Ne mogu da instaliram anti virus, i task manager mi je onesp

Ne mogu da instaliram anti virus, i task manager mi je onesp

offline
  • DBZ 
  • Novi MyCity građanin
  • Pridružio: 16 Maj 2009
  • Poruke: 4

ne mogu da instaliram neki redovan anti-virus, a onaj što sam imao mi je onesposobio taj virus il već šta je.Uspeo sam i jedino neki anti malware da instaliram i on pronadje ovo

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.

ali ne može da se reši toga. Reinstalirao sam windows i formatirao C disk i dalje je tu, verovatno se uvukao negde na D ali imam prefiše stvari tamo koje mi trebaju i ne mogu da ih obrišem. Ima li neke pomoći ?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...

Kreneš od ovoga...


offline
  • DBZ 
  • Novi MyCity građanin
  • Pridružio: 16 Maj 2009
  • Poruke: 4

evo ga

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:30:32 PM, on 16/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20772)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Flock\flock.exe
C:\Program Files\uTorrent\uTorrent.exe
F:\yxrs.exe
C:\Users\Dejan\Desktop\New Folder\asd.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5E579F29-5227-4038-AB44-32714F1E9307}: NameServer = 194.247.192.1 194.247.192.33
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 4953 bytes

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Šta ti je drive F: ? Particija na HDD-u, flash drive?




Arrow Skini program RSIT na Desktop:

http://images.malwareremoval.com/random/RSIT.exe


Pokreni ga dvoklikom a zatim klikni Continue.


Na kraju procesa će se otvoriti dva loga: prvi, log.txt će biti maksimizovan i njega je potrebno iskopirati u temu na forumu, te drugi, info.txt koji će biti minimizovan (koji nam za sada ne treba).


Postavi sadržaj file-a log.txt u iduću poruku (taj file će biti sačuvan kao C:\rsit\log.txt).

offline
  • DBZ 
  • Novi MyCity građanin
  • Pridružio: 16 Maj 2009
  • Poruke: 4

Logfile of random's system information tool 1.06 (written by random/random)
Run by Dejan at 2009-05-16 20:19:40
Microsoft Windows XP Professional Service Pack 3
System drive C: has 291 GB (97%) free of 300 GB
Total RAM: 2047 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:19:44 PM, on 16/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20772)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Flock\flock.exe
C:\Program Files\uTorrent\uTorrent.exe
D:\Program files\Rockstar Games\GTA San Andreas\gta_sa.exe
C:\Users\Dejan\Desktop\RSIT.exe
C:\Program Files\trend micro\Dejan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [RemoteControl9] "C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"
O4 - HKLM\..\Run: [PDVD9LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5E579F29-5227-4038-AB44-32714F1E9307}: NameServer = 194.247.192.1 194.247.192.33
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 5030 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll [2008-03-25 509328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"=C:\WINDOWS\system32\SysTray.Exe [2008-05-05 3072]
"RemoteControl9"=C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe [2009-02-16 87336]
"PDVD9LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe [2008-10-13 124200]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2009-05-10 75048]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-04-01 36352]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-07-03 16876032]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 135168]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-29 135168]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2007-01-23 178960]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-04-06 1347216]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-05-05 40448]

C:\Users\All Users\Start Menu\Programs\Startup
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-09-30 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-05-05 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-05-05 133632]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=1
"DisableTaskMgr"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SynchronousMachineGroupPolicy"=0
"SynchronousUserGroupPolicy"=0
"EnableLUA"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMConfigurePrograms"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoSMConfigurePrograms"=
"NoToolbarCustomize"=
"NoBandCustomize"=
"NoActiveDesktop"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Programi\ACDSee 10\acdsee-10-0-219-en.exe"="D:\Programi\ACDSee 10\acdsee-10-0-219-en.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE:*:Enabled:ipsec"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:ipsec"
"C:\WINDOWS\Explorer.EXE"="C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe"="C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe:*:Enabled:ipsec"
"C:\Program Files\Logitech\SetPoint\LULnchr.exe"="C:\Program Files\Logitech\SetPoint\LULnchr.exe:*:Enabled:ipsec"
"C:\WINDOWS\RTHDCPL.EXE"="C:\WINDOWS\RTHDCPL.EXE:*:Enabled:ipsec"
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe:*:Enabled:ipsec"
"C:\Program Files\Logitech\SetPoint\SetPoint.exe"="C:\Program Files\Logitech\SetPoint\SetPoint.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\userinit.exe"="C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec"
"C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe"="C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe:*:Enabled:ipsec"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76de4f71-412a-11de-a981-4d6564696130}]
shell\AUtOplay\command - F:\yxrs.exe
shell\AutoRun\command - F:\yxrs.exe
shell\exPLoRe\command - F:\yxrs.exe
shell\open\command - F:\yxrs.exe


