:20 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 09:01 . 2012-04-02 09:01 -------- d-----w- c:\program files\Common Files\SpeedBit
2012-04-02 09:01 . 2012-04-02 09:01 84480 ----a-w- c:\windows\system32\EasyHook32.dll
2012-04-02 09:01 . 2012-04-02 09:01 102912 ----a-w- c:\windows\system32\EasyHook64.dll
2012-04-02 09:01 . 2012-04-02 14:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2012-04-02 09:01 . 1998-12-05 11:18 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2012-04-01 23:32 . 2012-04-01 23:32 -------- d-----w- c:\documents and settings\All Users\Application Data\YTD YouTube Downloader & Converter
2012-03-31 17:18 . 2012-03-31 17:18 -------- d-----w- c:\program files\Common Files\Java
2012-03-31 17:17 . 2012-03-31 17:16 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-28 17:06 . 2012-03-28 17:06 -------- d-----w- c:\windows\system32\AGEIA
2012-03-28 17:06 . 2012-03-28 17:07 -------- d-----w- c:\program files\AGEIA Technologies
2012-03-28 17:05 . 2012-03-28 17:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-03-28 16:53 . 2001-08-17 11:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-03-28 16:53 . 2001-08-17 11:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-03-28 16:53 . 2007-10-30 16:47 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2012-03-28 16:53 . 2007-10-30 16:47 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-03-27 12:12 . 2012-03-27 12:12 -------- d-----w- C:\$WIN_NT$.~BT
2012-03-27 12:01 . 2012-03-27 12:01 -------- d-----w- c:\program files\Alcohol Soft
2012-03-26 09:28 . 2012-03-26 09:28 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2012-03-25 20:48 . 2012-03-25 20:48 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 20:20 . 2011-11-28 18:57 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-31 17:16 . 2012-02-02 10:14 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-27 11:59 . 2007-12-09 15:58 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-03-07 00:15 . 2011-11-30 11:57 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:15 . 2012-03-08 21:14 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-07 00:03 . 2011-11-30 11:58 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-07 00:03 . 2011-11-30 11:58 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-07 00:02 . 2011-11-30 11:58 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-07 00:01 . 2011-11-30 11:58 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-07 00:01 . 2011-11-30 11:58 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-03-07 00:01 . 2011-11-30 11:58 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-03-07 00:01 . 2011-11-30 11:58 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-06 23:58 . 2011-11-30 11:58 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-02-29 23:58 . 2011-11-28 13:50 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-29 23:58 . 2011-11-28 13:50 881984 ----a-w- c:\windows\system32\nvgenco32.dll
2012-02-29 23:58 . 2011-11-28 13:50 2522944 ----a-w- c:\windows\system32\nvcuvid.dll
2012-02-29 23:58 . 2011-11-28 13:50 1000256 ----a-w- c:\windows\system32\nvdispco32.dll
2012-02-29 23:58 . 2008-12-25 22:08 5918720 ----a-w- c:\windows\system32\nvcuda.dll
2012-02-29 23:58 . 2008-12-25 22:08 2291712 ----a-w- c:\windows\system32\nvapi.dll
2012-02-29 23:58 . 2008-12-25 22:08 18624512 ----a-w- c:\windows\system32\nvoglnt.dll
2012-02-29 23:58 . 2006-08-16 07:35 4309760 ----a-w- c:\windows\system32\nv4_disp.dll
2012-02-29 23:58 . 2006-08-16 07:35 13417632 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-03-18 08:38 . 2012-02-24 02:23 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-02-29 15494464]
"NvMediaCenter"="NvMCTray.dll" [2012-02-29 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-02-29 1634112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-10-30 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Marko^Start Menu^Programs^Startup^YouTube Uploader.lnk]
backup=c:\windows\pss\YouTube Uploader.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiweeHook
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magentic
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5]
2011-11-12 08:42 1647448 ----a-w- c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-03-23 09:42 136176 ----atw- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCShield Monitor]
2012-03-12 20:25 583680 ----a-w- c:\program files\MCShield\MCShieldRTM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 21:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 10:04 2879488 ------r- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56528:TCP"= 56528:TCP:Pando Media Booster
"56528:UDP"= 56528:UDP:Pando Media Booster
"57294:TCP"= 57294:TCP:Pando Media Booster
"57294:UDP"= 57294:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/9/2007 5:58 PM 697328]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [11/30/2011 1:58 PM 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11/30/2011 1:58 PM 337880]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2/29/2012 11:17 PM 279552]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [3/29/2012 9:56 AM 490840]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [4/12/2012 10:31 AM 784792]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/30/2011 1:58 PM 20696]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [4/20/2012 6:51 PM 2348352]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2/29/2012 11:17 PM 25984]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [5/19/2008 1:04 AM 4096]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys --> c:\windows\system32\DRIVERS\epfwtdir.sys [?]
S1 GhPciScan;GhostPciScanner;\??\c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys --> c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/2/2012 10:26 PM 253088]
S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver; [x]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys --> c:\windows\system32\DRIVERS\GenericMount.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\x:\ntglm7x.sys --> x:\NTGLM7X.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 20:20]
.
2012-04-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
.
2012-04-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1532298954-682003330-1007Core.job
- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-23 09:42]
.
2012-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1532298954-682003330-1007UA.job
- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-23 09:42]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
mSearch Bar = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = proxy.vektor.net:8080
uInternet Settings,ProxyOverride = <local>
IE: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Marko\Application Data\Mozilla\Firefox\Profiles\8ugh0x66.default\
FF - prefs.js: browser.search.defaulturl - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: browser.search.selectedEngine - Speedbit Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: network.proxy.ftp - proxy.vektor.net
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - proxy.vektor.net
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.vektor.net
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.vektor.net
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
Notify-TPSvc - TPSvc.dll
SafeBoot-Wdf01000.sys
MSConfigStartUp-SearchSettings - c:\program files\common files\spigot\search settings\searchsettings.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2012-04-21 00:43
Windows 5.1.2600 Service Pack 3, v.3244 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RunDLL32.exe
.
**************************************************************************
.
Completion time: 2012-04-21 00:47:21 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-20 22:47
.
Pre-Run: 22,582,022,144 bytes free
Post-Run: 22,570,954,752 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
Timeout=2
Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /usepmtimer /NoExecute=OptOut
.
- - End Of File - - 8733AB146D7A575B905CB797837018B0




