usporen rad racunara

1

usporen rad racunara

offline
  • Pridružio: 15 Feb 2012
  • Poruke: 77

primjetio sam da racunar sporo otvara datoteke,teze se pokrece,kod igrica jednostavno zakuje,sto nije bio slucaj pokusavao sam sa skeniranjem avirom personal,medjutim ne pronadje ni jedan zarazeni objekat,slucajno sam otvorio ikonicu windovs,i primjetio 93razlicita fajla $ntuninstall kb954155 wm9$,(te ikonice su nesto blijedje boje od ostalih)sto nisu bili tu,pa vas pitam da li bi rijesio problem ubrzanja da ih pokusam obrisat ako je izvodljivo bez posljedica po sistem.windovs 32 bita,.hvala unaprijed

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8448
  • Gde živiš: Novi Beograd

Zdravo,

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 15 Feb 2012
  • Poruke: 77

Napisano: 15 Feb 2012 17:26

DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_30
Run by Administrator at 17:23:24 on 2012-02-15
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\TP-LINK\TP-LINK 54M Wireless Client Utility\TWCU.exe
C:\Program Files\Olympus\ib\olycamdetect.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\IMESHA~1\MediaBar\Datamngr\DATAMN~1.EXE
C:\Program Files\Ask.com\Updater\Updater.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\dds(1).scr
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://search.babylon.com/?AF=109130&tt=090212_noffx&babsrc=HP_ss&mntrId=d0f0b59200000000000000096bed6a46
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTo0.dll
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Wincore Mediabar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\imesha~1\mediabar\datamngr\toolbar\wincoreimdtx.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files\babylontoolbar\babylontoolbar\1.5.3.17\bh\BabylonToolbar.dll
BHO: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: DataMngr: {be7a24f5-69cb-4708-b77b-b1eda6043b95} - c:\progra~1\imesha~1\mediabar\datamngr\BROWSE~1.DLL
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTo0.dll
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: GretechBHO Class: {f0181c6e-9218-4792-9f3c-e8df52b2f1ac} - c:\program files\gretech\gompicker\GomPickerBHO.dll
TB: {8dcb7100-df86-4384-8842-8fa844297b3f} - No File
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\prxtbuTo0.dll
TB: Wincore Mediabar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\imesha~1\mediabar\datamngr\toolbar\wincoreimdtx.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files\babylontoolbar\babylontoolbar\1.5.3.17\BabylonToolbarTlbr.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [MSIDLL] rundll32.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [TWCU] "c:\program files\tp-link\tp-link 54m wireless client utility\TWCU.exe" -nogui
mRun: [Olympus ib] "c:\program files\olympus\ib\olycamdetect.exe" /Startup
mRun: [MDS_Menu] "c:\program files\olympus\ib\muitransfer\muistartmenu.exe" "c:\program files\olympus\ib" updatewithcreateonce "software\olympus\ib\1.0"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [DATAMNGR] c:\progra~1\imesha~1\mediabar\datamngr\DATAMN~1.EXE
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
dPolicies-explorer: NoInstrumentation = 1 (0x1)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
LSP: c:\windows\system32\XDogcat.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1288678306750
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1287331788281
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 192.168.88.1 192.168.11.5 8.8.8.8
TCP: Interfaces\{D3C9FF96-BA57-4F3F-B103-ED4642B59D81} : DhcpNameServer = 192.168.88.1 192.168.11.5 8.8.8.8
Notify: AtiExtEvent - Ati2evxx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hbdif0er.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ba/