======List of files/folders created in the last 1 months======

2009-05-16 20:19:40 ----D---- C:\rsit
2009-05-16 20:19:40 ----D---- C:\Program Files\trend micro
2009-05-16 17:50:27 ----A---- C:\Program Files\cgckbgej.txt
2009-05-15 22:32:24 ----D---- C:\Users\Dejan\Application Data\WinRAR
2009-05-15 12:57:49 ----D---- C:\Users\All Users\Application Data\GRETECH
2009-05-15 12:57:04 ----D---- C:\Users\Dejan\Application Data\GRETECH
2009-05-15 12:56:55 ----D---- C:\Program Files\GRETECH
2009-05-15 11:18:24 ----D---- C:\Users\Dejan\Application Data\CyberLink
2009-05-15 11:14:30 ----D---- C:\Users\Dejan\Application Data\Winamp
2009-05-15 10:29:13 ----D---- C:\Users\Dejan\Application Data\BSplayer PRO
2009-05-15 09:51:45 ----D---- C:\Users\Dejan\Application Data\Malwarebytes
2009-05-15 09:28:56 ----D---- C:\Users\Dejan\Application Data\Flock
2009-05-15 00:53:04 ----A---- C:\WINDOWS\system32\h323log.txt
2009-05-15 00:52:12 ----A---- C:\WINDOWS\system32\hidserv.dll
2009-05-15 00:51:49 ----A---- C:\WINDOWS\adidsl.ini
2009-05-15 00:50:23 ----A---- C:\WINDOWS\system32\usbui.dll
2009-05-15 00:49:11 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-05-15 00:49:10 ----SHD---- C:\WINDOWS\Installer
2009-05-15 00:49:10 ----D---- C:\Program Files\Common Files\ODBC
2009-05-15 00:49:10 ----A---- C:\WINDOWS\ODBCINST.INI
2009-05-15 00:49:07 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-05-15 00:49:06 ----RD---- C:\Program Files
2009-05-15 00:49:06 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-15 00:49:06 ----D---- C:\Program Files\Common Files
2009-05-15 00:49:02 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-05-15 00:49:02 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-05-15 00:49:02 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-05-15 00:48:59 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-05-15 00:48:58 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-05-15 00:48:56 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-05-15 00:48:54 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-05-15 00:48:52 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-05-15 00:48:51 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-05-15 00:48:46 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-05-15 00:48:46 ----A---- C:\WINDOWS\system32\irclass.dll
2009-05-15 00:48:46 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-05-15 00:48:46 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-05-15 00:48:45 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-05-15 00:48:43 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-05-15 00:48:43 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-05-15 00:48:42 ----A---- C:\WINDOWS\system32\batt.dll
2009-05-15 00:48:41 ----A---- C:\WINDOWS\system32\storprop.dll
2009-05-15 00:48:41 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-05-15 00:48:35 ----ASH---- C:\Users\All Users\Application Data\desktop.ini
2009-05-15 00:46:50 ----RA---- C:\WINDOWS\SET8.tmp
2009-05-15 00:46:49 ----RA---- C:\WINDOWS\SET4.tmp
2009-05-15 00:46:47 ----RA---- C:\WINDOWS\SET3.tmp
2009-05-15 00:46:43 ----D---- C:\WINDOWS\system32\CatRoot2
2009-05-15 00:46:43 ----D---- C:\WINDOWS\system32\CatRoot
2009-05-15 00:46:38 ----SD---- C:\Users\All Users\Application Data\Microsoft
2009-05-15 00:45:52 ----A---- C:\WINDOWS\setuplog.txt
2009-05-15 00:45:46 ----A---- C:\ShowWPI.ini
2009-05-15 00:43:59 ----A---- C:\WINDOWS\system32\adadix32.dll
2009-05-15 00:43:59 ----A---- C:\WINDOWS\system32\ADADIX2K.DLL
2009-05-15 00:42:06 ----D---- C:\ppGames
2009-05-15 00:42:06 ----D---- C:\ppApps
2009-05-15 00:42:04 ----A---- C:\WINDOWS\~DF6C7F.tmp
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\sleep.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\pskill.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\oeminfo.ini
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\nircmdc.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\nircmd.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\myuninst.exe
2009-05-15 00:41:57 ----A---- C:\WINDOWS\system32\cmdhide.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\WAIT.EXE
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\Tweakui.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\Refresh.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\MyCleaner.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\cWnd.exe
2009-05-15 00:41:56 ----A---- C:\WINDOWS\system32\calc.exe
2009-05-15 00:41:55 ----A---- C:\WINDOWS\system32\DELTREE.EXE
2009-05-15 00:41:55 ----A---- C:\WINDOWS\system32\ChangeWallpaper.exe
2009-05-15 00:41:37 ----A---- C:\WINDOWS\Removes.ini
2009-05-15 00:41:35 ----AD---- C:\WINDOWS\LastXP
2009-05-15 00:41:05 ----D---- C:\Users
2009-05-15 00:41:04 ----SHD---- C:\System Volume Information
2009-05-15 00:40:31 ----RSH---- C:\boot.ini
2009-05-15 00:34:24 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-05-15 00:34:24 ----RSD---- C:\WINDOWS\Fonts
2009-05-15 00:34:24 ----RD---- C:\WINDOWS\Offline Web Pages
2009-05-15 00:34:24 ----HD---- C:\WINDOWS\inf
2009-05-15 00:34:24 ----D---- C:\WINDOWS\WinSxS
2009-05-15 00:34:24 ----D---- C:\WINDOWS\WBEM
2009-05-15 00:34:24 ----D---- C:\WINDOWS\twain_32
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Temp