[Link mogu videti samo ulogovani korisnici]

Dopuna: 21 Apr 2012 1:12

c:\windows\$NtUninstallKB14960$
c:\windows\$NtUninstallKB14960$\2136390361\@
c:\windows\$NtUninstallKB14960$\2136390361\L\tzweokge
c:\windows\$NtUninstallKB14960$\2136390361\loader.tlb
c:\windows\$NtUninstallKB14960$\2136390361\U\@00000001
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000c0
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000cb
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000cf
c:\windows\$NtUninstallKB14960$\2136390361\U\@80000000
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000c0
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000cb
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000cf
c:\windows\$NtUninstallKB14960$\3395889811
---------------------------------------------------------------------------

Ovo me unistilo.... sad se secam GUZ - Glavom U Zid

Dopuna: 21 Apr 2012 10:38

magma batice jel treba jos nesto da se radi ...


[Link mogu videti samo ulogovani korisnici]


Sta sad ?

Dopuna: 21 Apr 2012 10:40

magna Very Happy Very Happy Very Happy

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

MareBatice :: magna Very Happy Very Happy Very Happy

Polako druze, imam ja i svoj privatni zivot Wink




Korak #1
Logovi pokazuju tragove ostataka od ESET-a i Lavasoft Ad Watch Antivirusa:

Arrow Te ostatke ces ukloniti pomocu programa AppRemover

Procitaj taj clanak i isprati uputstvo da bi uklonio te ostatke:
Izabraces ovu opciju:
Clean Up a Failed Uninstall!