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hbdif0er.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hbdif0er.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}\components\RadioWMPCoreGecko19.dll
FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hbdif0er.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hbdif0er.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hbdif0er.default\extensions\engine@conduit.com\components\RadioWMPCore.dll
FF - component: c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hbdif0er.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\windows\system32\tvuax\npTVUAx.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - tt=090212_noffx
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - d0f0b59200000000000000096bed6a46
FF - user.js: extensions.BabylonToolbar_i.hardId - d0f0b59200000000000000096bed6a46
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15385
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1710:38:14
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Usluga Google a
R? ip100xp;TP-LINK 10/100Mbps PCI Network Adapter NT Driver
R? pfsvgae;pfsvgae
R? RkHit;RkHit
S? AntiVirSchedulerService;Avira AntiVir Scheduler
S? AntiVirService;Avira AntiVir Guard
S? avgio;avgio
S? avgntflt;avgntflt
S? eusk2par;EUTRON SmartKey Parallel Driver
S? seehcri;Sony Ericsson seehcri Device Driver
.
=============== Created Last 30 ================
.
2012-02-15 13:59:00 -------- d-----w- c:\documents and settings\administrator\application data\PCPro
2012-02-15 13:59:00 -------- d-----w- c:\documents and settings\administrator\application data\PC Cleaners
2012-02-15 13:58:49 -------- d-----w- c:\documents and settings\all users\application data\PC1Data
2012-02-15 09:38:17 -------- d-----w- c:\program files\BabylonToolbar
2012-02-15 08:39:14 -------- d-----w- c:\documents and settings\administrator\application data\DriverCure
2012-02-15 08:39:13 -------- d-----w- c:\documents and settings\administrator\application data\SpeedyPC Software
2012-02-15 08:38:30 -------- d-----w- c:\program files\SpeedyPC Software
2012-02-15 08:38:30 -------- d-----w- c:\documents and settings\all users\application data\SpeedyPC Software
2012-02-15 07:49:32 1 ----a-w- C:\s_pov.bin
2012-02-04 10:33:08 -------- d-----w- c:\program files\Activision
2012-01-29 09:32:01 -------- d-----w- c:\program files\Hard Truck 18 Wheels
2012-01-26 18:34:27 -------- d-----w- c:\program files\ijji
2012-01-26 18:34:18 -------- d-----w- c:\documents and settings\all users\application data\IBUpdaterService
2012-01-24 17:25:18 -------- d-----w- c:\documents and settings\administrator\application data\Capcom
2012-01-24 17:15:45 -------- d-----w- c:\program files\Capcom
2012-01-20 00:44:03 -------- d-----w- C:\LFS
2012-01-18 00:48:26 -------- d-----w- c:\documents and settings\administrator\application data\.minecraft
.
==================== Find3M ====================
.
2060-08-19 01:02:32 2023424 ------w- c:\windows\system32\Vcl50.bpl
2060-08-19 01:02:22 1496064 ------w- c:\windows\system32\Cc3250mt.dll
2060-08-19 01:02:12 248832 ------w- c:\windows\system32\Vclx50.bpl
2060-08-19 00:40:44 909824 ------w- c:\windows\system32\Cp3245mt.dll
2060-08-19 00:40:44 24064 ------w- c:\windows\system32\Borlndmm.dll
2012-02-15 14:10:36 5276432 ----a-w- c:\windows\uninst.exe
2012-02-04 07:32:50 21840 ----atw- c:\windows\system32\SIntfNT.dll
2012-02-04 07:32:50 17212 ----atw- c:\windows\system32\SIntf32.dll
2012-02-04 07:32:50 12067 ----atw- c:\windows\system32\SIntf16.dll
2012-01-23 16:54:23 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-12-10 14:24:06 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 17:24:20,82 ===============

