Tema za korisnike koji imaju zaražen računar

  • Začetnik teme Začetnik teme clan
  • Datum pokretanja Datum pokretanja
Uh, Norton...

Pravilo je prije bilo, ne znam sada, da svaki problem, nova tema, ovde se sada ne drze tog pravila ne znam zbog cega, ali ipak, Skini Hijak This program, samo skeniraj sa njim, nakon toga, log od tog programa iskopiraj ovde, pa cemo napraviti analizu istog i predloziti rjesenje..
Pored tog sto si naveo, vjerujem i mogu da sumnjam da ima jos toga sto treba da se ocisti..

Nije dovoljan samo AV program da bi jedan komp bio pristojno zasticen..
 
Evo mog izvestaja... poduzi.
Logfile of HijackThis v1.99.1
Scan saved at 23:32:16, on 2009-04-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SiSAudUt.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Konstantin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\Srbzila\firefox.exe
C:\Documents and Settings\Konstantin\Desktop\trazilicavirusa.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Axelero
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:0/proxy.pac
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - (no file)
O2 - BHO: MMklkl - {1428A472-5260-404E-9977-7ECDF1DAF936} - C:\WINDOWS\system32\mukmil.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SiS7012Utility] C:\WINDOWS\system32\SiSAudUt.exe -wdm
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: fffedeaabdcac - C:\WINDOWS\system32\fffedeaabdcac.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII\RpcSandraSrv.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 
Hmmm

Prvo. desni klik na ikonicu od tvog antivirus programa:
zatim opcija DISABLE

Zatim preuzmi sledeci program sa ovog linka

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Downloaduj na Desktop

Startuj program sa duplim klikom, isprati uputstva a zatim nista ne diraj niti pokreci bilo koji program , ne klikaj unutar prozora koji skenira..

Tokom rada ovaj program ce da iskljuci tvoju aktivnu internet konekciju, i kad bude gotovo skeniranje restartovace ti se komp..

Nakon zavrsetka program ce da prikaze log koji ces da postavis ovde...
 
Dragi moji pomagaci,
evo prilazem izvestaj i da napomenem da je za vreme rada se "ubacivao" norton, mada je bio iskljucen, kojeg sam iskljucivao sa W task managerom.

ComboFix 09-04-22.02 - Konstantin 2009-04-22 1:52.1 - NTFSx86
Running from: c:\documents and settings\Konstantin\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Konstantin\ResErrors.log
c:\documents and settings\Konstantin\Start Menu\Programs\System Security
c:\documents and settings\Konstantin\Start Menu\Programs\System Security\System Security 2009 Support.lnk
c:\windows\SNMPAPI.DLL
c:\windows\system32\mukmil.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DHLP
-------\Legacy_NTMLSVC
-------\Legacy_OREANS32
-------\Service_NtmlSvc
-------\Service_oreans32


((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.

2009-04-07 20:52 . 2009-04-08 01:26 826 ----a-w c:\windows\wininit.ini
2009-04-07 14:38 . 2009-04-07 14:38 -------- d-----w c:\documents and settings\Konstantin\Application Data\Nero
2009-04-06 21:23 . 2009-04-21 14:11 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-06 16:22 . 2009-04-06 16:22 4767 ----a-w c:\windows\Irremote.ini
2009-04-06 16:09 . 2009-04-06 16:09 -------- d-----w c:\program files\Windows Sidebar
2009-04-05 15:34 . 2009-04-05 15:34 32 --sha-w c:\windows\system32\{C2A4F7ED-350D-4767-8F70-EA3B52732969}.dat
2009-04-05 15:34 . 2009-04-05 15:34 32 --sha-w c:\windows\{B13B8A68-FC76-48B2-84BE-D1127BBF634E}.dat
2009-04-05 15:32 . 2009-04-05 15:32 32 --sha-w c:\windows\system32\{745E01C9-EC4A-46D3-8EEA-203B1BAED72B}.dat
2009-04-05 15:32 . 2009-04-05 15:32 32 --sha-w c:\windows\{6A5BFBE0-8629-404D-B0AC-6975D891DA46}.dat
2009-04-05 15:31 . 2002-09-21 01:12 83672 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-04-05 15:31 . 2002-09-21 01:12 73640 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-05 15:31 . 2002-09-21 01:12 123619 ----a-w c:\windows\system32\SYMEVNT.386
2009-04-05 15:31 . 2009-04-05 16:08 -------- d-----w c:\program files\Norton Internet Security
2009-04-05 15:30 . 2009-04-05 15:30 14 ----a-w c:\windows\system32\SR2.dat
2009-04-05 15:30 . 2009-04-05 15:30 -------- d-----w c:\documents and settings\Konstantin\Application Data\Symantec
2009-04-05 15:29 . 2009-04-22 00:10 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-05 15:29 . 2009-04-07 02:00 -------- d-----w c:\program files\Norton AntiVirus
2009-04-05 15:28 . 2009-04-05 15:33 -------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-04-05 15:28 . 2009-04-05 15:33 -------- d-----w c:\program files\Symantec
2009-04-05 15:22 . 2009-04-05 15:22 5311 ----a-w C:\huadio.tmp
2009-04-04 13:16 . 2009-04-06 00:31 -------- d-----w c:\program files\a2
2009-04-04 11:22 . 2008-10-16 12:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-04-04 11:22 . 2008-10-16 12:06 27496 ----a-w c:\windows\system32\mucltui.dll.mui
2009-04-04 11:22 . 2008-10-16 12:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-04-03 16:19 . 2009-04-03 16:20 -------- d-----w c:\documents and settings\All Users\Application Data\00104234
2009-03-30 21:14 . 2009-03-30 21:14 -------- d-----w c:\program files\Common Files\DivX Shared
2009-03-30 21:14 . 2009-03-30 21:16 -------- d-----w c:\program files\DivX

