IE sam otvara veliki broj tabova

1

IE sam otvara veliki broj tabova

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

U toku citanja maila, citanja vesti i sl. IE poludi i neprekidno pocne da otvara jedan za drugim tabove. Moze li se iz loga videti cime je to uzrokovano?

Logfile of HijackThis v1.99.1
Scan saved at 5:27:28 PM, on 1/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\zerocool\Desktop\hiki\TR3.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Nema niceg u logu...

Hajde da probamo da li ce mozda ComboFix da kaze nesto.

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

ComboFix 08-01-30.6 - zerocool 2008-01-30 18:59:13.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.323 [GMT 1:00]
Running from: C:\Documents and Settings\zerocool\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\kb1111p.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\UpMedia\ContentTool.dll
C:\WINDOWS\system32\UpMedia\SearchTool.dll
C:\WINDOWS\system32\winnb58.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_NTOSNH.SYS


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.

2008-01-28 11:13 . 2008-01-28 11:13 <DIR> d-------- C:\Program Files\Mayoko
2008-01-23 15:22 . 2008-01-23 18:32 <DIR> d-------- C:\Documents and Settings\zerocool\amsn
2008-01-23 15:21 . 2008-01-23 15:22 <DIR> d-------- C:\Program Files\aMSN
2008-01-22 15:25 . 2008-01-24 19:22 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-01-22 15:25 . 2008-01-22 15:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-01-22 12:49 . 2008-01-24 11:12 374 --a------ C:\Documents and Settings\zerocool\Application Data\internaldb6334.dat
2008-01-22 12:49 . 2008-01-22 12:49 189 --a------ C:\WINDOWS\wininit.ini
2008-01-22 12:48 . 2008-01-22 12:48 363,980 --a------ C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe
2008-01-22 12:48 . 2008-01-24 11:11 18,432 --a------ C:\Documents and Settings\zerocool\Application Data\internaldb41.dat
2008-01-22 12:48 . 2008-01-24 11:11 555 --a------ C:\Documents and Settings\zerocool\Application Data\internaldb8467.dat
2008-01-08 12:18 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-08 12:17 . 2008-01-08 12:17 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-01-03 12:34 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-01-03 12:34 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2007-12-30 22:58 . 2008-01-22 19:29 <DIR> d-------- C:\Program Files\Valve
2007-12-13 17:06 . 2007-12-13 17:06 <DIR> d-------- C:\Program Files\Common Files\DirectX
2007-12-08 23:44 . 2007-12-08 23:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-12-08 11:21 . 2007-12-22 15:58 <DIR> d-------- C:\Program Files\Messenger Plus! Live
2007-12-08 11:14 . 2007-12-08 11:21 <DIR> d-------- C:\Program Files\Windows Live
2007-12-08 11:14 . 2007-12-08 11:33 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-08 11:14 . 2007-12-08 11:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-02 11:56 . 2008-01-22 14:42 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-30 17:57 --------- d-----w C:\Documents and Settings\zerocool\Application Data\uTorrent
2008-01-26 06:31 --------- d-----w C:\Documents and Settings\zerocool\Application Data\LimeWire
2008-01-22 18:25 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-22 14:24 --------- d-----w C:\Program Files\MSN Messenger
2008-01-10 14:00 --------- d-----w C:\Program Files\GameHouse
2008-01-08 21:38 --------- d-----w C:\Program Files\dellete
2008-01-01 17:42 --------- d-----w C:\Program Files\Winamp
2007-12-30 21:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-17 18:31 --------- d-----w C:\Program Files\Opera
2007-11-28 16:43 --------- d-----w C:\Program Files\FlashGet
2007-11-28 16:09 --------- d-----w C:\Program Files\Free Download Manager
2007-11-22 21:21 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-11-14 11:09 212 ----a-w C:\delete.bat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NWEReboot"="" []
"NAV Agent"="C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe" [2001-07-21 09:09 50256]
"WFXSwtch"="C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe" [2001-07-19 08:04 26624]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-07-19 08:04 43520 C:\WINDOWS\system32\WFXSNT40.EXE]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-22 22:21 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"

R3 KCIRDA;%KCIRDA.ServiceDesc%;C:\WINDOWS\system32\DRIVERS\KCIrNet.sys [2001-10-04 09:23]
R3 NPDriver;Norton Unerase Protection Driver;C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [2001-07-26 06:00]
R3 QDFSDRV;QDFSDRV;C:\WINDOWS\system32\drivers\qdfsdrv.sys [2001-07-26 11:17]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2001-10-11 07:51]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1ca8d210-c9da-11dc-8fc8-0007951fccfb}]
\Shell\AutoRun\command - fooool.exe
\Shell\explore\Command - fooool.exe
\Shell\open\Command - fooool.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 19:39:40 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.exeG/task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca
"2008-01-25 16:30:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Common Files\Symantec Shared\NMAIN.EXEK /dat:C:\Program Files\Norton SystemWorks\swplugin.nsi /NSWCMD:OBCSchedule
"2008-01-30 18:04:18 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 19:04:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-01-30 19:15:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-30 18:15:25
ComboFix2.txt 2007-11-06 00:33:56



Dok je to radilo, Norton je prijavljivao ovo:

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Zanemari Nortona dok cistimo, tj. dozvoli ComboFixu da odradi svoj posao.
Ukoliko te Norton pita da li da dozvoli ili ne, kazi mu da dozvoli.

Uradi sledeće:
Preuzmi fajl gmer.zip sa ovog linka i sačuvaj na Desktop-u.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati to u Clipboard.
U polju za pisanje poruke na forumu klikni desno dugme misa i odaberi opciju Paste.