Dopuna: 15 Feb 2012 17:32

==== Installed Programs ======================
.
7-Zip 4.65
Adobe AIR
Adobe Reader X (10.1.2)
Adobe Shockwave Player 11.6
ALNO AG Kitchen Planner
Ask Toolbar
Ask Toolbar Updater
ATI Display Driver
µTorrent
Avanquest update
Avira AntiVir Personal - Free Antivirus
Babylon toolbar on IE
Beachhead 2000
Bonampak
CCleaner (remove only)
Chicken Invaders v1.30
Chicken Invaders: Revenge of the Yolk (Christmas Edition) v3.20
CoreAAC
Data Access Objects (DAO) 3.5
DivX Total Pack
EuroPlus+ REWARD
Foxy Fox DEMO
GOM PICKER
GOM Player
Google Chrome
Google Earth
Google Update Helper
GTA San Andreas
Hard Truck 18 Wheels of Steel
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
IBM ViaVoice Command and Control Runtime 7.0 - UK English
Intel(R) Extreme Graphics Driver
Intel(R) PRO Network Connections Drivers
Java Auto Updater
Java(TM) 6 Update 30
Malwarebytes Anti-Malware verzija 1.60.1.1000
Microsoft .NET Framework 2.0
Microsoft Default Manager
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Moorhuhn Kart 2 XXL
Moorhuhn Wanted XXL
Moorhuhn Winter-Edition
Mozilla Firefox 10.0.1 (x86 en-US)
MPEG2 Codec(libmpeg2/mad)
MSN Toolbar Platform
MSXML 4.0 SP2 (KB973688-)
Notepad++
Olympus ib
OpenAL
P2PFilter 3.0.5
Penguin Racers
Readon TV Movie Radio Player 7.5.0.0
Recuva (remove only)
Sandlot Connect Version 1.2.6
Secret Maryo Chronicles
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558-)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168-)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198-)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628-)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318-)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338-)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218-)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Skype™ 4.1
Sniper v. 2.33
Spider-Man(TM) - Friend or Foe
Sunčica među brojevima
Swarm
swMSM
TP-LINK Wireless Client Utility
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB955759)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
uTorrentBar Toolbar
Veetle TV
VLC media player 1.0.2
WebFldrs XP
Winamp
Wincore MediaBar
Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
WinRAR archiver
World War Zero
YouTube Downloader 2.6.1
zmaj
Zuma's Revenge!
.
==== End Of File ===========================elvax ::primjetio sam da racunar sporo otvara datoteke,teze se pokrece,kod igrica jednostavno zakuje,sto nije bio slucaj pokusavao sam sa skeniranjem avirom personal,medjutim ne pronadje ni jedan zarazeni objekat,slucajno sam otvorio ikonicu windovs,i primjetio 93razlicita fajla $ntuninstall kb954155 wm9$,(te ikonice su nesto blijedje boje od ostalih)sto nisu bili tu,pa vas pitam da li bi rijesio problem ubrzanja da ih pokusam obrisat ako je izvodljivo bez posljedica po sistem.windovs 32 bita,.hvala unaprijed

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8448
  • Gde živiš: Novi Beograd

Nisi odradio korak 3 sa onog uputstva. Postavi mi GMER logove.

offline
  • Pridružio: 15 Feb 2012
  • Poruke: 77

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8448
  • Gde živiš: Novi Beograd

