[bobby] JAD i CEMER

[bobby] JAD i CEMER

offline
  • Pridružio: 24 Apr 2007
  • Poruke: 31

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:27:13 PM, on 2/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\s t e l e k s\Desktop\jad i cemer\dilindara.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\dse235rgd0.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kxva] C:\WINDOWS\system32\kxvo.exe
O4 - HKCU\..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

--
End of file - 3004 bytes



offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

* Pokreni ESET Smart Security/ESET NOD32 na sledeci nacin :
Start>All Programs>ESET>ESET Smart Security ili pak ESET NOD32 Antivirus(ukoliko koristis samo Antivirus resenje).

* Kada ti se otvori glavni prozor programa, klikni na Setup opciju sa leve strane prozora;
* Izaberi Antivirus and antispyware opciju i klikni na Temporarily disable Antivirus and antispyware protection.
* Na sledece pitanje klikni Yes.

Napomena: Ne zaboravi da ukljuciš ovu opciju po završetku cišcenja.



Skini ComboFix sa jedne od sledecih adresa na Desktop:
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.



offline
  • Pridružio: 24 Apr 2007
  • Poruke: 31

ComboFix 09-02-19.01 - s t e l e k s 2009-02-21 20:29:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.304 [GMT 1:00]
Running from: c:\documents and settings\s t e l e k s\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
C:\jj.cmd
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\isee.exe
c:\windows\system32\dse235rgd0.dll
c:\windows\system32\kxvo.exe
c:\windows\system32\wedasgads0.dll
c:\windows\system32\wedasgads1.dll
D:\Autorun.inf
D:\jj.cmd

.
((((((((((((((((((((((((( Files Created from 2009-01-21 to 2009-02-21 )))))))))))))))))))))))))))))))
.

2009-02-21 20:18 . 2008-09-16 20:23 168,448 --a------ c:\windows\system32\unrar.dll
2009-02-21 20:17 . 2009-02-21 20:17 <DIR> d-------- c:\program files\K-Lite Codec Pack
2009-02-21 20:06 . 2008-01-07 14:29 352 --ah----- c:\windows\nod32fixtemdono.reg
2009-02-21 20:05 . 2009-02-21 20:05 <DIR> d-------- c:\program files\Webteh
2009-02-21 20:05 . 2009-02-21 20:05 <DIR> d-------- c:\documents and settings\s t e l e k s\Application Data\BSplayer Pro
2009-02-21 02:18 . 2009-02-21 02:18 <DIR> d-------- c:\program files\Atomic Alarm Clock

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 22:48 2,330,643 ----a-w c:\windows\system32\x264vfw.dll
2008-12-21 00:48 --------- d-----w c:\documents and settings\s t e l e k s\Application Data\Winamp
2008-12-19 08:37 189,330 --sh--r C:\ab31.exe
2008-12-17 07:55 186,269 --sh--r C:\dkpiw.com
2008-12-08 11:53 57,344 ----a-w c:\windows\system32\ff_vfw.dll
2008-12-07 18:08 795,648 ----a-w c:\windows\system32\xvidcore.dll
2008-12-07 18:08 130,048 ----a-w c:\windows\system32\xvidvfw.dll
2008-11-01 15:48 16,384 --sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-11-01 15:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2008-11-01 15:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008110120081102\index.dat
2008-11-01 15:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-03-05 526848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2007-12-21 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{329e0580-a98d-11dd-95d1-00300520b2e4}]
\Shell\AutoRun\command - dwg3gngs.exe
\Shell\explore\Command - dwg3gngs.exe
\Shell\open\Command - dwg3gngs.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a9a07e0-cedd-11dd-9608-00300520b2e4}]
\Shell\AutoRun\command - G:\jj.cmd
\Shell\explore\Command - G:\jj.cmd
\Shell\open\Command - G:\jj.cmd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ace51080-adab-11dd-95d8-d82f6386b960}]
\Shell\AutoRun\command - F:\dwg3gngs.exe
\Shell\explore\Command - F:\dwg3gngs.exe
\Shell\open\Command - F:\dwg3gngs.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ace51081-adab-11dd-95d8-d82f6386b960}]
\Shell\AutoRun\command - F:\dwg3gngs.exe
\Shell\explore\Command - F:\dwg3gngs.exe
\Shell\open\Command - F:\dwg3gngs.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5846710-a860-11dd-95d0-00300520b2e4}]
\Shell\AutoRun\command - F:\jj.cmd
\Shell\explore\Command - F:\jj.cmd
\Shell\open\Command - F:\jj.cmd
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
FF - ProfilePath - c:\documents and settings\s t e l e k s\Application Data\Mozilla\Firefox\Profiles\wl3ivayj.default\
FF - prefs.js: browser.search.selectedEngine - YouTube Video Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-02-21 20:30:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-21 20:32:28
ComboFix-quarantined-files.txt 2009-02-21 19:32:24