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-21 22:23 . 2007-02-08 15:29 -------- d-----w c:\documents and settings\Konstantin\Application Data\Skype
2009-04-21 20:50 . 2008-04-07 12:43 -------- d-----w c:\program files\Srbzila
2009-04-21 18:40 . 2009-01-26 15:22 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-21 14:15 . 2009-04-07 10:28 856 ----a-w C:\gmail_debug_response1.txt
2009-04-21 14:15 . 2009-04-07 10:28 819 ----a-w C:\gmail_debug_headers2.txt
2009-04-21 14:15 . 2009-04-07 10:28 818 ----a-w C:\gmail_debug_headers1.txt
2009-04-21 14:15 . 2009-04-07 10:28 279 ----a-w C:\gmail_debug_headers3.txt
2009-04-21 14:15 . 2009-04-07 10:28 237 ----a-w C:\gmail_debug_headers4.txt
2009-04-21 14:15 . 2009-04-07 10:28 219 ----a-w C:\gmail_debug_response4.txt
2009-04-21 14:15 . 2009-04-07 10:28 1638 ----a-w C:\gmail_debug_response2.txt
2009-04-21 14:15 . 2009-04-07 10:28 156 ----a-w C:\gmail_debug_response3.txt
2009-04-10 13:41 . 2009-02-05 13:39 -------- d-----w c:\program files\Common Files\Nero
2009-04-10 12:32 . 2009-02-05 13:40 -------- d-----w c:\documents and settings\All Users\Application Data\Nero
2009-04-09 17:20 . 2009-01-21 13:55 -------- d-----w c:\documents and settings\Konstantin\Application Data\uTorrent
2009-04-07 20:53 . 2008-12-05 13:29 -------- d-----w c:\program files\IMSurfSentinel
2009-04-07 14:48 . 2006-11-30 15:43 -------- d-----w c:\documents and settings\Konstantin\Application Data\Ahead
2009-04-05 11:52 . 2009-01-22 12:20 -------- d-----w c:\program files\ESET
2009-04-04 01:42 . 2007-02-11 22:42 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-27 11:33 . 2007-02-12 00:48 -------- d-----w c:\program files\Java
2009-03-17 16:47 . 2009-03-17 16:44 -------- d-----w c:\program files\QuickTime
2009-03-17 16:44 . 2007-05-22 21:22 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-17 16:39 . 2009-03-17 16:39 -------- d-----w c:\program files\Apple Software Update
2009-03-17 16:39 . 2009-03-17 16:39 -------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-03-17 11:52 . 2007-02-08 15:28 -------- d-----w c:\program files\Google
2009-03-09 04:19 . 2009-01-16 12:54 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 13:09 . 2009-03-08 13:09 -------- d-----w c:\documents and settings\Konstantin\Application Data\ABBYY
2009-01-22 15:17 . 2009-01-22 15:17 6656 ----a-w c:\windows\system32\haspvdd.dll
2007-09-05 09:23 . 2006-11-17 12:44 76344 ----a-w c:\documents and settings\Konstantin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-03-05 09:56 . 2007-03-05 09:56 18480 ----a-w c:\documents and settings\Konstantin\Application Data\GDIPFONTCACHEV1.DAT
2009-01-27 01:2009-01-27 01:34 34:38 . c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:2009-01-27 01:34 34:38 . c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-02-02 10:2007-02-11 00:01 27:50 . c:\program files\mozilla firefox\components\jar50.dll
2008-02-02 10:2007-02-11 00:01 27:50 . c:\program files\mozilla firefox\components\jsd3250.dll
2008-02-02 10:2007-02-11 00:01 27:50 . c:\program files\mozilla firefox\components\myspell.dll
2008-02-02 10:2007-02-11 00:01 27:50 . c:\program files\mozilla firefox\components\spellchk.dll
2008-02-02 10:2007-02-11 00:01 27:50 . c:\program files\mozilla firefox\components\xpinstal.dll
.