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

GMER 1.0.14.14116 - http://www.gmer.net
Rootkit scan 2008-01-30 23:19:05
Windows 5.1.2600 Service Pack 2


---- User code sections - GMER 1.0.14 ----

.text C:\Program Files\internet explorer\iexplore.exe[2656] USER32.dll!DialogBoxParamA 77D588E1 5 Bytes JMP 7E38C4D5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2656] USER32.dll!DialogBoxIndirectParamW 77D62598 5 Bytes JMP 7E38C510 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2656] USER32.dll!MessageBoxIndirectA 77D6AEF1 5 Bytes JMP 7E38C491 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2656] USER32.dll!MessageBoxExW 77D80559 5 Bytes JMP 7E38C3D9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2656] USER32.dll!MessageBoxExA 77D8057D 5 Bytes JMP 7E38C413 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2656] USER32.dll!DialogBoxIndirectParamA 77D86CED 5 Bytes JMP 7E38C54B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2656] USER32.dll!MessageBoxIndirectW 77D960B7 5 Bytes JMP 7E38C44D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- Devices - GMER 1.0.14 ----

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

---- Files - GMER 1.0.14 ----

File C:\RECYCLER\NPROTECT 0 bytes
File C:\RECYCLER\NPROTECT\00000019 5 bytes
File C:\RECYCLER\NPROTECT\00000020.hiv 8192 bytes
File C:\RECYCLER\NPROTECT\00000021.dat 2501 bytes
File C:\RECYCLER\NPROTECT\00000022 1003 bytes
File C:\RECYCLER\NPROTECT\00000023.hiv 8192 bytes
File C:\RECYCLER\NPROTECT\00000024.dat 1042 bytes
File C:\RECYCLER\NPROTECT\00000025 876 bytes
File C:\RECYCLER\NPROTECT\00000026.hiv 8192 bytes
File C:\RECYCLER\NPROTECT\00000027.dat 74 bytes
File C:\RECYCLER\NPROTECT\00000028 44 bytes
File C:\RECYCLER\NPROTECT\00000029.hiv 8192 bytes
File C:\RECYCLER\NPROTECT\00000030.dat 1416 bytes
File C:\RECYCLER\NPROTECT\00000031 20 bytes
File C:\RECYCLER\NPROTECT\00000032 12 bytes
File C:\RECYCLER\NPROTECT\00000033 200 bytes
File C:\RECYCLER\NPROTECT\00000034.hiv 12288 bytes
File C:\RECYCLER\NPROTECT\00000035.dat 3026 bytes
File C:\RECYCLER\NPROTECT\00000036 1616 bytes
File C:\RECYCLER\NPROTECT\00000038 35 bytes
File C:\RECYCLER\NPROTECT\00000040.CFU 447 bytes
File C:\RECYCLER\NPROTECT\00000041 38 bytes
File C:\RECYCLER\NPROTECT\00000042 247 bytes
File C:\RECYCLER\NPROTECT\00000043 285 bytes
File C:\RECYCLER\NPROTECT\00000044 171 bytes
File C:\RECYCLER\NPROTECT\00000045 28 bytes
File C:\RECYCLER\NPROTECT\00000046 416 bytes
File C:\RECYCLER\NPROTECT\00000047 577 bytes
File C:\RECYCLER\NPROTECT\00000048 257 bytes
File C:\RECYCLER\NPROTECT\00000049 267 bytes
File C:\RECYCLER\NPROTECT\00000050 509 bytes
File C:\RECYCLER\NPROTECT\00000051 402 bytes
File C:\RECYCLER\NPROTECT\00000052 87 bytes
File C:\RECYCLER\NPROTECT\00000053 282 bytes
File C:\RECYCLER\NPROTECT\00000054 437 bytes
File C:\RECYCLER\NPROTECT\00000055 272 bytes
File C:\RECYCLER\NPROTECT\00000056 493 bytes
File C:\RECYCLER\NPROTECT\00000057 267 bytes
File C:\RECYCLER\NPROTECT\00000059.cfu 577 bytes
File C:\RECYCLER\NPROTECT\00000060.cfu 257 bytes
File C:\RECYCLER\NPROTECT\00000061.CFU 267 bytes
File C:\RECYCLER\NPROTECT\00000062.CFU 509 bytes
File C:\RECYCLER\NPROTECT\00000063.CFU 402 bytes
File C:\RECYCLER\NPROTECT\00000064.CFU 87 bytes
File C:\RECYCLER\NPROTECT\00000065.cfu 282 bytes
File C:\RECYCLER\NPROTECT\00000066.cfu 437 bytes
File C:\RECYCLER\NPROTECT\00000067.CFU 272 bytes
File C:\RECYCLER\NPROTECT\00000068.cfu 493 bytes
File C:\RECYCLER\NPROTECT\00000069.CFU 267 bytes
File C:\RECYCLER\NPROTECT\00000070.RE5 2280 bytes
File C:\RECYCLER\NPROTECT\00000071.re5 3118 bytes
File C:\RECYCLER\NPROTECT\00000072.re5 2824 bytes
File C:\RECYCLER\NPROTECT\00000073.re5 2280 bytes
File C:\RECYCLER\NPROTECT\00000074.re5 2836 bytes
File C:\RECYCLER\NPROTECT\00000075.re5 2904 bytes