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 15 Feb 2012
  • Poruke: 77

ComboFix 12-02-15.01 - Administrator 16.02.2012 8:29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.387.1033.18.511.180 [GMT 1:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Application Data\facemoods.com
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Administrator\xmlUpdater.exe
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{89A43E80-AC6C-4DA8-9800-F4B30ED577C0}\PostBuild.exe
c:\documents and settings\Default User\xmlUpdater.exe
c:\windows\IsUn0407.exe
c:\windows\IsUn0415.exe
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\config\systemprofile\xmlUpdater.exe
c:\windows\system32\SET33.tmp
c:\windows\system32\SET46.tmp
c:\windows\system32\SET47.tmp
c:\windows\system32\SET77.tmp
c:\windows\system32\SET78.tmp
c:\windows\system32\SET79.tmp
c:\windows\system32\SET84.tmp
c:\windows\system32\SET87.tmp
c:\windows\system32\SETA9.tmp
c:\windows\system32\SETAA.tmp
c:\windows\system32\SETB1.tmp
c:\windows\system32\SETB9.tmp
c:\windows\system32\SETC7.tmp
c:\windows\system32\SETC8.tmp
c:\windows\system32\SETC9.tmp
c:\windows\system32\SETCD.tmp
c:\windows\system32\SETCE.tmp
c:\windows\system32\SETCF.tmp
c:\windows\system32\SETD3.tmp
c:\windows\system32\SETD5.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
-------\Service_RkHit
.
.
((((((((((((((((((((((((( Files Created from 2012-01-16 to 2012-02-16 )))))))))))))))))))))))))))))))
.
.
2012-02-15 22:58 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-15 22:58 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 22:53 . 2011-10-14 14:47 23040 ------w- c:\windows\system32\dllcache\mciseq.dll
2012-02-15 22:53 . 2011-10-14 14:47 176128 ------w- c:\windows\system32\dllcache\winmm.dll
2012-02-15 22:47 . 2011-11-03 15:27 386048 ------w- c:\windows\system32\dllcache\qdvd.dll
2012-02-15 22:45 . 2011-11-18 12:35 60416 ------w- c:\windows\system32\dllcache\packager.exe
2012-02-15 22:42 . 2011-09-28 07:05 599552 ------w- c:\windows\system32\dllcache\crypt32.dll
2012-02-15 22:41 . 2011-08-16 10:45 6144 ------w- c:\windows\system32\dllcache\iecompat.dll
2012-02-15 22:39 . 2011-06-24 14:09 139656 ------w- c:\windows\system32\dllcache\rdpwd.sys
2012-02-15 22:38 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys
2012-02-15 22:37 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2012-02-15 22:36 . 2011-04-21 13:52 105472 ------w- c:\windows\system32\dllcache\mup.sys
2012-02-15 22:35 . 2011-08-17 13:41 138496 ------w- c:\windows\system32\dllcache\afd.sys
2012-02-15 22:35 . 2008-06-20 11:59 361600 ------w- c:\windows\system32\dllcache\tcpip.sys
2012-02-15 22:35 . 2011-03-03 06:53 149504 ------w- c:\windows\system32\dllcache\dnsapi.dll
2012-02-15 22:35 . 2009-04-20 17:06 45568 ------w- c:\windows\system32\dllcache\dnsrslvr.dll
2012-02-15 22:35 . 2008-06-20 17:43 245248 ------w- c:\windows\system32\dllcache\mswsock.dll
2012-02-15 22:29 . 2011-12-30 16:03 21336 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-02-15 22:13 . 2012-02-15 22:13 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\IObit
2012-02-15 22:01 . 2012-02-15 22:01 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
2012-02-15 22:01 . 2012-02-15 22:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\IObit
2012-02-15 22:00 . 2012-02-15 22:00 -------- d-----w- c:\program files\IObit
2012-02-15 21:13 . 2012-02-15 21:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Finder
2012-02-15 13:59 . 2012-02-15 14:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\PCPro
2012-02-15 13:59 . 2012-02-15 13:59 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Cleaners
2012-02-15 13:58 . 2012-02-15 13:58 -------- d-----w- c:\documents and settings\All Users\Application Data\PC1Data
2012-02-15 09:38 . 2012-02-15 09:38 240 ----a-w- C:\user.js
2012-02-15 08:39 . 2012-02-15 08:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\DriverCure
2012-02-15 08:39 . 2012-02-15 08:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\SpeedyPC Software
2012-02-15 08:38 . 2012-02-15 09:39 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedyPC Software
2012-02-15 08:38 . 2012-02-15 08:38 -------- d-----w- c:\program files\SpeedyPC Software
2012-02-15 07:49 . 2012-02-15 08:08 1 ----a-w- C:\s_pov.bin
2012-02-04 10:33 . 2012-02-04 10:33 -------- d-----w- c:\program files\Activision
2012-01-29 09:32 . 2012-01-29 09:33 -------- d-----w- c:\program files\Hard Truck 18 Wheels
2012-01-26 18:34 . 2012-01-26 18:34 -------- d-----w- c:\program files\ijji
2012-01-26 18:34 . 2012-01-26 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\IBUpdaterService
2012-01-24 17:25 . 2012-01-25 14:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Capcom
2012-01-24 17:15 . 2012-01-24 17:15 -------- d-----w- c:\program files\Capcom
2012-01-20 00:44 . 2012-02-03 11:48 -------- d-----w- C:\LFS
2012-01-18 00:48 . 2012-01-18 02:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\.minecraft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2060-08-19 01:02 . 2011-09-28 23:02 2023424 ------w- c:\windows\system32\Vcl50.bpl
2060-08-19 01:02 . 2011-09-28 23:02 1496064 ------w- c:\windows\system32\Cc3250mt.dll
2060-08-19 01:02 . 2011-09-28 23:02 248832 ------w- c:\windows\system32\Vclx50.bpl
2060-08-19 00:40 . 2011-09-28 23:02 909824 ------w- c:\windows\system32\Cp3245mt.dll