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\wins
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\wbem
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\usmt
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\spool
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\ShellExt
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\Setup
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\scripting
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\ras
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\oobe
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\npp
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\mui
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\inetsrv
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\IME
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\icsxml
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\ias
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\export
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\en-US
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\en
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\drivers
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\dhcp
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\config
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\3com_dmi
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\3076
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\2052
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1054
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1042
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1041
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1037
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1033
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1031
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1028
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system32\1025
2009-05-15 00:34:24 ----D---- C:\WINDOWS\system
2009-05-15 00:34:24 ----D---- C:\WINDOWS\security
2009-05-15 00:34:24 ----D---- C:\WINDOWS\repair
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Provisioning
2009-05-15 00:34:24 ----D---- C:\WINDOWS\PeerNet
2009-05-15 00:34:24 ----D---- C:\WINDOWS\pchealth
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Network Diagnostic
2009-05-15 00:34:24 ----D---- C:\WINDOWS\mui
2009-05-15 00:34:24 ----D---- C:\WINDOWS\msapps
2009-05-15 00:34:24 ----D---- C:\WINDOWS\msagent
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Media
2009-05-15 00:34:24 ----D---- C:\WINDOWS\L2Schemas
2009-05-15 00:34:24 ----D---- C:\WINDOWS\java
2009-05-15 00:34:24 ----D---- C:\WINDOWS\ime
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Help
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Driver Cache
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Debug
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Cursors
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Connection Wizard
2009-05-15 00:34:24 ----D---- C:\WINDOWS\Config
2009-05-15 00:34:24 ----D---- C:\WINDOWS\AppPatch
2009-05-15 00:34:24 ----D---- C:\WINDOWS\addins
2009-05-15 00:34:24 ----D---- C:\WINDOWS
2009-05-15 00:34:24 ----AD---- C:\WINDOWS\Web
2009-05-15 00:34:24 ----AD---- C:\WINDOWS\system32
2009-05-15 00:34:24 ----AD---- C:\WINDOWS\Resources
2009-05-14 23:57:07 ----D---- C:\Program Files\uTorrent
2009-05-14 23:56:41 ----D---- C:\Users\Dejan\Application Data\uTorrent
2009-05-14 23:55:31 ----D---- C:\Program Files\WinRAR
2009-05-14 23:54:45 ----D---- C:\Users\Dejan\Application Data\Macromedia
2009-05-14 23:54:45 ----D---- C:\Users\Dejan\Application Data\Adobe
2009-05-14 23:43:23 ----D---- C:\Users\Dejan\Application Data\Logitech
2009-05-14 23:43:06 ----SHD---- C:\RECYCLER
2009-05-14 23:43:06 ----R---- C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2009-05-14 23:42:19 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
2009-05-14 23:42:13 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-05-14 23:42:12 ----A---- C:\WINDOWS\system32\WdfCoInstaller01005.dll
2009-05-14 23:42:12 ----A---- C:\WINDOWS\KHALMNPR.Exe
2009-05-14 23:42:08 ----A---- C:\WINDOWS\system32\KemXML.dll
2009-05-14 23:42:08 ----A---- C:\WINDOWS\system32\KemWnd.dll
2009-05-14 23:42:08 ----A---- C:\WINDOWS\system32\KemUtil.dll
2009-05-14 23:42:08 ----A---- C:\WINDOWS\system32\kemutb.dll
2009-05-14 23:41:55 ----D---- C:\Users\All Users\Application Data\Logitech
2009-05-14 23:41:54 ----D---- C:\Program Files\Logitech
2009-05-14 23:41:52 ----D---- C:\Program Files\Common Files\Logitech
2009-05-14 23:38:35 ----D---- C:\Users\Dejan\Application Data\Mozilla
2009-05-14 23:38:31 ----D---- C:\Program Files\Mozilla Firefox
2009-05-14 23:35:44 ----D---- C:\WINDOWS\system32\Lang
2009-05-14 23:35:40 ----D---- C:\Users\Dejan\Application Data\ATI
2009-05-14 23:35:40 ----D---- C:\Users\All Users\Application Data\ATI
2009-05-14 23:35:25 ----D---- C:\Users\Dejan\Application Data\Identities
2009-05-14 23:35:25 ----A---- C:\WINDOWS\OEWABLog.txt
2009-05-14 23:35:11 ----ASH---- C:\Users\Dejan\Application Data\desktop.ini
2009-05-14 23:35:10 ----SD---- C:\Users\Dejan\Application Data\Microsoft
2009-05-14 23:31:30 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2009-05-14 23:31:28 ----RA---- C:\WINDOWS\system32\ATIODE.exe.manifest