nastavak sledi jer je prevelik
 
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-28 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS7012Utility"="c:\windows\system32\SiSAudUt.exe" [2001-11-21 294912]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2008-09-02 26112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2002-09-21 54976]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-09-21 38592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sat_speed.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Server4PC.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Konstantin^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"Wmi"=3 (0x3)
"winmgmt"=2 (0x2)
"WebClient"=2 (0x2)
"SharedAccess"=2 (0x2)
"Irmon"=2 (0x2)
"helpsvc"=2 (0x2)
"gusvc"=3 (0x3)
"ERSvc"=2 (0x2)
"BITS"=2 (0x2)
"AppMgmt"=3 (0x3)
"AntiVirService"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\documents and settings\Konstantin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Voipwise.com\\Voipwise\\Voipwise.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII\\Win32\\RpcDataSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII\\RpcSandraSrv.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R3 autorun;autorun;c:\huadio.tmp [2009-04-05 5311]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;c:\windows\system32\DRIVERS\SkyNET.SYS [2006-03-14 349184]
S2 ccPxySvc;Symantec Proxy Service;c:\program files\Norton Internet Security\ccPxySvc.exe [2002-09-21 34496]
S2 MA1908Driver;MA1908Driver;c:\windows\system32\drivers\ma1908.sys [1998-07-09 22528]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [2001-11-26 165760]


--- Other Services/Drivers In Memory ---

*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - ASCTRM
*Deregistered* - Aspi32
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - ccEvtMgr
*Deregistered* - ccPwdSvc
*Deregistered* - ccPxySvc
*Deregistered* - Cdfs
*Deregistered* - Cinemsup
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - EIO
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - gusvc
*Deregistered* - Hardlock
*Deregistered* - Haspnt
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - irda
*Deregistered* - IRENUM
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MA1908Driver
*Deregistered* - MDM
*Deregistered* - mdmxsdk
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - navapsvc
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - NISUM
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasirda
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - SAVRT
*Deregistered* - SAVRTPEL
*Deregistered* - SBService
*Deregistered* - Schedule
*Deregistered* - Secdrv
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssmdrv
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMIDSCO
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - SymWSC
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-04-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-08 22:42]

2009-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-842925246-725345543-1003.job
- c:\documents and settings\Konstantin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-17 14:00]

2009-04-10 c:\windows\Tasks\Norton AntiVirus - Scan my computer.job
- c:\progra~1\NORTON~1\NAVW32.EXE [2002-09-20 17:31]

2009-04-05 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2009-04-05 07:04]
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{5ECD31F0-F91A-11d4-B3CA-00D0B70A09D2} - WDShell
Notify-WgaLogon - (no file)


.
- i jos jedan nastavak
 
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-22 02:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\system32\49b84b87f0833ebb9b8b54949b24c19c.sys 39936 bytes executable
c:\windows\system32\_49b84b87f0833ebb9b8b54949b24c19c.sys_.vir 39936 bytes executable

scan completed successfully
hidden files: 2

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\49b84b87f0833ebb9b8b54949b24c19c]
"ImagePath"="system32\49b84b87f0833ebb9b8b54949b24c19c.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\autorun]
"ImagePath"="\??\c:\huadio.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\B2C2, Inc.\d712c606]
@Class="REG_SZ"
@DACL=(02 0000)
"MulticastConflictAction"=dword:00000002
"NetworkChoice"="Eutelsat W3 7 E"
"LastSelectedSat"="Hotbird 13 E"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1060)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\ftpxext.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Norton Internet Security\NISUM.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Norton AntiVirus\NAVAPSVC.EXE
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Completion time: 2009-04-22 2:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-22 00:22

Pre-Run: 10.401.284.096 bytes free
Post-Run: 12.424.392.704 bytes free

364 --- E O F --- 2008-03-27 13:44


pozz i hvala
 
Pošalji.
A da li si možda primetio neka poboljšanja nakon skeniranja sa ComboFix-om?