2060-08-19 00:40 . 2011-09-28 23:02 24064 ------w- c:\windows\system32\Borlndmm.dll
2012-02-15 14:10 . 2011-02-06 17:35 5276432 ----a-w- c:\windows\uninst.exe
2012-02-04 07:32 . 2011-03-26 01:04 21840 ----atw- c:\windows\system32\SIntfNT.dll
2012-02-04 07:32 . 2011-03-26 01:04 17212 ----atw- c:\windows\system32\SIntf32.dll
2012-02-04 07:32 . 2011-03-26 01:04 12067 ----atw- c:\windows\system32\SIntf16.dll
2012-01-23 16:54 . 2011-12-26 06:04 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2012-01-12 16:54 . 2008-10-31 13:52 1869056 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:46 . 2008-04-14 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2008-04-14 10:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2008-04-14 10:00 385024 ----a-w- c:\windows\system32\html.iec
2011-12-10 14:24 . 2011-04-26 22:26 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-18 12:35 . 2008-04-14 10:00 60416 ----a-w- c:\windows\system32\packager.exe
2012-02-12 19:47 . 2011-05-07 23:52 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-09-30 . 038CA45522FE9B756EFB90DBFA9141EA . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
.
.
c:\windows\System32\wscntfy.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-03 15:31 1514152 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-11-02 641400]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-29 620376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-29 126976]
"TWCU"="c:\program files\TP-LINK\TP-LINK 54M Wireless Client Utility\TWCU.exe" [2008-03-27 479412]
"Olympus ib"="c:\program files\Olympus\ib\olycamdetect.exe" [2010-09-30 93360]
"MDS_Menu"="c:\program files\Olympus\ib\MUITransfer\MUIStartMenu.exe" [2010-07-01 220336]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-29 155648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-03 25626408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2011-12-13 225280]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-11-02 00:28 641400 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Readon Technology\\Readon TV Movie Radio Player 7.5.0.0\\internettv.exe"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
.
R1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [2.5.2011 5:31 30656]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [15.2.2012 23:00 497496]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [20.5.2011 1:07 136360]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [21.3.2011 2:01 27632]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23.4.2011 6:07 136176]
S3 gupdatem;Usluga Google ažuriranje (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [23.4.2011 6:07 136176]
S3 ip100xp;TP-LINK 10/100Mbps PCI Network Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [1.6.2011 17:47 26752]
S3 pfsvgae;pfsvgae;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\pfsvgae.sys --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\pfsvgae.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASPI32
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 05:07]
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 05:07]
.
2012-02-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-01-03 15:31]
.
2012-02-15 c:\windows\Tasks\SpeedyPC Pro.job
- c:\program files\SpeedyPC Software\SpeedyPC\SpeedyPC.exe [2011-10-09 01:19]
.
2012-02-16 c:\windows\Tasks\User_Feed_Synchronization-{226F826B-D51C-4C13-8859-F3BA7BF943F8}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&affID=110482&mntrId=d0f0b59200000000000000096bed6a46
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
LSP: c:\windows\system32\XDogcat.dll
TCP: DhcpNameServer = 192.168.88.1 192.168.11.5 8.8.8.8
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hbdif0er.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ba/
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - user.js: extensions.BabylonToolbar_i.babTrack - tt=090212_noffx
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - d0f0b59200000000000000096bed6a46
FF - user.js: extensions.BabylonToolbar_i.hardId - d0f0b59200000000000000096bed6a46
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15385
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1710:38
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Toolbar-!{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-MSIDLL - (no file)
AddRemove-Moorhuhn Winter-Edition - c:\windows\IsUn0407.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2012-02-16 08:39
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-436374069-1637723038-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,dd,b8,94,2d,2d,b4,dd,41,8f,0a,b2,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,53,ba,33,09,71,1d,7e,46,97,8b,b7,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(1036)
c:\windows\system32\XDogcat.dll
.
- - - - - - - > 'explorer.exe'(2120)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\XDogcat.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\acs.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
.
**************************************************************************
.
Completion time: 2012-02-16 08:45:24 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-16 07:45
.
Pre-Run: 18.702.712.832 bytes free
Post-Run: 18.851.627.008 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 425EC5AE30A2EEE0746F1F608E8BD3D0