2009-05-14 23:31:28 ----RA---- C:\WINDOWS\system32\ATIODCLI.exe.manifest
2009-05-14 23:31:28 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
2009-05-14 23:31:26 ----RA---- C:\WINDOWS\system32\ATIDEMGX.dll
2009-05-14 23:30:54 ----D---- C:\Program Files\ATI Technologies
2009-05-14 23:27:33 ----R---- C:\WINDOWS\system32\ChCfg.exe
2009-05-14 23:27:18 ----D---- C:\WINDOWS\system32\RTCOM
2009-05-14 23:27:17 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-05-14 23:27:14 ----R---- C:\WINDOWS\SoundMan.exe
2009-05-14 23:27:14 ----R---- C:\WINDOWS\SkyTel.exe
2009-05-14 23:27:13 ----R---- C:\WINDOWS\RtlUpd.exe
2009-05-14 23:27:11 ----R---- C:\WINDOWS\RTLCPL.exe
2009-05-14 23:27:06 ----R---- C:\WINDOWS\RTHDCPL.exe
2009-05-14 23:27:05 ----R---- C:\WINDOWS\MicCal.exe
2009-05-14 23:27:00 ----R---- C:\WINDOWS\Alcmtr.exe
2009-05-14 23:26:58 ----R---- C:\WINDOWS\alcwzrd.exe
2009-05-14 23:26:57 ----D---- C:\Program Files\Realtek
2009-05-14 23:26:49 ----A---- C:\WINDOWS\HideWin.exe
2009-05-14 23:26:48 ----R---- C:\WINDOWS\RtlExUpd.dll
2009-05-14 23:25:49 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-05-14 23:25:48 ----D---- C:\Program Files\AMD
2009-05-14 23:23:09 ----A---- C:\WINDOWS\Fast800.ini
2009-05-14 23:23:05 ----A---- C:\WINDOWS\system32\IPDETECT.EXE
2009-05-14 23:23:05 ----A---- C:\WINDOWS\adirasx64.exe
2009-05-14 23:23:05 ----A---- C:\WINDOWS\adiras.ini
2009-05-14 23:23:05 ----A---- C:\WINDOWS\adiras.exe
2009-05-14 23:23:00 ----A---- C:\WINDOWS\system32\coclassfast.dll
2009-05-14 23:23:00 ----A---- C:\WINDOWS\enddisk32.exe
2009-05-14 23:23:00 ----A---- C:\WINDOWS\autoclk.exe
2009-05-14 23:22:59 ----A---- C:\WINDOWS\system32\unaddrv.x64.exe
2009-05-14 23:22:59 ----A---- C:\WINDOWS\system32\unaddrv.exe
2009-05-14 23:22:59 ----A---- C:\WINDOWS\system32\ADADIX16.DLL
2009-05-14 23:22:49 ----D---- C:\Program Files\SAGEM
2009-05-14 23:21:12 ----A---- C:\WINDOWS\system32\unrar.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2009-05-14 23:21:11 ----A---- C:\WINDOWS\system32\dpl100.dll
2009-05-14 23:21:10 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2009-05-14 23:21:10 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2009-05-14 23:21:10 ----A---- C:\WINDOWS\system32\divx.dll
2009-05-14 23:21:09 ----D---- C:\Program Files\K-Lite Codec Pack
2009-05-14 23:20:25 ----D---- C:\Users\All Users\Application Data\Malwarebytes
2009-05-14 23:20:24 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\vxblock.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxwave.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxmas.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxdrv.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\pxafs.dll
2009-05-14 23:19:21 ----N---- C:\WINDOWS\system32\px.dll
2009-05-14 23:19:19 ----D---- C:\Program Files\Winamp
2009-05-14 23:18:28 ----D---- C:\totalcmd
2009-05-14 23:18:28 ----A---- C:\WINDOWS\wincmd.ini
2009-05-14 23:17:41 ----D---- C:\Program Files\Flock
2009-05-14 23:15:37 ----D---- C:\Users\All Users\Application Data\CyberLink
2009-05-14 23:15:32 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-14 23:15:32 ----D---- C:\Program Files\Common Files\CyberLink
2009-05-14 23:15:13 ----D---- C:\Program Files\CyberLink
2009-05-14 23:15:05 ----A---- C:\WINDOWS\system32\msxml3a.dll
2009-05-14 23:14:33 ----D---- C:\Users\All Users\Application Data\Temp
2009-05-14 23:13:33 ----D---- C:\Program Files\Webteh
2009-05-14 23:10:54 ----D---- C:\Users\All Users\Application Data\ACD Systems
2009-05-14 23:10:52 ----D---- C:\Program Files\Common Files\ACD Systems
2009-05-14 23:10:52 ----D---- C:\Program Files\ACD Systems
2009-05-14 23:07:57 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-05-14 23:07:08 ----D---- C:\Users\All Users\Application Data\Windows Genuine Advantage
2009-05-14 23:06:46 ----D---- C:\WINDOWS\SoftwareDistribution
2009-05-14 23:06:44 ----SD---- C:\WINDOWS\system32\Microsoft
2009-05-14 23:06:44 ----D---- C:\WINDOWS\Prefetch
2009-05-14 23:06:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-05-14 23:04:39 ----D---- C:\Program Files\Microsoft Silverlight
2009-05-14 23:04:35 ----A---- C:\WINDOWS\system32\javaws.exe
2009-05-14 23:04:35 ----A---- C:\WINDOWS\system32\javaw.exe
2009-05-14 23:04:35 ----A---- C:\WINDOWS\system32\java.exe
2009-05-14 23:04:25 ----D---- C:\Program Files\Java
2009-05-14 23:04:25 ----D---- C:\Program Files\Common Files\Java
2009-05-14 23:04:03 ----D---- C:\Program Files\Common Files\InstallShield
2009-05-14 23:00:57 ----D---- C:\WINDOWS\system32\XPSViewer
2009-05-14 23:00:57 ----D---- C:\Program Files\MSBuild
2009-05-14 23:00:56 ----D---- C:\Program Files\Reference Assemblies
2009-05-14 23:00:52 ----N---- C:\WINDOWS\system32\spmsg2.dll
2009-05-14 22:59:37 ----RSD---- C:\WINDOWS\assembly
2009-05-14 22:59:37 ----D---- C:\WINDOWS\Microsoft.NET
2009-05-14 22:59:36 ----D---- C:\WINDOWS\system32\URTTemp
2009-05-14 22:59:33 ----N---- C:\WINDOWS\system32\XpsSvcs.dll
2009-05-14 22:59:33 ----N---- C:\WINDOWS\system32\XPSSHHDR.dll
2009-05-14 22:59:24 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-05-14 22:58:38 ----D---- C:\Program Files\Windows Sidebar
2009-05-14 22:58:36 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-05-14 22:58:36 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-05-14 22:58:27 ----D---- C:\Program Files\Alky for Applications