File C:\RECYCLER\NPROTECT\00000077.sed 535 bytes
File C:\RECYCLER\NPROTECT\00000078.FOL 472 bytes
File C:\RECYCLER\NPROTECT\00000079.FOL 577 bytes
File C:\RECYCLER\NPROTECT\00000080.FOL 194 bytes
File C:\RECYCLER\NPROTECT\00000081.FOL 202 bytes
File C:\RECYCLER\NPROTECT\00000082.FOL 509 bytes
File C:\RECYCLER\NPROTECT\00000083.FOL 402 bytes
File C:\RECYCLER\NPROTECT\00000084.FOL 124 bytes
File C:\RECYCLER\NPROTECT\00000085.FOL 211 bytes
File C:\RECYCLER\NPROTECT\00000086.FOL 370 bytes
File C:\RECYCLER\NPROTECT\00000087.FOL 206 bytes
File C:\RECYCLER\NPROTECT\00000088.FOL 418 bytes
File C:\RECYCLER\NPROTECT\00000089.FOL 202 bytes
File C:\RECYCLER\NPROTECT\00000090 3 bytes
File C:\RECYCLER\NPROTECT\00000091.DAT 32 bytes
File C:\RECYCLER\NPROTECT\00000092.VBS 232 bytes
File C:\RECYCLER\NPROTECT\00000093 107 bytes
File C:\RECYCLER\NPROTECT\00000095.dat 718 bytes
File C:\RECYCLER\NPROTECT\00000096.dat 7846 bytes
File C:\RECYCLER\NPROTECT\00000097.dat 631 bytes
File C:\RECYCLER\NPROTECT\00000098.dat 646 bytes
File C:\RECYCLER\NPROTECT\00000099.dat 1485 bytes
File C:\RECYCLER\NPROTECT\00000100.DAT 189 bytes
File C:\RECYCLER\NPROTECT\00000101.DAT 864 bytes
File C:\RECYCLER\NPROTECT\00000102 286 bytes
File C:\RECYCLER\NPROTECT\00000103.dat 39 bytes
File C:\RECYCLER\NPROTECT\00000104.DAT 698 bytes
File C:\RECYCLER\NPROTECT\00000105.DAT 121 bytes
File C:\RECYCLER\NPROTECT\00000106.DAT 127 bytes
File C:\RECYCLER\NPROTECT\00000107.DAT 735 bytes
File C:\RECYCLER\NPROTECT\00000108.DAT 1541 bytes
File C:\RECYCLER\NPROTECT\00000109 270 bytes
File C:\RECYCLER\NPROTECT\00000110.DAT 411 bytes
File C:\RECYCLER\NPROTECT\00000111.dat 341 bytes
File C:\RECYCLER\NPROTECT\00000113.DAT 361 bytes
File C:\RECYCLER\NPROTECT\00000114.DAT 1437 bytes
File C:\RECYCLER\NPROTECT\00000115 53 bytes
File C:\RECYCLER\NPROTECT\00000116 133 bytes
File C:\RECYCLER\NPROTECT\00000117 68 bytes
File C:\RECYCLER\NPROTECT\00000118 1918 bytes
File C:\RECYCLER\NPROTECT\00000119 68 bytes
File C:\RECYCLER\NPROTECT\00000120 126 bytes
File C:\RECYCLER\NPROTECT\00000121 66 bytes
File C:\RECYCLER\NPROTECT\00000122 62 bytes
File C:\RECYCLER\NPROTECT\00000123 31 bytes
File C:\RECYCLER\NPROTECT\00000124 4883 bytes
File C:\RECYCLER\NPROTECT\00000125 34 bytes
File C:\RECYCLER\NPROTECT\00000126 128 bytes
File C:\RECYCLER\NPROTECT\00000127 10945 bytes
File C:\RECYCLER\NPROTECT\00000128 2966 bytes
File C:\RECYCLER\NPROTECT\00000129 442 bytes
File C:\RECYCLER\NPROTECT\00000130 210 bytes
File C:\RECYCLER\NPROTECT\00000131 9 bytes
File C:\RECYCLER\NPROTECT\00000133 2464 bytes
File C:\RECYCLER\NPROTECT\00000134 33 bytes
File C:\RECYCLER\NPROTECT\00000135 8 bytes
File C:\RECYCLER\NPROTECT\00000136.DAT 307 bytes
File C:\RECYCLER\NPROTECT\00000137.DAT 12148 bytes
File C:\RECYCLER\NPROTECT\00000138 808 bytes
File C:\RECYCLER\NPROTECT\00000139 33 bytes
File C:\RECYCLER\NPROTECT\00000140 666 bytes
File C:\RECYCLER\NPROTECT\00000141 421 bytes
File C:\RECYCLER\NPROTECT\00000142 31 bytes
File C:\RECYCLER\NPROTECT\00000143 760 bytes
File C:\RECYCLER\NPROTECT\00000144 277 bytes
File C:\RECYCLER\NPROTECT\00000145 77 bytes
File C:\RECYCLER\NPROTECT\00000146 808 bytes
File C:\RECYCLER\NPROTECT\00000147.dat 589 bytes
File C:\RECYCLER\NPROTECT\00000148.SYS 6736 bytes
File C:\RECYCLER\NPROTECT\00000149 3 bytes
File C:\RECYCLER\NPROTECT\00000150.dat 8947 bytes
File C:\RECYCLER\NPROTECT\00000152.bad 371 bytes
File C:\RECYCLER\NPROTECT\00000153.BAD 2 bytes
File C:\RECYCLER\NPROTECT\00000154 162 bytes
File C:\RECYCLER\NPROTECT\00000155 21872 bytes
File C:\RECYCLER\NPROTECT\00000156 180799 bytes
File C:\RECYCLER\NPROTECT\00000157 708 bytes
File C:\RECYCLER\NPROTECT\00000158 230 bytes
File C:\RECYCLER\NPROTECT\00000159.dat 21 bytes
File C:\RECYCLER\NPROTECT\00000161 155 bytes
File C:\RECYCLER\NPROTECT\00000162 1551 bytes
File C:\RECYCLER\NPROTECT\00000163 1114 bytes