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8448
  • Gde živiš: Novi Beograd

Otvoriti Notepad i iskopirati sledeci tekst:

Folder::
c:\documents and settings\Administrator\Application Data\PCPro
c:\documents and settings\Administrator\Application Data\PC Cleaners
c:\documents and settings\All Users\Application Data\PC1Data

Driver::
pfsvgae


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 15 Feb 2012
  • Poruke: 77

ComboFix 12-02-15.01 - Administrator 16.02.2012 14:42:23.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.387.1033.18.511.310 [GMT 1:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\cfscript
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Application Data\PC Cleaners
c:\documents and settings\Administrator\Application Data\PC Cleaners\app.log
c:\documents and settings\Administrator\Application Data\PCPro
c:\documents and settings\All Users\Application Data\PC1Data
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_PFSVGAE
-------\Service_pfsvgae
.
.
((((((((((((((((((((((((( Files Created from 2012-01-16 to 2012-02-16 )))))))))))))))))))))))))))))))
.
.
2012-02-16 10:40 . 2012-02-16 11:09 -------- d-----w- c:\documents and settings\Administrator\dwhelper
2012-02-16 10:12 . 2012-02-16 10:12 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Ilivid Player
2012-02-16 07:38 . 2012-02-16 07:38 -------- d-----w- c:\windows\system32\wbem\snmp
2012-02-16 07:38 . 2012-02-16 07:38 -------- d-----w- c:\windows\system32\xircom
2012-02-16 07:38 . 2012-02-16 07:38 -------- d-----w- c:\program files\microsoft frontpage
2012-02-15 22:58 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-15 22:58 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
2012-02-15 22:53 . 2011-10-14 14:47 23040 ------w- c:\windows\system32\dllcache\mciseq.dll
2012-02-15 22:53 . 2011-10-14 14:47 176128 ------w- c:\windows\system32\dllcache\winmm.dll
2012-02-15 22:47 . 2011-11-03 15:27 386048 ------w- c:\windows\system32\dllcache\qdvd.dll
2012-02-15 22:45 . 2011-11-18 12:35 60416 ------w- c:\windows\system32\dllcache\packager.exe
2012-02-15 22:42 . 2011-09-28 07:05 599552 ------w- c:\windows\system32\dllcache\crypt32.dll
2012-02-15 22:41 . 2011-08-16 10:45 6144 ------w- c:\windows\system32\dllcache\iecompat.dll
2012-02-15 22:39 . 2011-06-24 14:09 139656 ------w- c:\windows\system32\dllcache\rdpwd.sys
2012-02-15 22:38 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys
2012-02-15 22:37 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2012-02-15 22:36 . 2011-04-21 13:52 105472 ------w- c:\windows\system32\dllcache\mup.sys
2012-02-15 22:35 . 2011-08-17 13:41 138496 ------w- c:\windows\system32\dllcache\afd.sys
2012-02-15 22:35 . 2008-06-20 11:59 361600 ------w- c:\windows\system32\dllcache\tcpip.sys
2012-02-15 22:35 . 2011-03-03 06:53 149504 ------w- c:\windows\system32\dllcache\dnsapi.dll
2012-02-15 22:35 . 2009-04-20 17:06 45568 ------w- c:\windows\system32\dllcache\dnsrslvr.dll
2012-02-15 22:35 . 2008-06-20 17:43 245248 ------w- c:\windows\system32\dllcache\mswsock.dll
2012-02-15 22:29 . 2011-12-30 16:03 21336 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-02-15 22:13 . 2012-02-15 22:13 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\IObit
2012-02-15 22:01 . 2012-02-15 22:01 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
2012-02-15 22:01 . 2012-02-15 22:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\IObit
2012-02-15 22:00 . 2012-02-15 22:00 -------- d-----w- c:\program files\IObit
2012-02-15 21:13 . 2012-02-15 21:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Finder
2012-02-15 09:38 . 2012-02-15 09:38 240 ----a-w- C:\user.js
2012-02-15 08:39 . 2012-02-15 08:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\DriverCure