Pre-Run: 855,437,312 bytes free
Post-Run: 865,427,456 bytes free

116

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\ab31.exe
C:\dkpiw.com

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{329e0580-a98d-11dd-95d1-00300520b2e4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a9a07e0-cedd-11dd-9608-00300520b2e4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ace51080-adab-11dd-95d8-d82f6386b960}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ace51081-adab-11dd-95d8-d82f6386b960}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5846710-a860-11dd-95d0-00300520b2e4}]


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

=============================

- Preuzmi USBNoRisk na Desktop i pokreni ga duplim klikom na ikonicu programa.
- Sacekaj koji sekund dok program izvrsi inicijalno skeniranje.
- Ubacuj sve USB memorijske uredjaje redom u USB slot i svaki zadrzi u slotu po 10 sekundi.
- Ukoliko imas vise uredjaja za proveru, onda na parcetu papira zapisi kojim redom su ubacivani jer ce nam kasnije trebati taj podatak
- Kada zavrsis sa svim uredjajima, klikni desno dugme misa na sred prozora programa i odaberi opciju Save log. To ce automatski otvoriti log u Notepadu. Iskopiraj nam taj log iz Notepada na forum.

Objasnjenje: U USB memorijske uredjaje spadaju svi oni uredjaji koji po prikljucivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uredjaji itd.

offline
  • Pridružio: 24 Apr 2007
  • Poruke: 31

ComboFix 09-02-19.01 - s t e l e k s 2009-02-21 20:47:06.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.232 [GMT 1:00]
Running from: c:\documents and settings\s t e l e k s\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\s t e l e k s\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\ab31.exe
C:\dkpiw.com
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\ab31.exe
C:\dkpiw.com

.
((((((((((((((((((((((((( Files Created from 2009-01-21 to 2009-02-21 )))))))))))))))))))))))))))))))
.

2009-02-21 20:18 . 2008-09-16 20:23 168,448 --a------ c:\windows\system32\unrar.dll
2009-02-21 20:17 . 2009-02-21 20:17 <DIR> d-------- c:\program files\K-Lite Codec Pack
2009-02-21 20:06 . 2008-01-07 14:29 352 --ah----- c:\windows\nod32fixtemdono.reg
2009-02-21 20:05 . 2009-02-21 20:05 <DIR> d-------- c:\program files\Webteh
2009-02-21 20:05 . 2009-02-21 20:05 <DIR> d-------- c:\documents and settings\s t e l e k s\Application Data\BSplayer Pro
2009-02-21 02:18 . 2009-02-21 02:18 <DIR> d-------- c:\program files\Atomic Alarm Clock

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 22:48 2,330,643 ----a-w c:\windows\system32\x264vfw.dll
2008-12-21 00:48 --------- d-----w c:\documents and settings\s t e l e k s\Application Data\Winamp
2008-12-08 11:53 57,344 ----a-w c:\windows\system32\ff_vfw.dll
2008-12-07 18:08 795,648 ----a-w c:\windows\system32\xvidcore.dll
2008-12-07 18:08 130,048 ----a-w c:\windows\system32\xvidvfw.dll
2008-11-01 15:48 16,384 --sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
2008-11-01 15:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2008-11-01 15:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008110120081102\index.dat
2008-11-01 15:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-03-05 526848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2007-12-21 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
FF - ProfilePath - c:\documents and settings\s t e l e k s\Application Data\Mozilla\Firefox\Profiles\wl3ivayj.default\
FF - prefs.js: browser.search.selectedEngine - YouTube Video Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-02-21 20:48:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-21 20:50:09
ComboFix-quarantined-files.txt 2009-02-21 19:50:05
ComboFix2.txt 2009-02-21 19:32:30