File C:\RECYCLER\NPROTECT\00000164 151 bytes
File C:\RECYCLER\NPROTECT\00000165 399 bytes
File C:\RECYCLER\NPROTECT\00000167 31 bytes
File C:\RECYCLER\NPROTECT\00000168.dat 31 bytes
File C:\RECYCLER\NPROTECT\00000169.dat 180799 bytes
File C:\RECYCLER\NPROTECT\00000170.dat 21880 bytes
File C:\RECYCLER\NPROTECT\00000171.DAT 708 bytes
File C:\RECYCLER\NPROTECT\00000173.dat 5349 bytes
File C:\RECYCLER\NPROTECT\00000175.bat 152134 bytes
File C:\RECYCLER\NPROTECT\00000176 4240 bytes
File C:\RECYCLER\NPROTECT\00000177.dat 49894 bytes
File C:\RECYCLER\NPROTECT\00000178.reg 49885 bytes
File C:\RECYCLER\NPROTECT\00000179.dat 1325 bytes
File C:\RECYCLER\NPROTECT\00000180.DAT 2886 bytes
File C:\RECYCLER\NPROTECT\00000181.reg 58 bytes
File C:\RECYCLER\NPROTECT\00000182.dat 67 bytes
File C:\RECYCLER\NPROTECT\00000183 2886 bytes
File C:\RECYCLER\NPROTECT\00000184 1358 bytes
File C:\RECYCLER\NPROTECT\00000185 2 bytes
File C:\RECYCLER\NPROTECT\00000186 42 bytes
File C:\RECYCLER\NPROTECT\00000187 47946 bytes
File C:\RECYCLER\NPROTECT\00000188 3 bytes
File C:\RECYCLER\NPROTECT\00000189 224 bytes
File C:\RECYCLER\NPROTECT\00000190 190 bytes
File C:\RECYCLER\NPROTECT\00000191 5003 bytes
File C:\RECYCLER\NPROTECT\00000193.dat 1764 bytes
File C:\RECYCLER\NPROTECT\00000194 125 bytes
File C:\RECYCLER\NPROTECT\00000195 3 bytes
File C:\RECYCLER\NPROTECT\00000196.dat 76 bytes
File C:\RECYCLER\NPROTECT\00000197.dat 76 bytes
File C:\RECYCLER\NPROTECT\00000198 12 bytes
File C:\RECYCLER\NPROTECT\00000199 189 bytes
File C:\RECYCLER\NPROTECT\00000200 31 bytes
File C:\RECYCLER\NPROTECT\00000202 1412 bytes
File C:\RECYCLER\NPROTECT\00000203 1433 bytes
File C:\RECYCLER\NPROTECT\00000205 1804 bytes
File C:\RECYCLER\NPROTECT\00000206.dat 2300 bytes
File C:\RECYCLER\NPROTECT\00000207 2265 bytes
File C:\RECYCLER\NPROTECT\00000208 3838 bytes
File C:\RECYCLER\NPROTECT\00000209 1012 bytes
File C:\RECYCLER\NPROTECT\00000210 18726 bytes
File C:\RECYCLER\NPROTECT\00000211 923 bytes
File C:\RECYCLER\NPROTECT\00000212.dat 3709 bytes
File C:\RECYCLER\NPROTECT\00000215 760 bytes
File C:\RECYCLER\NPROTECT\00000216.dat 194 bytes
File C:\RECYCLER\NPROTECT\00000217 194 bytes
File C:\RECYCLER\NPROTECT\00000218 40 bytes
File C:\RECYCLER\NPROTECT\00000219 39 bytes
File C:\RECYCLER\NPROTECT\00000220.sed 385 bytes
File C:\RECYCLER\NPROTECT\00000221 451 bytes
File C:\RECYCLER\NPROTECT\00000222 359 bytes
File C:\RECYCLER\NPROTECT\00000223 159 bytes
File C:\RECYCLER\NPROTECT\00000224 115 bytes
File C:\RECYCLER\NPROTECT\00000225.txt 43 bytes
File C:\RECYCLER\NPROTECT\00000226 72 bytes
File C:\RECYCLER\NPROTECT\00000227 203 bytes
File C:\RECYCLER\NPROTECT\00000228 145 bytes
File C:\RECYCLER\NPROTECT\00000229 149 bytes
File C:\RECYCLER\NPROTECT\00000230 153 bytes
File C:\RECYCLER\NPROTECT\00000231.txt 222 bytes
File C:\RECYCLER\NPROTECT\00000232 379 bytes
File C:\RECYCLER\NPROTECT\00000234 146 bytes
File C:\RECYCLER\NPROTECT\00000235 150 bytes
File C:\RECYCLER\NPROTECT\00000237 143 bytes
File C:\RECYCLER\NPROTECT\00000238 147 bytes
File C:\RECYCLER\NPROTECT\00000239 151 bytes
File C:\RECYCLER\NPROTECT\00000240.edb 65536 bytes
File C:\RECYCLER\NPROTECT\00000241 149 bytes
File C:\RECYCLER\NPROTECT\00000242 174 bytes
File C:\RECYCLER\NPROTECT\00000243 148 bytes
File C:\RECYCLER\NPROTECT\00000244 150 bytes
File C:\RECYCLER\NPROTECT\00000245 235 bytes
File C:\RECYCLER\NPROTECT\00000246 155 bytes
File C:\RECYCLER\NPROTECT\00000247 233 bytes
File C:\RECYCLER\NPROTECT\00000248 154 bytes
File C:\RECYCLER\NPROTECT\00000249 237 bytes
File C:\RECYCLER\NPROTECT\00000250 156 bytes
File C:\RECYCLER\NPROTECT\00000251 173 bytes
File C:\RECYCLER\NPROTECT\00000252 173 bytes
File C:\RECYCLER\NPROTECT\00000253 182 bytes
File C:\RECYCLER\NPROTECT\00000255 268 bytes
File C:\RECYCLER\NPROTECT\00000256 262 bytes