2012-02-15 08:39 . 2012-02-15 08:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\SpeedyPC Software
2012-02-15 08:38 . 2012-02-15 09:39 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedyPC Software
2012-02-15 08:38 . 2012-02-15 08:38 -------- d-----w- c:\program files\SpeedyPC Software
2012-02-04 10:33 . 2012-02-04 10:33 -------- d-----w- c:\program files\Activision
2012-01-29 09:32 . 2012-01-29 09:33 -------- d-----w- c:\program files\Hard Truck 18 Wheels
2012-01-26 18:34 . 2012-01-26 18:34 -------- d-----w- c:\program files\ijji
2012-01-26 18:34 . 2012-01-26 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\IBUpdaterService
2012-01-24 17:25 . 2012-01-25 14:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Capcom
2012-01-24 17:15 . 2012-01-24 17:15 -------- d-----w- c:\program files\Capcom
2012-01-20 00:44 . 2012-02-03 11:48 -------- d-----w- C:\LFS
2012-01-18 00:48 . 2012-01-18 02:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\.minecraft
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2060-08-19 01:02 . 2011-09-28 23:02 2023424 ------w- c:\windows\system32\Vcl50.bpl
2060-08-19 01:02 . 2011-09-28 23:02 1496064 ------w- c:\windows\system32\Cc3250mt.dll
2060-08-19 01:02 . 2011-09-28 23:02 248832 ------w- c:\windows\system32\Vclx50.bpl
2060-08-19 00:40 . 2011-09-28 23:02 909824 ------w- c:\windows\system32\Cp3245mt.dll
2060-08-19 00:40 . 2011-09-28 23:02 24064 ------w- c:\windows\system32\Borlndmm.dll
2012-02-15 14:10 . 2011-02-06 17:35 5276432 ----a-w- c:\windows\uninst.exe
2012-02-04 07:32 . 2011-03-26 01:04 21840 ----atw- c:\windows\system32\SIntfNT.dll
2012-02-04 07:32 . 2011-03-26 01:04 17212 ----atw- c:\windows\system32\SIntf32.dll
2012-02-04 07:32 . 2011-03-26 01:04 12067 ----atw- c:\windows\system32\SIntf16.dll
2012-01-23 16:54 . 2011-12-26 06:04 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2012-01-12 16:54 . 2008-10-31 13:52 1869056 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:46 . 2008-04-14 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2008-04-14 10:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2008-04-14 10:00 385024 ----a-w- c:\windows\system32\html.iec
2011-12-10 14:24 . 2011-04-26 22:26 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-12 19:47 . 2011-05-07 23:52 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-09-30 . 038CA45522FE9B756EFB90DBFA9141EA . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2012-02-16_07.40.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-16 13:52 . 2012-02-16 13:52 16384 c:\windows\Temp\Perflib_Perfdata_688.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-03 15:31 1514152 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-11-02 641400]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-29 620376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-29 126976]
"TWCU"="c:\program files\TP-LINK\TP-LINK 54M Wireless Client Utility\TWCU.exe" [2008-03-27 479412]
"Olympus ib"="c:\program files\Olympus\ib\olycamdetect.exe" [2010-09-30 93360]
"MDS_Menu"="c:\program files\Olympus\ib\MUITransfer\MUIStartMenu.exe" [2010-07-01 220336]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-04 281768]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-29 155648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-03 25626408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2011-12-13 225280]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-11-02 00:28 641400 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Readon Technology\\Readon TV Movie Radio Player 7.5.0.0\\internettv.exe"=
"c:\\Program Files\\Veetle\\Player\\VeetleNet.exe"=
.