2009-05-14 22:58:15 ----A---- C:\WINDOWS\control.ini
2009-05-14 22:58:15 ----A---- C:\AUTOEXEC.BAT
2009-05-14 22:58:02 ----D---- C:\WINDOWS\system32\dllcache
2009-05-14 22:58:02 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-05-14 22:57:24 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-05-14 22:57:21 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-05-14 22:57:17 ----HD---- C:\Program Files\WindowsUpdate
2009-05-14 22:56:52 ----D---- C:\WINDOWS\system32\DirectX
2009-05-14 22:56:44 ----A---- C:\WINDOWS\system32\atrace.dll
2009-05-14 22:56:42 ----A---- C:\WINDOWS\system32\desktop.ini
2009-05-14 22:56:42 ----A---- C:\WINDOWS\desktop.ini
2009-05-14 22:56:34 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-05-14 22:56:32 ----D---- C:\Program Files\Common Files\Services
2009-05-14 22:56:32 ----A---- C:\WINDOWS\system32\acctres.dll
2009-05-14 22:56:28 ----SD---- C:\WINDOWS\Tasks
2009-05-14 22:56:28 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-05-14 22:56:27 ----D---- C:\Program Files\Common Files\MSSoap
2009-05-14 22:56:22 ----D---- C:\WINDOWS\srchasst
2009-05-14 22:56:21 ----D---- C:\WINDOWS\system32\Macromed
2009-05-14 22:56:18 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-05-14 22:56:18 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-05-14 22:56:18 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-05-14 22:56:18 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-05-14 22:56:17 ----A---- C:\WINDOWS\system32\wups.dll
2009-05-14 22:56:17 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-05-14 22:56:17 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-05-14 22:56:16 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-05-14 22:56:11 ----D---- C:\Program Files\Movie Maker
2009-05-14 22:55:48 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-05-14 22:55:48 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-05-14 22:55:48 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-05-14 22:55:47 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-05-14 22:55:43 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-05-14 22:55:43 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-05-14 22:55:42 ----D---- C:\WINDOWS\system32\Restore
2009-05-14 22:55:42 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-05-14 22:55:42 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-05-14 22:55:42 ----A---- C:\WINDOWS\system32\srclient.dll
2009-05-14 22:55:41 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-05-14 22:55:41 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-05-14 22:55:41 ----A---- C:\WINDOWS\system32\ils.dll
2009-05-14 22:55:40 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-05-14 22:55:40 ----A---- C:\WINDOWS\system32\msconf.dll
2009-05-14 22:55:40 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-05-14 22:55:37 ----D---- C:\Program Files\NetMeeting
2009-05-14 22:55:36 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-05-14 22:55:36 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-05-14 22:55:34 ----A---- C:\WINDOWS\system32\inetres.dll
2009-05-14 22:55:34 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-05-14 22:55:32 ----D---- C:\Program Files\Outlook Express
2009-05-14 22:55:32 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-05-14 22:55:32 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-05-14 22:55:31 ----A---- C:\WINDOWS\system32\mstask.dll
2009-05-14 22:55:31 ----A---- C:\WINDOWS\system32\isign32.dll
2009-05-14 22:55:31 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-05-14 22:55:31 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-05-14 22:55:30 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-05-14 22:55:23 ----D---- C:\Program Files\Common Files\System
2009-05-14 22:55:21 ----D---- C:\Program Files\Internet Explorer
2009-05-14 22:55:02 ----HD---- C:\Program Files\Uninstall Information
2009-05-14 22:54:53 ----D---- C:\Program Files\ComPlus Applications
2009-05-14 22:54:52 ----A---- C:\WINDOWS\vbaddin.ini
2009-05-14 22:54:52 ----A---- C:\WINDOWS\vb.ini
2009-05-14 22:54:48 ----D---- C:\WINDOWS\Registration
2009-05-14 22:54:33 ----D---- C:\Program Files\Windows Media Connect 2
2009-05-14 22:54:32 ----D---- C:\Program Files\Windows Media Player
2009-05-14 22:54:32 ----A---- C:\WINDOWS\system32\cygwin1.dll
2009-05-14 22:54:31 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2009-05-14 22:54:31 ----A---- C:\WINDOWS\system32\autoitx3.dll
2009-05-14 22:54:31 ----A---- C:\WINDOWS\system32\atl71.dll
2009-05-14 22:54:31 ----A---- C:\WINDOWS\system32\atl70.dll
2009-05-14 22:54:30 ----A---- C:\WINDOWS\system32\vb40032.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\ssleay32.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\openal32.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvcr71.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvcr70.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvcp71.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvcp70.dll
2009-05-14 22:54:29 ----A---- C:\WINDOWS\system32\msvci70.dll
2009-05-14 22:54:28 ----A---- C:\WINDOWS\system32\msstkprp.dll
2009-05-14 22:54:28 ----A---- C:\WINDOWS\system32\msstdfmt.dll