File C:\RECYCLER\NPROTECT\00000257 11113 bytes
File C:\RECYCLER\NPROTECT\00000258 10720 bytes
File C:\RECYCLER\NPROTECT\00000259.dat 195 bytes
File C:\RECYCLER\NPROTECT\00000260 4796 bytes
File C:\RECYCLER\NPROTECT\00000261 1084 bytes
File C:\RECYCLER\NPROTECT\00000262 137 bytes
File C:\RECYCLER\NPROTECT\00000263.DAT 176 bytes
File C:\RECYCLER\NPROTECT\00000264.DAT 210 bytes
File C:\RECYCLER\NPROTECT\00000265 421 bytes
File C:\RECYCLER\NPROTECT\00000266 456 bytes
File C:\RECYCLER\NPROTECT\00000267 26413 bytes
File C:\RECYCLER\NPROTECT\00000268 1802 bytes
File C:\RECYCLER\NPROTECT\00000269 61 bytes
File C:\RECYCLER\NPROTECT\00000270 4457 bytes
File C:\RECYCLER\NPROTECT\00000271 486 bytes
File C:\RECYCLER\NPROTECT\00000272 412 bytes
File C:\RECYCLER\NPROTECT\00000274 162 bytes
File C:\RECYCLER\NPROTECT\00000275 159 bytes
File C:\RECYCLER\NPROTECT\00000276 168 bytes
File C:\RECYCLER\NPROTECT\00000277 3 bytes
File C:\RECYCLER\NPROTECT\00000278 2966 bytes
File C:\RECYCLER\NPROTECT\00000279 180 bytes
File C:\RECYCLER\NPROTECT\00000280 200 bytes
File C:\RECYCLER\NPROTECT\00000281 365 bytes
File C:\RECYCLER\NPROTECT\00000282 309 bytes
File C:\RECYCLER\NPROTECT\00000283 309 bytes
File C:\RECYCLER\NPROTECT\00000284 385 bytes
File C:\RECYCLER\NPROTECT\00000285 265 bytes
File C:\RECYCLER\NPROTECT\00000286 75 bytes
File C:\RECYCLER\NPROTECT\00000287 442 bytes
File C:\RECYCLER\NPROTECT\00000288 398 bytes
File C:\RECYCLER\NPROTECT\00000289 442 bytes
File C:\RECYCLER\NPROTECT\00000290 455 bytes
File C:\RECYCLER\NPROTECT\00000291 16610 bytes
File C:\RECYCLER\NPROTECT\00000292 597 bytes
File C:\RECYCLER\NPROTECT\00000294 222 bytes
File C:\RECYCLER\NPROTECT\00000295 1050 bytes
File C:\RECYCLER\NPROTECT\00000296.dat 2640 bytes
File C:\RECYCLER\NPROTECT\00000297.hiv 8192 bytes
File C:\RECYCLER\NPROTECT\00000298.dat 81 bytes
File C:\RECYCLER\NPROTECT\00000299.dat 1554 bytes
File C:\RECYCLER\NPROTECT\00000300.hiv 8192 bytes
File C:\RECYCLER\NPROTECT\00000301.dat 20 bytes
File C:\RECYCLER\NPROTECT\00000302.DAT 640 bytes
File C:\RECYCLER\NPROTECT\00000303 364 bytes
File C:\RECYCLER\NPROTECT\00000304 246 bytes
File C:\RECYCLER\NPROTECT\00000305 249 bytes
File C:\RECYCLER\NPROTECT\00000306 242 bytes
File C:\RECYCLER\NPROTECT\00000307 4 bytes
File C:\RECYCLER\NPROTECT\00000308 5118 bytes
File C:\RECYCLER\NPROTECT\00000309 45 bytes
File C:\RECYCLER\NPROTECT\00000310 4618 bytes
File C:\RECYCLER\NPROTECT\00000311 59 bytes
File C:\RECYCLER\NPROTECT\00000313 53 bytes
File C:\RECYCLER\NPROTECT\00000314 1498 bytes
File C:\RECYCLER\NPROTECT\00000315 42 bytes
File C:\RECYCLER\NPROTECT\00000316 191 bytes
File C:\RECYCLER\NPROTECT\00000317 1574 bytes
File C:\RECYCLER\NPROTECT\00000318.old 9200 bytes
File C:\RECYCLER\NPROTECT\00000319.dat 194 bytes
File C:\RECYCLER\NPROTECT\00000320.DAT 148 bytes
File C:\RECYCLER\NPROTECT\00000321.old 124 bytes
File C:\RECYCLER\NPROTECT\00000322.dat 44278 bytes
File C:\RECYCLER\NPROTECT\00000323.dat 2256 bytes
File C:\RECYCLER\NPROTECT\00000324.DAT 1782 bytes
File C:\RECYCLER\NPROTECT\00000325.DAT 1087 bytes
File C:\RECYCLER\NPROTECT\00000326.DAT 350 bytes
File C:\RECYCLER\NPROTECT\00000327.dat 151 bytes
File C:\RECYCLER\NPROTECT\00000328.bat 5679 bytes
File C:\RECYCLER\NPROTECT\00000329 7680 bytes
File C:\RECYCLER\NPROTECT\00000330.bat 270995 bytes
File C:\RECYCLER\NPROTECT\00000332.CFE 142336 bytes
File C:\RECYCLER\NPROTECT\00000333.bat 33 bytes
File C:\RECYCLER\NPROTECT\00000334 8192 bytes
File C:\RECYCLER\NPROTECT\00000335.dat 82306 bytes
File C:\RECYCLER\NPROTECT\00000336.sys 1024 bytes
File C:\RECYCLER\NPROTECT\00000337.txt 7614 bytes
File C:\RECYCLER\NPROTECT\00000338.dat 999830 bytes
File C:\RECYCLER\NPROTECT\00000339.dat 165 bytes
File C:\RECYCLER\NPROTECT\00000340.CFE 101376 bytes
File C:\RECYCLER\NPROTECT\00000341.bat 1268 bytes