R1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [2.5.2011 5:31 30656]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [15.2.2012 23:00 497496]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [20.5.2011 1:07 136360]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [21.3.2011 2:01 27632]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23.4.2011 6:07 136176]
S3 gupdatem;Usluga Google ažuriranje (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [23.4.2011 6:07 136176]
S3 ip100xp;TP-LINK 10/100Mbps PCI Network Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [1.6.2011 17:47 26752]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASPI32
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 05:07]
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-23 05:07]
.
2012-02-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-01-03 15:31]
.
2012-02-15 c:\windows\Tasks\SpeedyPC Pro.job
- c:\program files\SpeedyPC Software\SpeedyPC\SpeedyPC.exe [2011-10-09 01:19]
.
2012-02-16 c:\windows\Tasks\User_Feed_Synchronization-{226F826B-D51C-4C13-8859-F3BA7BF943F8}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 12:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.searchqu.com/406
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
LSP: c:\windows\system32\XDogcat.dll
TCP: DhcpNameServer = 192.168.88.1 192.168.11.5 8.8.8.8
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hbdif0er.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ba/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
FF - user.js: extensions.BabylonToolbar_i.babTrack - tt=090212_noffx
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - d0f0b59200000000000000096bed6a46
FF - user.js: extensions.BabylonToolbar_i.hardId - d0f0b59200000000000000096bed6a46
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15385
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1710:38
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2012-02-16 14:53
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-436374069-1637723038-1417001333-500\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (Administrator)
"{28387537-E3F9-4ED7-860C-11E69AF4A8A0}"=hex:51,66,7a,6c,4c,1d,3b,1b,27,6f,29,
37,cd,b7,bc,03,9c,0e,4e,ba,9c,b4,ea,bb
"{BE7A24F5-69CB-4708-B77B-B1EDA6043B95}"=hex:51,66,7a,6c,4c,1d,3b,1b,e5,3e,6b,
a1,ff,3d,63,0a,ad,79,ee,b1,a0,44,79,8e
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=hex:51,66,7a,6c,4c,1d,3b,1b,6f,66,13,
cb,7e,41,0d,0d,bb,af,1d,1f,de,52,36,5b
"{99079A25-328F-4BD4-BE04-00955ACAA0A7}"=hex:51,66,7a,6c,4c,1d,3b,1b,35,80,16,
86,bb,66,bf,06,a4,06,5f,c9,5c,8a,e2,bc
"{9D717F81-9148-4F12-8568-69135F087DB0}"=hex:51,66,7a,6c,4c,1d,3b,1b,91,65,60,
82,7c,c5,79,02,9f,6a,36,4f,59,48,3f,ab
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(904)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(992)
c:\windows\system32\XDogcat.dll
.
- - - - - - - > 'explorer.exe'(2592)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\XDogcat.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\acs.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
.
**************************************************************************
.
Completion time: 2012-02-16 14:58:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-16 13:58
ComboFix2.txt 2012-02-16 07:45
.
Pre-Run: 18.696.757.248 bytes free
Post-Run: 18.718.175.232 bytes free
.
- - End Of File - - 71A0ADFF6FEA14CD4087D7189F13CF1C

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8448
  • Gde živiš: Novi Beograd

Kakvo je sada stanje?

Ko je trenutno na forumu
 

Ukupno su 788 korisnika na forumu :: 26 registrovanih, 6 sakrivenih i 756 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Sale, aleksmajstor, Bane san, dragon986, Drug pukovnik, goxin, HDMI, HrcAk47, ikan, ivan979, louderick, mercedesamg, Milan A. Nikolic, Miskohd, Mr. Majevica, Najax, nenaddz, oddsock, pein, Recce, royst33, stegonosa, Tas011, Toni, virked, Vlad000