Kaspersky se ponasao cudno

1

Kaspersky se ponasao cudno

offline
  • jt  Male
  • Građanin
  • sales representative
  • Pridružio: 27 Jun 2005
  • Poruke: 255

Posle instalacije nekoliko programa sa dvd-a iskljucio sma komp i ostavio sam dvd u drive-u. Posle starta win-a kaspersky nije bio u "resident protection" rezimu (ikonica je bila siva) i obavestio je o prisustvu "Adware not a virus:AdWare.Win32.TimeSink". Posle ignor-a, se opet pokrenuo i sad radi. To je neki bug Kaspersky-a ili je "bug" u kompu?

Uradio sam i Hijack This. Rezultat:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:33:52 PM, on 9/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\igfxext.exe
C:\DOCUME~1\PC\LOCALS~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\PC\Desktop\ez egy uj scan\a kis hamis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.ns.ac.rs:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Append to existing PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - [Link mogu videti samo ulogovani korisnici]
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: ,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 9095 bytes



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Pozzz,

log izgleda cist, ali cemo ici dublje.

* Klikni desnim tasterom na Kaspersky ikonicu ( ) u donjem, desnom uglu ekrana i izaberi Pause Protection.
* U prozoru koji se otvori, izaberi By User Request.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.


Skini ComboFix sa jedne od sledecih adresa na Desktop:
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.



offline
  • jt  Male
  • Građanin
  • sales representative
  • Pridružio: 27 Jun 2005
  • Poruke: 255

Evo log file:

ComboFix 08-09-05.12 - PC 2008-09-09 20:23:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.625 [GMT 2:00]
Running from: D:\firefox downloads\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\Desktop_.ini

.
((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
.