File C:\RECYCLER\NPROTECT\00000342.DAT 194 bytes
File C:\RECYCLER\NPROTECT\00000343.DAT 3193 bytes
File C:\RECYCLER\NPROTECT\00000344.dat 629 bytes
File C:\RECYCLER\NPROTECT\00000345.DAT 453 bytes
File C:\RECYCLER\NPROTECT\00000346.dat 194 bytes
File C:\RECYCLER\NPROTECT\00000347.dat 12 bytes
File C:\RECYCLER\NPROTECT\00000348.CFE 51200 bytes
File C:\RECYCLER\NPROTECT\00000350.LOC 2815 bytes
File C:\RECYCLER\NPROTECT\00000351.LOC 3275 bytes
File C:\RECYCLER\NPROTECT\00000352.dat 441 bytes
File C:\RECYCLER\NPROTECT\00000353.CFE 393216 bytes
File C:\RECYCLER\NPROTECT\00000354.LOC 4090 bytes
File C:\RECYCLER\NPROTECT\00000355.reg 296 bytes
File C:\RECYCLER\NPROTECT\00000356.DAT 117 bytes
File C:\RECYCLER\NPROTECT\00000357.CFE 52736 bytes
File C:\RECYCLER\NPROTECT\00000358 4718592 bytes
File C:\RECYCLER\NPROTECT\00000359.DAT 202 bytes
File C:\RECYCLER\NPROTECT\00000360.CFE 73728 bytes
File C:\RECYCLER\NPROTECT\00000361.dat 367 bytes
File C:\RECYCLER\NPROTECT\00000362.bat 47298 bytes
File C:\RECYCLER\NPROTECT\00000363.bat 3821 bytes
File C:\RECYCLER\NPROTECT\00000364.vbs 15399 bytes
File C:\RECYCLER\NPROTECT\00000365.CFE 80412 bytes
File C:\RECYCLER\NPROTECT\00000366.CFE 15360 bytes
File C:\RECYCLER\NPROTECT\00000368.bat 1734 bytes
File C:\RECYCLER\NPROTECT\00000369 499 bytes
File C:\RECYCLER\NPROTECT\00000370.exe 388608 bytes
File C:\RECYCLER\NPROTECT\00000371 100 bytes
File C:\RECYCLER\NPROTECT\00000372.bat 66676 bytes
File C:\RECYCLER\NPROTECT\00000373.vbs 349 bytes
File C:\RECYCLER\NPROTECT\00000374.CFE 65536 bytes
File C:\RECYCLER\NPROTECT\00000375.vbs 737 bytes
File C:\RECYCLER\NPROTECT\00000376.DAT 369 bytes
File C:\RECYCLER\NPROTECT\00000377.DAT 343 bytes
File C:\RECYCLER\NPROTECT\00000378.VBS 805 bytes
File C:\RECYCLER\NPROTECT\00000379.DAT 225 bytes
File C:\RECYCLER\NPROTECT\00000380.DAT 91 bytes
File C:\RECYCLER\NPROTECT\00000381.DAT 198 bytes
File C:\RECYCLER\NPROTECT\00000382.reg 49304 bytes
File C:\RECYCLER\NPROTECT\00000383.DAT 14 bytes
File C:\RECYCLER\NPROTECT\00000384.CFE 38400 bytes
File C:\RECYCLER\NPROTECT\00000000 156 bytes
File C:\RECYCLER\NPROTECT\00000001.cmd 1692 bytes
File C:\RECYCLER\NPROTECT\00000002.exe 388608 bytes
File C:\RECYCLER\NPROTECT\00000003 6 bytes
File C:\RECYCLER\NPROTECT\00000004 6 bytes
File C:\RECYCLER\NPROTECT\00000005.bat 149 bytes
File C:\RECYCLER\NPROTECT\00000006 215 bytes
File C:\RECYCLER\NPROTECT\00000007 296 bytes
File C:\RECYCLER\NPROTECT\00000008 118 bytes
File C:\RECYCLER\NPROTECT\00000009 124 bytes
File C:\RECYCLER\NPROTECT\00000010 52 bytes
File C:\RECYCLER\NPROTECT\00000011 53 bytes
File C:\RECYCLER\NPROTECT\00000012 180 bytes
File C:\RECYCLER\NPROTECT\00000013.DAT 481 bytes
File C:\RECYCLER\NPROTECT\00000014.DAT 632 bytes
File C:\RECYCLER\NPROTECT\00000015 14 bytes
File C:\RECYCLER\NPROTECT\00000016 12 bytes
File C:\RECYCLER\NPROTECT\00000017 14 bytes
File C:\RECYCLER\NPROTECT\00000386.CFE 11264 bytes
File C:\RECYCLER\NPROTECT\00000387.DAT 124 bytes
File C:\RECYCLER\NPROTECT\00000388.bat 1614 bytes
File C:\RECYCLER\NPROTECT\00000389.DAT 318 bytes
File C:\RECYCLER\NPROTECT\00000390.dat 535 bytes
File C:\RECYCLER\NPROTECT\00000391.DAT 88 bytes
File C:\RECYCLER\NPROTECT\00000392.CFE 51200 bytes
File C:\RECYCLER\NPROTECT\00000393.com 51200 bytes
File C:\RECYCLER\NPROTECT\00000394 6 bytes
File C:\RECYCLER\NPROTECT\00000395 45 bytes
File C:\RECYCLER\NPROTECT\00000396.bat 1853 bytes
File C:\RECYCLER\NPROTECT\00000397.exe 42860 bytes
File C:\RECYCLER\NPROTECT\00000398.exe 5149 bytes
File C:\RECYCLER\NPROTECT\00000399 178 bytes
File C:\RECYCLER\NPROTECT\00000400.vbs 657 bytes
File C:\RECYCLER\NPROTECT\00000401.txt 583 bytes
File C:\RECYCLER\NPROTECT\00000402.DAT 211 bytes
File C:\RECYCLER\NPROTECT\00000403.bat 517 bytes
File C:\RECYCLER\NPROTECT\00000405.DAT 278 bytes