Takodje ti preporucujem da deinstaliras "SweetIM For Internet Explorer 3.0b" , a ja cu ukloniti ostatke Spigot Inc-a




.




Korak#2

Otvoriti Notepad i iskopirati sledeci tekst:


Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]

DDS::
uStart Page = hxxp://search.speedbit.com/?aff=svd_0

Firefox::
FF - ProfilePath - c:\documents and settings\Marko\Application Data\Mozilla\Firefox\Profiles\8ugh0x66.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=
FF - prefs.js: browser.search.selectedEngine - Speedbit Search
FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=

ClearJavaCache::

Driver::
Application Updater

Folder::
c:\program files\Application Updater



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

Ma opusteno ,nisi me razumeo samo sam napisao ispravno tvoj nick jer 1 put sam pogresio ... Smile

A program AppRemover

Pod opcijom Clean UP a Failed Uninstall nista mi nije naso ...


ComboFix 12-04-20.03 - Marko 04/21/2012 12:14:40.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.616 [GMT 2:00]
Running from: c:\documents and settings\Marko\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Marko\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Application Updater
c:\program files\Application Updater\ApplicationUpdater.exe
c:\program files\Application Updater\config.ini
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_APPLICATION_UPDATER
-------\Service_Application Updater
.
.
((((((((((((((((((((((((( Files Created from 2012-03-21 to 2012-04-21 )))))))))))))))))))))))))))))))
.
.
2012-04-20 21:42 . 2012-04-20 21:47 -------- d-----w- c:\documents and settings\Marko\Application Data\IObit
2012-04-20 16:52 . 2012-04-20 16:52 -------- d-----w- c:\documents and settings\UpdatusUser.MARKO-B6212365F
2012-04-20 16:51 . 2012-02-29 20:30 15494464 ----a-w- c:\windows\system32\nvcpl.dll
2012-04-20 16:51 . 2012-02-29 20:30 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-04-20 16:51 . 2012-02-29 20:30 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-04-20 16:51 . 2012-02-29 20:30 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-04-20 16:51 . 2012-02-29 20:30 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-04-20 16:46 . 2012-02-29 23:58 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-04-20 16:45 . 2012-02-29 23:58 17534976 ----a-w- c:\windows\system32\nvcompiler.dll
2012-04-20 16:08 . 2012-04-20 20:27 -------- d-----w- c:\documents and settings\All Users\Application Data\MCShield
2012-04-20 16:08 . 2012-04-20 16:08 -------- d-----w- c:\program files\MCShield
2012-04-20 15:34 . 2012-04-20 15:34 -------- d-----w- c:\program files\Trend Micro
2012-04-20 07:36 . 2012-04-20 07:36 1409 ----a-w- c:\windows\QTFont.for
2012-04-19 12:01 . 2012-04-19 12:01 -------- d-----w- c:\documents and settings\Marko\Local Settings\Application Data\ApplicationHistory
2012-04-10 08:12 . 2012-04-10 08:24 -------- d-----w- C:\Download
2012-04-07 08:24 . 2012-04-11 13:33 -------- d-----w- c:\documents and settings\Marko\Local Settings\Application Data\Adobe
2012-04-04 14:37 . 2012-04-06 12:23 -------- d-----w- c:\documents and settings\Marko\Application Data\uTorrent
2012-04-04 08:25 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2012-04-04 08:12 . 2006-12-19 03:12 16062464 ------r- c:\windows\RTHDCPL.exe
2012-04-04 08:09 . 2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
2012-04-04 08:09 . 2012-04-04 08:09 315392 ----a-w- c:\windows\HideWin.exe
2012-04-03 21:38 . 2012-04-03 21:38 -------- d-----w- c:\documents and settings\UpdatusUser\Searches
2012-04-03 21:27 . 2012-04-03 21:27 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2012-04-03 21:21 . 2012-04-03 21:57 -------- d-----w- c:\windows\nview
2012-04-02 20:26 . 2012-04-14 20:20 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 09:01 . 2012-04-02 09:01 -------- d-----w- c:\program files\Common Files\SpeedBit
2012-04-02 09:01 . 2012-04-02 09:01 84480 ----a-w- c:\windows\system32\EasyHook32.dll
2012-04-02 09:01 . 2012-04-02 09:01 102912 ----a-w- c:\windows\system32\EasyHook64.dll
2012-04-02 09:01 . 2012-04-02 14:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2012-04-02 09:01 . 1998-12-05 11:18 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2012-04-01 23:32 . 2012-04-01 23:32 -------- d-----w- c:\documents and settings\All Users\Application Data\YTD YouTube Downloader & Converter
2012-03-31 17:18 . 2012-03-31 17:18 -------- d-----w- c:\program files\Common Files\Java
2012-03-31 17:17 . 2012-03-31 17:16 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-28 17:06 . 2012-03-28 17:06 -------- d-----w- c:\windows\system32\AGEIA
2012-03-28 17:06 . 2012-03-28 17:07 -------- d-----w- c:\program files\AGEIA Technologies
2012-03-28 17:05 . 2012-03-28 17:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-03-28 16:53 . 2001-08-17 11:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-03-28 16:53 . 2001-08-17 11:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-03-28 16:53 . 2007-10-30 16:47 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2012-03-28 16:53 . 2007-10-30 16:47 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-03-27 12:12 . 2012-03-27 12:12 -------- d-----w- C:\$WIN_NT$.~BT
2012-03-27 12:01 . 2012-03-27 12:01 -------- d-----w- c:\program files\Alcohol Soft