Pre-Run: 855,105,536 bytes free
Post-Run: 845,975,552 bytes free

90

---------------------------------------------------------------------------------


nemam ni jednog USB-a a ni ostalih uredjaja koji idu na USB-e portove ... mozda da je neko nekada donosio USB, ali oni sada nisu tu



----------------------------------------------------------------------------------



USBNoRisk by bobby

Started at 2/21/2009 8:51:18 PM

Scanning for connected USB Mass storage...
----------------------------------------
========================================

Scanning for other storage...
----------------------------------------
D: {7d3c5d03-a82f-11dd-a9e5-806d6172696f}
C: {7d3c5d05-a82f-11dd-a9e5-806d6172696f}
========================================


Scanning fixed storage for autorun.inf files...
----------------------------------------
Autorun.inf on C: - None
----------------------------------------

Sanitizing Shell Menu...
----------------------------------------
No key found for C:
No key found for 7d3c5d05-a82f-11dd-a9e5-806d6172696f
========================================

Autorun.inf on D: - None
----------------------------------------

Sanitizing Shell Menu...
----------------------------------------
No key found for D:
No key found for 7d3c5d03-a82f-11dd-a9e5-806d6172696f
========================================

========================================

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Ja bih rekao da je ovaj racunar sada cist.

Ima li jos nekih vidljivih simptoma, ili da privedemo ciscenje kraju?

offline
  • Pridružio: 24 Apr 2007
  • Poruke: 31

Izgleda zdravo Smile
HVALA PUNO


PS: posalji mi svoju sliku da je okacim na zid pored ikone

KRALJ SI

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Potrebno je da odradis jos nesto:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore


===============================

Sliku ne mogu da ti posaljem. Ako saznas moj identitet, onda cu morati da te ubijem Mr. Green


P.S. Nadam se da znas te ninja fore i da prihvatas salu Smile

offline
  • Pridružio: 24 Apr 2007
  • Poruke: 31

Evo sada sam citao onu temu sto je onaj zarko pisao [Link mogu videti samo ulogovani korisnici]

pisao sam se od smjeha ... malo se zakoplikovalo

sale nikad nije dosta ... jos jednom puno hvala

Ko je trenutno na forumu
 

Ukupno su 3487 korisnika na forumu :: 83 registrovanih, 10 sakrivenih i 3394 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 5253 - dana 09 Dec 2025 16:26

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 100ka, 252., 9191vs, A.R.Chafee.Jr., bbrasnjo3, BOXRR, BZ, cavatina, Ciri1994, cole77, comi, cyprus, DeerHunter, Denaya, DezurniOperativni, Dimitrise93, dj.ape, draganl, Dusko Nikolin, dzada, FOX, Giskard, gorankuba, GUARIN, Hippolyte Mondain, Hitri, iceburn, Jablan, joca83, Jose, Josef, Još malo pa deda, Kajzer Soze, kenny74, kib, koko19, Kozi-RS, kuntakinte, ladro, laganini123, Lester Freamon, Lošmi, luka35, Manjane, metallac777, Mi lao shu, milanstankovic087, milenko crazy north, Millennium, Milo97, miltonhewitt6, Mis uz pusku, Mldo, Motocar, mux, N.e.m.a.nj.a., NBGD, nebidrag, oganj123, Peruta, Pilence, pirke96, Povratak1912, precan, Prečanin30, Resad76, ruma, savuni, Sevatar, shlauf, Sićko, skvara, Snorks, tubular, uljmanac, ulogovan, Vanderx, Velizar Laro, VJ, x011, yiyi, zoran77, 127