File C:\RECYCLER\NPROTECT\00000406.dat 508835 bytes
File C:\RECYCLER\NPROTECT\00000407.DAT 306 bytes
File C:\RECYCLER\NPROTECT\00000408.CFE 131072 bytes
File C:\RECYCLER\NPROTECT\00000409.dat 404 bytes
File C:\RECYCLER\NPROTECT\00000410.bat 3424 bytes
File C:\RECYCLER\NPROTECT\00000411.dat 30426 bytes
File C:\RECYCLER\NPROTECT\00000412.DAT 6268554 bytes
File C:\RECYCLER\NPROTECT\00000413.dat 1111 bytes
File C:\RECYCLER\NPROTECT\00000414.CFE 146432 bytes
File C:\RECYCLER\NPROTECT\00000415.dat 30 bytes
File C:\RECYCLER\NPROTECT\00000416.CFE 24576 bytes
File C:\RECYCLER\NPROTECT\00000417.dat 589 bytes
File C:\RECYCLER\NPROTECT\00000418.sed 309 bytes
File C:\RECYCLER\NPROTECT\00000419.dat 329 bytes
File C:\RECYCLER\NPROTECT\00000420.DAT 1660 bytes
File C:\RECYCLER\NPROTECT\00000421.DAT 463 bytes
File C:\RECYCLER\NPROTECT\00000423.bat 11769 bytes
File C:\RECYCLER\NPROTECT\00000424.bat 10060 bytes
File C:\RECYCLER\NPROTECT\00000425.CFE 31144 bytes
File C:\RECYCLER\NPROTECT\00000426.dat 2104 bytes
File C:\RECYCLER\NPROTECT\00000427.CFE 49152 bytes
File C:\RECYCLER\NPROTECT\00000428.DAT 840628 bytes
File C:\RECYCLER\NPROTECT\00000429.DAT 206 bytes
File C:\RECYCLER\NPROTECT\00000430.DAT 346 bytes
File C:\RECYCLER\NPROTECT\00000431.DAT 390 bytes
File C:\RECYCLER\NPROTECT\00000432.vbs 1128 bytes
File C:\RECYCLER\NPROTECT\00000433.dat 555 bytes
File C:\RECYCLER\NPROTECT\00000434.dat 22389 bytes
File C:\RECYCLER\NPROTECT\00000435.DAT 148 bytes
File C:\RECYCLER\NPROTECT\00000436.dat 5618 bytes
File C:\RECYCLER\NPROTECT\00000437.CFE 161792 bytes
File C:\RECYCLER\NPROTECT\00000438.CFE 136704 bytes
File C:\RECYCLER\NPROTECT\00000439.CFE 212480 bytes
File C:\RECYCLER\NPROTECT\00000441.DAT 238 bytes
File C:\RECYCLER\NPROTECT\00000442.dat 19347 bytes
File C:\RECYCLER\NPROTECT\00000443.DAT 202 bytes
File C:\RECYCLER\NPROTECT\00000444.dat 536 bytes
File C:\RECYCLER\NPROTECT\00000445.bat 804 bytes
File C:\RECYCLER\NPROTECT\00000446.CFE 49152 bytes
File C:\RECYCLER\NPROTECT\00000447.dat 2490 bytes
File C:\RECYCLER\NPROTECT\00000448.dat 912 bytes
File C:\RECYCLER\NPROTECT\00000449.dat 886 bytes
File C:\RECYCLER\NPROTECT\00000450.dat 16607 bytes
File C:\RECYCLER\NPROTECT\00000451.DAT 171 bytes
File C:\RECYCLER\NPROTECT\00000452.DAT 17714 bytes
File C:\RECYCLER\NPROTECT\00000453.DAT 2687 bytes
File C:\RECYCLER\NPROTECT\00000454.dat 188383 bytes
File C:\RECYCLER\NPROTECT\00000455.CFE 68096 bytes
File C:\RECYCLER\NPROTECT\00000458.JPG 45657 bytes
File C:\RECYCLER\NPROTECT\00000459.AVI 184320000 bytes
File C:\RECYCLER\NPROTECT\00000460.SUB 1673 bytes
File C:\RECYCLER\NPROTECT\00000461.JPG 61725 bytes
File C:\RECYCLER\NPROTECT\NPROTECT.LOG 646528 bytes
File C:\RECYCLER\NPROTECT\Thumbs.db 371200 bytes
File C:\RECYCLER\NPROTECT\00000018.BAT 1150 bytes
File C:\RECYCLER\NPROTECT\00000037 1786 bytes
File C:\RECYCLER\NPROTECT\00000058.cfu 416 bytes
File C:\RECYCLER\NPROTECT\00000076.RE5 3604 bytes
File C:\RECYCLER\NPROTECT\00000094.DAT 283 bytes
File C:\RECYCLER\NPROTECT\00000112.dat 93 bytes
File C:\RECYCLER\NPROTECT\00000132 343 bytes
File C:\RECYCLER\NPROTECT\00000151 19 bytes
File C:\RECYCLER\NPROTECT\00000172.DAT 230 bytes
File C:\RECYCLER\NPROTECT\00000192.dat 533 bytes
File C:\RECYCLER\NPROTECT\00000214 43 bytes
File C:\RECYCLER\NPROTECT\00000233 557 bytes
File C:\RECYCLER\NPROTECT\00000254 910 bytes
File C:\RECYCLER\NPROTECT\00000273.DAT 1395 bytes
File C:\RECYCLER\NPROTECT\00000293 13709 bytes
File C:\RECYCLER\NPROTECT\00000312 6214 bytes
File C:\RECYCLER\NPROTECT\00000331.DAT 409 bytes
File C:\RECYCLER\NPROTECT\00000349.e_e 163328 bytes
File C:\RECYCLER\NPROTECT\00000367.CFE 181776 bytes
File C:\RECYCLER\NPROTECT\00000385.bat 1471 bytes
File C:\RECYCLER\NPROTECT\00000404.dat 1272 bytes
File C:\RECYCLER\NPROTECT\00000422.CFE 98816 bytes
File C:\RECYCLER\NPROTECT\00000440.bat 5487 bytes