2009-05-14 22:54:27 ----A---- C:\WINDOWS\system32\mfc71u.dll
2009-05-14 22:54:27 ----A---- C:\WINDOWS\system32\mfc71.dll
2009-05-14 22:54:27 ----A---- C:\WINDOWS\system32\mfc70u.dll
2009-05-14 22:54:26 ----A---- C:\WINDOWS\system32\mfc70.dll
2009-05-14 22:54:26 ----A---- C:\WINDOWS\system32\libssl32.dll
2009-05-14 22:54:26 ----A---- C:\WINDOWS\system32\libmmd.dll
2009-05-14 22:54:25 ----A---- C:\WINDOWS\system32\libintl3.dll
2009-05-14 22:54:25 ----A---- C:\WINDOWS\system32\libiconv2.dll
2009-05-14 22:54:25 ----A---- C:\WINDOWS\system32\libeay32.dll
2009-05-14 22:54:24 ----A---- C:\WINDOWS\system32\cygwinb19.dll
2009-05-14 22:54:14 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-05-14 22:54:14 ----A---- C:\WINDOWS\system32\hticons.dll
2009-05-14 22:54:13 ----D---- C:\Program Files\Windows NT
2009-05-14 22:54:13 ----A---- C:\WINDOWS\system32\winchat.exe
2009-05-14 22:54:12 ----A---- C:\WINDOWS\system32\reset.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tskill.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\tscon.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\shadow.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\regini.exe
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-05-14 22:54:11 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\msg.exe
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\logoff.exe
2009-05-14 22:54:10 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-05-14 22:54:02 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-05-14 22:54:02 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-05-14 22:54:02 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-05-14 22:54:02 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-05-14 22:54:01 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-05-14 22:54:00 ----A---- C:\WINDOWS\system32\tsgqec.dll
2009-05-14 22:54:00 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-05-14 22:54:00 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2009-05-14 22:54:00 ----A---- C:\WINDOWS\system32\aaclient.dll
2009-05-14 22:53:59 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-05-14 22:53:59 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-05-14 22:53:59 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-05-14 22:53:58 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-05-14 22:53:57 ----D---- C:\WINDOWS\system32\MsDtc
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-05-14 22:53:57 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-05-14 22:53:56 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-05-14 22:53:56 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-05-14 22:53:56 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-05-14 22:53:56 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-05-14 22:53:55 ----D---- C:\WINDOWS\system32\Com
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-05-14 22:53:55 ----A---- C:\WINDOWS\system32\colbact.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\stclient.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-05-14 22:53:54 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-05-14 22:53:53 ----A---- C:\WINDOWS\system32\comuid.dll
2009-05-14 22:53:53 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-05-14 22:53:53 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-05-14 22:53:53 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-05-14 22:53:45 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-05-14 22:53:45 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-05-14 22:53:45 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-05-14 22:53:45 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2009-05-14 23:14:30 ----A---- C:\WINDOWS\system32\msxml3r.dll
2009-05-14 23:08:41 ----A---- C:\WINDOWS\system.ini
2009-05-14 22:58:13 ----A---- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/05/14 23:15:37]; \??\C:\Program Files\CyberLink\PowerDVD9\000.fcl []
R3 abp470n5;abp470n5; \??\C:\WINDOWS\system32\drivers\ikkoon.sys []
R3 adiusbaw;USB ADSL WAN Adapter; C:\WINDOWS\system32\DRIVERS\adiusbaw.sys [2007-02-07 118552]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-09-30 3331584]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-07-02 89600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-05-05 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-07-03 4745216]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-01-23 34576]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2007-01-23 33296]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [2007-01-23 28176]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S2 ELOADER;General Purpose USB Driver (adildr.sys); C:\WINDOWS\System32\Drivers\adildr.sys [2007-02-07 56088]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-05-05 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-05-05 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-09-30 581632]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-09-30 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 143360]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 991232]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-05-05 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Sality virus - ovo ne može da se očisti na valjan način.