ComboFix nije odradio posao.Posle njega mi je znatno usporen komp.
Skenirao sam sve sa Nortonom, pronasao tri problema od kojih je dva obrisao a treci izolirao. Da bi ostao po strani uradio sam safemod i sada ga ne vidim da je aktivan.
Brzina kompa se vratila.
 
@Pestafest

1.nisi se javio do sad da ti kazemo proceduru za uninstal ComboFix.
Po logu, tvoj problem sa virusom je rijesen..

2. Imas mnoooogo pokrenutih procesa zajedno sa WIndowsom, to je najveci razlog usporenog racunara, da ovaj pu ne pominjem i sam Norton AV.

3. Trebalo bi da sklonimo sve viska startup procese, da uninstaliras CF pa ce nam kazes kako stanje stoji..

Postupak za uninstall ComboFix-a

Start
Run

Kucas

ComboFix /u (Obrati paznju na razmak izmedju x /)

nakon toga OK

kad bude gotovo, dobices obavijestenje o tome da je ComboFix uninstaliran

Sledeci korak je da nam nekako napises listu
Startup procesa:

Ne znam kako se snalazis sa slikanjem desktopa, ali to bi bilo najbolje da nam pokazes u slici i rijeci:

Da bi to vidio:
ides na
Start
Run
kucas
msconfig
pa OK
zatim
nadji karticu Startup

Tu imas spisak svih startno pokrenutih programa

AJ, pa cimaj sta se desava.
 
Malwarebytes kaze ovo

Malwarebytes' Anti-Malware 1.36
Database version: 2047
Windows 5.1.2600 Service Pack 2

4/30/2009 5:08:10 PM
mbam-log-2009-04-30 (17-08-03).txt

Scan type: Full Scan (C:\|)
Objects scanned: 104141
Time elapsed: 24 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\COMODO\COMODO Internet Security\Quarantine\lsass.exe (Worm.Autoit) -> No action taken.
C:\Win\names.txt (Worm.Autoit) -> No action taken.


A hijackthis kaze ovo

Logfile of HijackThis v1.99.1
Scan saved at 5:11:10 PM, on 4/30/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\vecna\vecna.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\cssdll32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

Treba li da brinem? Treba li da idem na opciju za brisanje ova dva fajla u Malwarebytesu?
 
Nema na čemu.
smiley_emoticons_wink_gruen.gif
 
Imam problem i sumnjam da je virus u pitanju! Ne mogu da pokrenem ni registy editor,task menager niti da u group polisy ista u vezi administrativnih podesavanja promenim! Takodje nema sanse da pokrenem antivirus niti da bilo koju instalaciju antivirusa !U pocetku sam mogao da pokrenem AVG 2007 i skinuo sam updates sa neta ali se error pojavio i program nije mogao da ih instalira! Isao sam u event tracker i naisao sam na ogroman broj upozorenja i ozbiljnih greski gde mi racunar kaze da su neki sektori na hard disku osteceni,ali masina i dalje radi! Ponekad mi se desi da internet explorer odjednom zabaguje i da mi komp zakuca,kada pokusam da udjem u task m. pojavi mi se error da je iskljucen na zahtev administratora a ja to nisam uradio! Pomozite jer mi je vec na slican nacin skoro riknuo hdd!

e da imam combofix i on do sada nije prijavljivao nikakve greske!
 
Poslednja izmena od moderatora:
... nego mozes li mi preporuciti neki dobar antivirus ali da je za dzabe?...
Pazi ovako, svaki AV program (znači i oni koji su komercijalni), možeš koristiti kao da su potpuno free. Tu naravno ne mislim na upotrebu piratskih ključeva, serijskih brojeva, passworda, patcheva itd., već na jedan potpuno legalan način. Naime, skoro sve AV kompanije nude mogućnost korišćenja njihovih komercijalnih AV programa izvestan broj probnih dana sasvim besplatno (15-30-60...) i za to vreme program je potpuno funkcionalan (mislim na sve njegove module) kao da ste ga i platili. Nakon isteka tog probnog perioda, jednostavno deinstalirate program (najbolje uz korišćenje originalnog uninstall tool-a, čisto da budete sigurni da će ga u potpunosti ukloniti, a to je vrlo bitno), onda ponovite instalaciju i dobićete novi probni period za korišćenje (kao i prethodni put). Na ovaj način dakle, možete potpuno legalno koristiti i one programe koje do tada niste mogli, upravo zbog toga što nisu besplatni. I da, naravno, ja sam uvek za Kaspera. ;)
 

Back
Top