---- EOF - GMER 1.0.14 ----

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Izvini sto si cekala.

Da krenemo ovako:

1. Posalji mi da pregledam sledeci fajl:
C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe
Poslaces mi ga preko sledece upload forme:
http://www.mycity.rs/ambulanta-upload.php

2. Ima tragova infekcije jednim crvom koji se siri putem USB prenosnih memorijskih uredjaja (USB stikovi, flash drajvovi, MP3 plejeri, mobilni telefoni koji se prikljucuju na USB itd.)
Posedujes li nesto od takvih uredjaja?

3. U Notepadu otvori sledeci fajl:
C:\WINDOWS\wininit.ini
Iskopiraj mi u poruku sadrzaj tog fajla.

4. Potrazi da li na racunaru imas sledece fajlove:
C:\WINDOWS\system32\drivers\ntosnh.sys
C:\WINDOWS\system32\drivers\ntoss.sys
C:\WINDOWS\system32\ldr.exe

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

1. poslala sam

2. u poslednje vreme cesto prikljucujem 2 USB memory sticka, mp3 plejer i USB citac kartice, koju koristim na tel.

3. [rename]
C:\WINDOWS\system32\UpMedia\SearchTool.dll=C:\DOCUME~1\zerocool\LOCALS~1\Temp\smoA6.tmp
C:\WINDOWS\system32\UpMedia\ContentTool.dll=C:\DOCUME~1\zerocool\LOCALS~1\Temp\smoA7.tmp

Dopuna: 01 Feb 2008 20:05

4. nema ni jedan od navedenih

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

1. poslati fajl je Adware, izbrisi ga

2. O ovome cemo vise kasnije.

3. Otvori ponovo taj fajl u Notepadu, izbrisi tekst koji se u njemu nalazi, pa ga snimi tako praznog (File > Save).

4. Hmm... moram da razmislim o ovome.


E, da se vratimo na tacku 2 i USB uredjaje. Logovi kazu da je tvoj windows podesen da automatski startuje fajl foool.exe sa sticka cim se ubaci USB stick u komp.

Od sada pa nadalje, drzi stisnut SHIFT taster dok ubacujes bilo koji USB stick u komp. Isto vazi za memorijske kartice, mp3 plejere i ostale uredjaje na kojima mogu da se drze fajlovi.

Evo malog programcica za dezinfekciju USB drajvova:

Flash_Disinfector.

program se pokreće dvoklikom na Flash_Disinfector.exe
kada se pojavi poruka sa obaveštenjem, potrebno je priključiti inficirane USB flash drive-ove (pri tome držati pritisnut taster Shift kako bi se izbegao autoplay)
kliknuti na OK i sačekati da se proces završi
kada se pojavi poruka Done !!, kliknuti na OK.


Javljam se ponovo cim smislim sta i kako oko tacke 4, a ti mi javi da li je Flash Disinfector nasao nesto na tvojim drajvovima.

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

1. Izbrisala

2. odradila i nije pronaslo nista, ali se "oglasio" Norton na sledeci nacin:



3. uradila i to

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Aman, iskljuci Nortona dok cistimo racunar.
Njemu je sve zivo sumnjivo i maliciozno, pa cak i pola programa koji mi ovde koristimo za ciscenje.
Jel ti Flash Disinfector na kraju napravio nekakav log?
Voleo bih da znam da li je nesto nasao ili ne.

Sto se tice tacke 4, posavetovao sam se sa dr_Borom, i on kaze da nema tu nicega, da je ono bio samo zaostali trag u registry bazi.

Ko je trenutno na forumu
 

Ukupno su 1171 korisnika na forumu :: 41 registrovanih, 3 sakrivenih i 1127 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, A.R.Chafee.Jr., Apok, bbogdan, Boris90, brundo65, coaaco, Djokkinen, djuradj, Dorcolac, Drenic7, Džordžino, Georgius, GhostOfSparta480, Hans Gajger, ivica976, jukeboxer, Klecaviks, ljuba, M1los, Mihajlo, mikrimaus, mkukoleca, MrNo, nebojsag, nemkea71, nikoladim, oldtimer, operniki, Parker, Primus17, procesor, raptorsi, sasa87, su27, Suva planina, virked, vladaa012, yrraf, zastavnik, zicko.spacek