2008-09-09 19:19 . 2008-09-09 19:19 <DIR> d-------- C:\Documents and Settings\PC\Application Data\Windows Search
2008-09-09 19:19 . 2008-09-09 19:19 <DIR> d-------- C:\Documents and Settings\PC\Application Data\Windows Desktop Search
2008-09-09 19:18 . 2008-09-09 19:18 <DIR> d-------- C:\Program Files\Windows Desktop Search
2008-09-09 19:17 . 2008-03-07 19:02 192,000 -----c--- C:\WINDOWS\system32\dllcache\offfilt.dll
2008-09-09 19:17 . 2008-03-07 19:02 98,304 -----c--- C:\WINDOWS\system32\dllcache\nlhtml.dll
2008-09-09 19:17 . 2008-03-07 19:02 29,696 -----c--- C:\WINDOWS\system32\dllcache\mimefilt.dll
2008-09-09 17:37 . 2008-09-09 17:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-08 22:03 . 2008-09-08 22:03 <DIR> d-------- C:\Program Files\PowerQuest
2008-09-08 20:43 . 2008-09-08 20:43 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-09-08 20:41 . 2008-09-08 20:41 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-09-08 20:41 . 2008-09-08 20:42 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-09-08 20:40 . 2008-09-08 20:40 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-09-08 20:17 . 2008-06-23 18:57 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-08 20:17 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-09-08 20:17 . 2007-03-08 07:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-09-08 20:17 . 2008-06-23 18:57 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-09-08 20:17 . 2008-06-23 18:57 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-09-08 20:17 . 2008-06-23 18:57 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-09-08 20:17 . 2008-06-23 18:57 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-09-08 20:17 . 2008-06-23 18:57 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-09-08 20:17 . 2008-06-23 11:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-09-08 20:05 . 2008-09-08 20:05 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-09-08 19:57 . 2008-05-01 16:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-08 19:56 . 2008-04-11 21:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-08 19:53 . 2008-06-13 13:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-08 19:50 . 2008-05-08 16:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-08 19:40 . 2008-09-08 20:17 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-09-08 19:40 . 2008-09-09 19:20 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-09-08 15:56 . 2008-09-09 00:18 <DIR> d-------- C:\CPM
2008-09-08 15:25 . 2008-09-08 15:25 <DIR> d-------- C:\ApolloOutput
2008-09-08 15:24 . 2008-09-08 15:25 <DIR> d-------- C:\Program Files\No1 DVD Ripper
2008-09-07 17:25 . 2008-09-07 17:26 <DIR> d-------- C:\Program Files\Rar Repair Tool
2008-09-07 17:12 . 2008-09-07 17:24 <DIR> d-------- C:\Program Files\Actual Rar Repair
2008-09-07 13:32 . 2008-09-07 13:36 <DIR> d-------- C:\Documents and Settings\PC\Application Data\Desktop Maestro
2008-09-07 13:31 . 2008-09-07 13:35 <DIR> d-------- C:\Program Files\Desktop Maestro
2008-09-07 13:19 . 2008-09-07 13:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-09-06 15:05 . 2008-09-06 15:13 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-09-06 15:05 . 2008-09-06 15:05 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-09-06 15:04 . 2008-09-06 15:04 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-09-06 15:04 . 2008-09-09 20:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-06 15:04 . 2008-09-09 20:26 4,336,672 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-06 15:04 . 2008-09-09 20:26 491,552 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-06 15:04 . 2008-09-09 20:26 39,152 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-06 15:04 . 2008-09-09 20:26 3,808 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-06 15:01 . 2008-09-06 15:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-06 08:48 . 2008-09-06 08:48 <DIR> d-------- C:\Program Files\Common Files\NSV
2008-09-04 19:27 . 2008-09-04 19:28 <DIR> d-------- C:\j2sdk1.4.2_18
2008-09-04 14:24 . 2008-09-04 14:29 <DIR> d-------- C:\Program Files\eMule
2008-09-04 14:20 . 2008-09-04 15:18 <DIR> d-------- C:\Documents and Settings\PC\Application Data\LimeWire
2008-09-04 14:19 . 2008-09-04 14:20 <DIR> d-------- C:\Program Files\LimeWire
2008-09-03 15:25 . 2008-09-03 15:25 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-03 15:25 . 2008-09-03 15:25 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-03 15:25 . 2008-09-03 15:25 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-03 15:25 . 2008-09-03 15:25 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-03 15:25 . 2008-04-14 05:42 32,866 --------- C:\WINDOWS\slrundll.exe
2008-09-03 15:21 . 2008-09-03 15:26 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-03 15:20 . 2008-04-14 05:42 294,912 -----c--- C:\WINDOWS\system32\dllcache\dlimport.exe
2008-09-03 15:15 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\002887_.tmp
2008-09-02 22:41 . 2008-09-02 22:41 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-09-02 22:39 . 2008-09-02 22:47 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-09-02 22:38 . 2008-09-02 22:39 <DIR> d-------- C:\Program Files\MestRe-C
2008-09-02 22:34 . 2008-09-02 22:34 <DIR> d-------- C:\Python25
2008-09-02 22:34 . 2006-09-23 03:30 327,680 --a------ C:\WINDOWS\system32\pythoncom25.dll
2008-09-02 22:34 . 2006-09-23 03:18 102,400 --a------ C:\WINDOWS\system32\pywintypes25.dll
2008-09-02 22:32 . 2008-09-02 22:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CambridgeSoft
2008-09-02 22:19 . 2008-09-02 22:19 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-09-02 22:19 . 2008-09-02 22:19 <DIR> d-------- C:\Program Files\CambridgeSoft
2008-09-02 18:16 . 2008-09-02 18:16 <DIR> d-------- C:\Program Files\ESET
2008-09-02 18:16 . 2008-09-02 18:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-09-02 14:01 . 2008-09-02 14:01 <DIR> d-------- C:\Program Files\AxBx
2008-09-01 20:37 . 2008-09-09 02:44 <DIR> d-------- C:\Program Files\PersonalWebKit3
2008-09-01 20:37 . 2008-09-01 20:37 286,720 --a------ C:\WINDOWS\iun507.exe
2008-09-01 20:26 . 2008-09-01 21:17 <DIR> d-------- C:\Documents and Settings\PC\Application Data\DMCache
2008-09-01 09:50 . 2008-09-01 09:52 <DIR> d-------- C:\Program Files\Yahoo!
2008-08-31 18:15 . 2008-08-31 18:15 <DIR> d-------- C:\WINDOWS\Sun
2008-08-31 14:17 . 2008-09-09 19:18 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-08-31 14:02 . 2008-04-14 05:42 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-08-27 23:08 . 2008-08-27 23:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Cadsoft
2008-08-27 23:06 . 2008-08-27 23:06 <DIR> d-------- C:\Program Files\Common Files\Cadsoft