Ono što treba da uradiš jeste:

- formatiraj C: particiju i instaliraj Windows.
- odmah nakon toga skini i skeniraj ovim programom:

http://www.freedrweb.com/download+cureit/gr/

Potrebno je skenirati kompletan HDD kako se ne bi opet inficirao.

Nakon toga bi sve trebalo biti ok.

Ono što je bitno - skeniranje moraš izvršiti odmah nakon instalacije Windows-a. Znači, nikakve instalacije programa ili otvaranje ostalih particija pomoću Windows Explorer-a pre no što sve bude dezinfikovano.


Nisi mi odgovorio šta ti je F: drive. U svakom slučaju, i on je inficiran. Imaj to na umu.


Detaljno uputstvo za skeniranje:

Preuzmi Dr.Web CureIt (~13 MB).
Dvoklikom pokreni launch.exe, nakon čega će se pojaviti uvodni prozor - klikni Start

Pojaviće se obaveštenje o započinjanju uvodnog skeniranja - klikni OK

Sačekaj nekoliko minuta da Dr.Web CureIt izvrši Express Scan; ukoliko malware bude pronađen, klikom na taster Yes to All u prozoru koji se pojavi dozvoli programu da izvrši dezinfekciju

Klikni Options > Change settings F9; u prozoru koji će se otvoriti, dečekiraj opciju Heuristic Analysis a zatim klikni OK

U glavnom prozoru obeleži opciju Complete scan a zatim klikni i Dr.Web CureIt će započeti skeniranje

Ukoliko malware bude pronađen, klikom na taster Yes to All u prozoru koji se pojavi dozvoli programu da izvrši dezinfekciju

Kada skeniranje bude završeno, klikni Select all taster (ukoliko je dostupan), a zatim klikni Cure i,
u meniju koji se otvori, klikni Move incurable:


Po završetku procesa, klikni File > Save report list i sačuvaj log na Desktopu

offline
  • DBZ 
  • Novi MyCity građanin
  • Pridružio: 16 Maj 2009
  • Poruke: 4

Jesam ga, hvala ti mnogo.Predlpostavljam da hoces da vidis log pa cu ti prekopirati.