2012-03-26 09:28 . 2012-03-26 09:28 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2012-03-25 20:48 . 2012-03-25 20:48 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 20:20 . 2011-11-28 18:57 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-31 17:16 . 2012-02-02 10:14 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-27 11:59 . 2007-12-09 15:58 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-03-07 00:15 . 2011-11-30 11:57 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:15 . 2012-03-08 21:14 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-07 00:03 . 2011-11-30 11:58 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-07 00:03 . 2011-11-30 11:58 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-07 00:02 . 2011-11-30 11:58 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-07 00:01 . 2011-11-30 11:58 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-07 00:01 . 2011-11-30 11:58 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-03-07 00:01 . 2011-11-30 11:58 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-03-07 00:01 . 2011-11-30 11:58 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-06 23:58 . 2011-11-30 11:58 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-02-29 23:58 . 2011-11-28 13:50 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-29 23:58 . 2011-11-28 13:50 881984 ----a-w- c:\windows\system32\nvgenco32.dll
2012-02-29 23:58 . 2011-11-28 13:50 2522944 ----a-w- c:\windows\system32\nvcuvid.dll
2012-02-29 23:58 . 2011-11-28 13:50 1000256 ----a-w- c:\windows\system32\nvdispco32.dll
2012-02-29 23:58 . 2008-12-25 22:08 5918720 ----a-w- c:\windows\system32\nvcuda.dll
2012-02-29 23:58 . 2008-12-25 22:08 2291712 ----a-w- c:\windows\system32\nvapi.dll
2012-02-29 23:58 . 2008-12-25 22:08 18624512 ----a-w- c:\windows\system32\nvoglnt.dll
2012-02-29 23:58 . 2006-08-16 07:35 4309760 ----a-w- c:\windows\system32\nv4_disp.dll
2012-02-29 23:58 . 2006-08-16 07:35 13417632 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-03-18 08:38 . 2012-02-24 02:23 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( [Link mogu videti samo ulogovani korisnici] )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-21 10:27 . 2012-04-21 10:27 16384 c:\windows\Temp\Perflib_Perfdata_7a0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-11-12 1647448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-02-29 15494464]
"NvMediaCenter"="NvMCTray.dll" [2012-02-29 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-02-29 1634112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-10-30 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Marko^Start Menu^Programs^Startup^YouTube Uploader.lnk]
backup=c:\windows\pss\YouTube Uploader.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5]
2011-11-12 08:42 1647448 ----a-w- c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-03-23 09:42 136176 ----atw- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCShield Monitor]
2012-03-12 20:25 583680 ----a-w- c:\program files\MCShield\MCShieldRTM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 21:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 10:04 2879488 ------r- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56528:TCP"= 56528:TCP:Pando Media Booster
"56528:UDP"= 56528:UDP:Pando Media Booster
"57294:TCP"= 57294:TCP:Pando Media Booster
"57294:UDP"= 57294:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/9/2007 5:58 PM 697328]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [11/30/2011 1:58 PM 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11/30/2011 1:58 PM 337880]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2/29/2012 11:17 PM 279552]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [3/29/2012 9:56 AM 490840]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/30/2011 1:58 PM 20696]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [4/20/2012 6:51 PM 2348352]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2/29/2012 11:17 PM 25984]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [5/19/2008 1:04 AM 4096]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys --> c:\windows\system32\DRIVERS\epfwtdir.sys [?]
S1 GhPciScan;GhostPciScanner;\??\c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys --> c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/2/2012 10:26 PM 253088]
S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver; [x]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys --> c:\windows\system32\DRIVERS\GenericMount.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\x:\ntglm7x.sys --> x:\NTGLM7X.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 20:20]
.
2012-04-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
.
2012-04-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1532298954-682003330-1007Core.job
- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-23 09:42]
.
2012-04-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1532298954-682003330-1007UA.job
- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-23 09:42]
.
.
------- Supplementary Scan -------
.
mSearch Bar = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = proxy.vektor.net:8080
uInternet Settings,ProxyOverride = <local>
IE: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Marko\Application Data\Mozilla\Firefox\Profiles\8ugh0x66.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: network.proxy.ftp - proxy.vektor.net
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - proxy.vektor.net
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.vektor.net
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.vektor.net
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2012-04-21 12:28
Windows 5.1.2600 Service Pack 3, v.3244 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RunDLL32.exe
c:\program files\AVAST Software\Avast\setup\avast.setup
.
**************************************************************************
.
Completion time: 2012-04-21 12:32:42 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-21 10:32
ComboFix2.txt 2012-04-20 22:47
.
Pre-Run: 22,243,041,280 bytes free
Post-Run: 22,077,931,520 bytes free
.
- - End Of File - - F3F758B88BEC216A636A00F46552EF40