2008-08-27 23:05 . 2008-08-27 23:05 <DIR> d-------- C:\Program Files\3D Home Architect
2008-08-27 23:05 . 2008-08-27 23:05 0 --a------ C:\WINDOWS\system32\_r_a_p_.tmp
2008-08-26 18:20 . 2008-08-26 18:20 <DIR> d-------- C:\Program Files\uTorrent
2008-08-26 18:20 . 2008-09-07 18:01 <DIR> d-------- C:\Documents and Settings\PC\Application Data\uTorrent
2008-08-25 18:27 . 2008-08-25 18:27 <DIR> d-------- C:\WINDOWS\Performance
2008-08-25 18:27 . 2008-08-25 18:27 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-08-25 18:27 . 2008-08-25 18:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2008-08-25 17:02 . 2008-08-25 17:02 <DIR> d-------- C:\Program Files\Apple Software Update
2008-08-25 17:02 . 2008-08-25 17:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-08-25 12:53 . 2008-08-25 12:53 <DIR> d-------- C:\Program Files\YouTube Downloader
2008-08-24 19:49 . 2008-08-25 01:37 413 --a------ C:\WINDOWS\wcx_ftp.ini
2008-08-24 17:23 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-24 17:22 . 2008-09-04 19:29 <DIR> d-------- C:\Program Files\Java
2008-08-24 17:22 . 2008-08-24 17:22 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-24 16:45 . 2008-09-03 15:49 19,144 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-08-24 16:43 . 2008-08-24 16:43 <DIR> d-------- C:\Program Files\Safari
2008-08-24 14:52 . 2008-08-24 14:52 <DIR> d-------- C:\Documents and Settings\PC\Application Data\InterVideo
2008-08-24 14:04 . 2008-08-24 16:44 <DIR> d-------- C:\Documents and Settings\PC\Application Data\Apple Computer
2008-08-24 13:57 . 2008-08-24 13:57 <DIR> d-------- C:\Program Files\InterVideo Information Service
2008-08-24 13:57 . 2008-08-24 13:57 <DIR> d-------- C:\Program Files\Common Files\Ulead
2008-08-24 13:57 . 2008-09-04 10:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-24 13:57 . 2006-05-11 18:41 654 --------- C:\WINDOWS\remove.iss
2008-08-24 13:56 . 2008-08-24 13:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-08-24 13:55 . 2008-08-24 13:55 <DIR> d-------- C:\Program Files\InterVideo
2008-08-24 13:55 . 2008-08-24 13:55 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2008-08-23 22:21 . 2008-08-23 22:35 <DIR> d-------- C:\WINDOWS\Logs
2008-08-23 13:25 . 2008-08-23 13:25 <DIR> d-------- C:\Documents and Settings\PC\Option
2008-08-23 13:07 . 2008-08-23 13:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FAM
2008-08-23 13:06 . 2008-08-23 22:09 <DIR> d-------- C:\Program Files\NewTech Infosystems
2008-08-23 13:06 . 2008-08-23 13:06 6,144 --a------ C:\WINDOWS\system32\drivers\NTIDrvr.sys
2008-08-23 13:06 . 2008-08-23 13:06 1,024 -r-h----- C:\WINDOWS\system32\NTIOFM4.dll
2008-08-23 13:06 . 2008-08-23 13:25 1,024 -r-h----- C:\WINDOWS\system32\NTIBUN5.dll
2008-08-23 11:39 . 2008-08-23 11:39 244 --ah----- C:\sqmnoopt00.sqm
2008-08-23 11:39 . 2008-08-23 11:39 232 --ah----- C:\sqmdata00.sqm
2008-08-23 01:37 . 2008-08-23 01:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GRETECH
2008-08-23 01:37 . 2008-09-09 01:52 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-08-23 01:35 . 2008-08-23 01:35 <DIR> d-------- C:\Program Files\GRETECH
2008-08-23 01:35 . 2008-08-23 01:35 <DIR> d-------- C:\Documents and Settings\PC\Application Data\GRETECH
2008-08-23 01:30 . 2008-08-23 11:15 <DIR> d-------- C:\Documents and Settings\PC\Contacts
2008-08-23 01:29 . 2008-09-03 15:36 <DIR> d-------- C:\Program Files\MSN Messenger
2008-08-23 00:44 . 2008-09-06 15:02 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-23 00:44 . 2008-09-06 15:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-23 00:31 . 2008-08-23 00:31 <DIR> d-------- C:\Documents and Settings\PC\Application Data\Nero
2008-08-23 00:28 . 2008-08-23 00:28 <DIR> d-------- C:\Program Files\Nero
2008-08-23 00:28 . 2008-08-23 00:29 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-08-23 00:28 . 2008-08-23 00:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-08 14:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-24 11:57 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-20 12:07 --------- d-----w C:\Program Files\Intel
2008-08-20 10:55 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-08-20 10:55 --------- d-----w C:\Program Files\Realtek
2008-08-20 10:37 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-29 18:20 24,774 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
2008-07-21 16:34 121,872 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-08-22 12:03 251,392 ----a-w C:\Program Files\opera\program\plugins\dapop.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-07-16 768520]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-06-27 143360]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-06-27 163840]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2008-06-27 135168]
"ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-04-04 421888]
"Boot"="C:\Acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-07-29 206088]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 C:\WINDOWS\RTHDCPL.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2008-08-20 45056]
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= msaud32_divx.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Handy Backup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
--a------ 2006-10-22 23:24 620152 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM]
--a------ 2007-03-20 16:40 1884160 C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DesktopMaestro]
--a------ 2008-08-01 10:35 3213200 C:\Program Files\Desktop Maestro\deskmech.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2008-06-24 16:06 1840424 C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a------ 2006-03-20 17:34 213936 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 05:42 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-06-08 09:31 2221352 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-06-19 09:53 570664 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ApexDC++\\ApexDC.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R2 MSSQL$CSSQL05;SQL Server (CSSQL05);C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 29178224]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Google Update - C:\Documents and Settings\PC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\PC\Application Data\Mozilla\Firefox\Profiles\xc5a1icr.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\browser\nppdf32.dll
FF -: plugin - C:\Program Files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll
FF -: plugin - C:\Program Files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDP32.DLL
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-09-09 20:34:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\WINDOWS\5ES6ES6ES0ET19N2