It_s_the_Great_Pumpkin__1966_.exe;D:\Dejan\Charile Brown and Snoopy;Win32.Sector.17;Cured.;
daemon4121-lite.exe\data051;D:\Dejan\Programi\daemon4121-lite.exe;Adware.Shopper;;
daemon4121-lite.exe;D:\Dejan\Programi;Archive contains infected objects;Moved.;
ffdshow_rev1928_20080410_xxl_setup.exe;D:\Dejan\Programi;Trojan.MulDrop.15890;Deleted.;
Firefox Setup 3.0.10.exe;D:\Dejan\Programi;Win32.Sector.17;Cured.;
GOMPLAYERENSETUP.EXE;D:\Dejan\Programi;Win32.Sector.17;Cured.;
xchat-2.8.7c.exe\data011;D:\Dejan\Programi\xchat-2.8.7c.exe;Trojan.DownLoad.31821;;
xchat-2.8.7c.exe;D:\Dejan\Programi;Archive contains infected objects;Moved.;
acdsee-10-0-219-en.exe;D:\Dejan\Programi\ACDSee 10;Win32.Sector.17;Cured.;
bsplayer_pro231.974.exe;D:\Dejan\Programi\BSplayer Pro v2.31 Build 974 [Software][Players][www.erostorrent.com];Win32.Sector.17;Cured.;
CORE10k.EXE;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz];Win32.Sector.17;Cured.;
CLSM.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup;Win32.Sector.17;Cured.;
instmsiw.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup;Win32.Sector.17;Cured.;
setup.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup;Win32.Sector.17;Cured.;
RichVideo.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup\RichVideo;Win32.Sector.17;Cured.;
RichVideoInstall.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup\RichVideo;Win32.Sector.17;Cured.;
RichVideoUnInstall.exe;D:\Dejan\Programi\CyberLink.PowerDVD.Ultra.v9.0.waxe.[Movie-Torrentz]\CyberLink_PowerDVD9_Ultra_setup\RichVideo;Win32.Sector.17;Cured.;
7za.exe;D:\Program files\Activision\Call of Duty 4 - Modern Warfare\Mods\ModWarfare;Win32.Sector.17;Cured.;
Transformers.exe;D:\Program files\Activision\Transformers - The Game;Win32.Sector.17;Cured.;
Launcher.exe;D:\Program files\Capcom\MotoGP 08;Win32.Sector.17;Cured.;
Pure.exe;D:\Program files\Disney Interactive Studios\Pure;Win32.Sector.17;Cured.;
DSN1.exe;D:\Program files\Disney Interactive Studios\Pure\eReg;Win32.Sector.17;Cured.;
Fouc.exe;D:\Program files\Empire Interactive\FlatOut Ultimate Carnage\FlatOut Ultimate Carnage;Win32.Sector.17;Cured.;
launcher.exe;D:\Program files\Empire Interactive\FlatOut Ultimate Carnage\FlatOut Ultimate Carnage;Win32.Sector.17;Cured.;
dxwebsetup.exe;D:\Program files\Empire Interactive\FlatOut Ultimate Carnage\FlatOut Ultimate Carnage\#readme#\redist;Win32.Sector.17;Cured.;
vcredist_x86.exe;D:\Program files\Empire Interactive\FlatOut Ultimate Carnage\FlatOut Ultimate Carnage\#readme#\redist;Win32.Sector.17;Cured.;
protect.exe;D:\Program files\Empire Interactive\FlatOut2;Win32.Sector.17;Cured.;
settings.exe;D:\Program files\KONAMI\Pro Evolution Soccer 2008;Win32.Sector.17;Cured.;
Unleashed Editor.exe;D:\Program files\THQ\MX vs ATV Unleashed;Win32.Sector.17;Cured.;
_isdel.exe;D:\Program files\THQ\MX vs ATV Unleashed;Win32.Sector.17;Cured.;
A0004073.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP1;Win32.Sector.17;Cured.;
A0004474.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004499.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004599.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004645.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004699.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004748.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004920.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004921.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004937.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004957.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004958.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004959.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004960.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004961.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004965.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004970.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004977.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0004978.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005025.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005045.EXE;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005236.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005237.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005247.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005248.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005249.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005250.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005251.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005252.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005255.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005260.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005263.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005264.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005371.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005390.EXE;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005587.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005588.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005599.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005600.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005601.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005602.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005603.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005604.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005607.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005612.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005615.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005616.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP10;Win32.Sector.17;Cured.;
A0005717.EXE;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP11;Win32.Sector.17;Cured.;
A0005746.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP11;Win32.Sector.17;Cured.;
A0004102.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP2;Win32.Sector.17;Cured.;
A0004229.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP4;Win32.Sector.17;Cured.;
A0004263.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP5;Win32.Sector.17;Cured.;
A0004379.exe;D:\System Volume Information\_restore{023E65F5-8FFD-4290-95BF-B1C0F60A5A03}\RP8;Win32.Sector.17;Cured.;
A0000794.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000796.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000798.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000799.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000806.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000807.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000810.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000811.exe;D:\System Volume Information\_restore{48D35831-0504-42E9-B7BC-FC9A8C553AE9}\RP5;Win32.Sector.17;Cured.;
A0000795.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000796.exe\data051;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3\A0000796.exe;Adware.Shopper;;
A0000796.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Archive contains infected objects;Moved.;
A0000797.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Trojan.MulDrop.15890;Deleted.;
A0000798.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000799.EXE;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000800.exe\data011;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3\A0000800.exe;Trojan.DownLoad.31821;;
A0000800.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Archive contains infected objects;Moved.;
A0000801.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000802.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000803.EXE;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000804.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000805.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000806.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000807.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000808.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000809.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000810.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000811.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000812.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000813.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000814.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000815.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000816.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000817.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000818.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000819.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000820.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000821.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
A0000822.exe;D:\System Volume Information\_restore{B1A3582D-7C66-45F0-BAD9-4172F0B8D6D9}\RP3;Win32.Sector.17;Cured.;
uoiyi.exe;F:\;Win32.Sector.17;Deleted.;
vvcfo.exe;F:\;Win32.Sector.17;Deleted.;
yxrs.exe;F:\;Win32.Sector.17;Deleted.;

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

To bi trebalo biti to. Instaliraj antivirus i onda polako dalje...


poz

Ko je trenutno na forumu
 

Ukupno su 948 korisnika na forumu :: 33 registrovanih, 7 sakrivenih i 908 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: comi_pfc, darios, dehhhhi, Dimitrije Paunovic, djordje92sm, draganl, hyla, kybonacci, Lazarus, ljuba, Lucky_Bastard, mean_machine, mercedesamg, Mihajlo, Milan A. Nikolic, mkukoleca, ObelixSRB, pein, perko91, Povratak1912, procesor, Profica, proka89, radoznao, Romibrat, sasa87, shone34, Sirius, Trpe Grozni, Vatreni Zmaj, W123, YugoSlav, Zoca