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6104

Idea Sto se tice samog malware-a, imao si na sistemu aktivan ZeroAccess i on je sad uklonjen.
Na sistemu vise nemas aktivnog malware-a.




Arrow Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.





Arrow Poseti ovu temu:
[Link mogu videti samo ulogovani korisnici]
Preuzmi ESET Uninstaller i alat pokreni iz Safe Moda po uputstvu.

To bi bilo to. Pozdrav. Wink

Ko je trenutno na forumu
 

Ukupno su 1899 korisnika na forumu :: 82 registrovanih, 3 sakrivenih i 1814 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 6018 - dana 19 Dec 2025 13:41

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Antoni S, Apis Dr, aramis s, Avalon015, bojank, BOXRR, brandža84, CHARLIE JA., cifra, Cigi, Colt D, Comyymoc, Crazzer, crnitrn, deLacy, Despot Đurađ, DezurniOperativni, dijica, DJUNTA, Dogma21, dragoljub11987, dule10savic, dusko barajevo, Dzoni70, gobrad, GveX, ikan, istina, Jan, janbo, Jezekijel, Joksss, Jonbonjovi, Još malo pa deda, Kajzer Soze, Kalem, kibihrchak, knutveliki, Kubovac, Kudun, kuntalo, leopard83, MarkoW, mean_machine, mige84, Milos1389, Misterrno, moldway, mrkanidja, Neutral-M, Nikola70, niksa517, Nomica, Paklenica, Panter, Papadubi, pceklic, pein, pisac12, powSrb, RJ, Robin, rokokoko, sekretar, Shajlok, Singidunumac, SlaKoj, Smiljke, Smiljkovich, spot4chulle, Stanlio, Str2022, vaci, vathra, VJ, yagosh, YFSS33, yip314, zdrebac, zexon, zubri