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\searchindexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxext.exe
C:\DOCUME~1\PC\LOCALS~1\temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2008-09-09 20:38:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-09 18:37:56

Pre-Run: 3,705,581,568 bytes free
Post-Run: 3,644,452,864 bytes free

282 --- E O F --- 2008-09-08 20:49:03

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Sad moram na spavanje, a sutra su radovi na mrezi, necu imati struju do 18h popodne. Tako da znas, odgovor tek sutra oko 21h.

offline
  • jt  Male
  • Građanin
  • sales representative
  • Pridružio: 27 Jun 2005
  • Poruke: 255

Ok. unapred hvala na odgovor.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Evo ovo uradi, pa cu sutra videti rezultate:

Preuzmi gmer.zip sa ovog linka i sačuvaj na Desktopu.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde ta dva fajla koja smo malopre snimili




Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Desni klik na sred forme programa. Pojaviće se menij u kojem je potrebno otići na Options i tu štiklirati opciju Only non MS files
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao fajl file3.txt


Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde fajl koji smo malopre snimili

offline
  • jt  Male
  • Građanin
  • sales representative
  • Pridružio: 27 Jun 2005
  • Poruke: 255

rezultati:

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Ima li sad nekih problema?

offline
  • jt  Male
  • Građanin
  • sales representative
  • Pridružio: 27 Jun 2005
  • Poruke: 255

Sad nema nista.

Dopuna: 10 Sep 2008 21:51

Momentalno nema nikakvih.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

OK. Uradi jos ovo:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore




Ako se nesto novo pojavi, javi se, znas gde smo.

Pozzz

Ko je trenutno na forumu
 

Ukupno su 1025 korisnika na forumu :: 82 registrovanih, 7 sakrivenih i 936 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 1MAP, aleksjevt, Betty25, bobomicek, Bojan198527, bojank, BORUTUS, BWG, Denaya, dinamik, doktor1964, Dorcolac, dragisa dragisa, drpera, Duh sa sekirom, dulleo, Foxhound59, Frunze, g_g, Georgius, Gheljda, istina, ivan1973, jarovitt, Kobrim, Kototamopeva, littlebunny, mainstream, malimedo01, Micko97, mikrimaus, milbos, milenko crazy north, MiroslavD, mist-mist, Miškić, mm1811, mrav pesadinac, N.e.m.a.nj.a., nebidrag, nemkea71, niksa517, NMNJ, Ognjen D., Pero, Petarvu, radoznao, Ranutovac, Razdroid, redstar72, Rothmans, ruseskij, Rusmir, samo opusteno, sap, sekretar, shajone, Shinobi, Stojan Mrsavi, strela, SympathyForTheDevil, synergia, Timočka Divizija, trajkoni018, Trimi68, tubular, vathra, Veless, Vica1958, Vlada1389, vladetije, voja64, vuk77, Weteran, yiyi, yrraf, Zmaj Tolak, zodiac94, zombicar153, Zoran1959, Zrcalo, zukara