Drugaricin racunar

Drugaricin racunar

offline
  • Tomica
  • Komitet za bezbednost saobraćaja
  • Pridružio: 22 Jun 2006
  • Poruke: 430
  • Gde živiš: Kragujevac

pozdrav drugari... Drugarica mi se nesto zalila da joj racunar u zadnje vreme se ponasa cudno, pa ako mozete hajde da pogledamo sta je...Hvala puno...

DDS (Ver_09-07-30.01) - NTFSx86
Run by Jelena at 1:50:40,88 on sre 16.09.2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.47 [GMT 2:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Windows\sqlexec64.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\Jelena\LOCALS~1\Temp\owurg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Jelena\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = [Link mogu videti samo ulogovani korisnici]
uURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
uURLSearchHooks: ScreensaversList.com Toolbar: {0b270564-bd36-49cf-9e92-eb349732f0aa} - c:\program files\screensaverslist.com\tbScr1.dll
mURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
BHO: ScreensaversList.com Toolbar: {0b270564-bd36-49cf-9e92-eb349732f0aa} - c:\program files\screensaverslist.com\tbScr1.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask.com Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Ask.com Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: ScreensaversList.com Toolbar: {0b270564-bd36-49cf-9e92-eb349732f0aa} - c:\program files\screensaverslist.com\tbScr1.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [WinFast Schedule] c:\program files\winfast\wfdtv\WFWIZ.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [cdoosoft] c:\docume~1\jelena\locals~1\temp\herss.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [JMB36X IDE Setup] c:\windows\jm\JMInsIDE.exe
mRun: [JMB36X Configure] c:\windows\system32\JMRaidSetup.exe boot
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [WinFast Schedule] c:\program files\winfast\wftvfm\WFWIZ.exe
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [WinFastDTV] c:\program files\winfast\wfdtv\DTVSchdl.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [MSN] c:\windows\sqlexec64.exe
mRun: [run32] c:\win\lsass.exe
StartupFolder: c:\docume~1\jelena\startm~1\programs\startup\nikonm~1.lnk - c:\program files\common files\nikon\monitor\NkMonitor.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Winamp Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
IE: Open in new background tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/229?0492f8bcceec4c138b372c174b0d793c
IE: Open in new foreground tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/230?0492f8bcceec4c138b372c174b0d793c
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - [Link mogu videti samo ulogovani korisnici]
SEH: hook dll rising: {bb4c402f-882a-4526-8c08-51278ea437c1} - c:\windows\system32\e8main0.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jelena\applic~1\mozilla\firefox\profiles\xwqxc4mr.default\
FF - prefs.js: browser.search.defaulturl - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\documents and settings\jelena\application data\mozilla\firefox\profiles\xwqxc4mr.default\extensions\{0b270564-bd36-49cf-9e92-eb349732f0aa}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\jelena\application data\mozilla\firefox\profiles\xwqxc4mr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

FF - user.js: browser.sessionstore.resume_from_crash - false

============= SERVICES / DRIVERS ===============

R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\onghpn.sys --> c:\windows\system32\drivers\onghpn.sys [?]
R3 WFIOCTL;WFIOCTL;c:\program files\winfast\wftvfm\WFIOCTL.sys [2009-6-27 9446]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-9-15 54752]
S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys --> c:\windows\system32\drivers\cdaudio.sys [?]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]

=============== Created Last 30 ================

2009-09-16 01:48 <DIR> --d-h--- c:\windows\PIF
2009-09-16 00:14 <DIR> --d----- c:\documents and settings\jelena\Tracing
2009-09-15 23:35 54,752 a------- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-09-15 23:32 3,426,072 a------- c:\windows\system32\d3dx9_32.dll
2009-09-15 23:32 <DIR> --d----- c:\program files\Microsoft SQL Server Compact Edition
2009-09-15 23:30 <DIR> --d----- c:\program files\Microsoft
2009-09-15 23:30 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-09-15 23:19 <DIR> --d----- c:\program files\common files\Windows Live
2009-09-14 23:15 <DIR> --dshr-- C:\Win
2009-09-14 23:15 57,394 ---shr-- c:\windows\sqlexec64.exe
2009-09-13 23:35 218,137 a------- C:\mjafm.exe
2009-09-13 15:56 218,142 a------- C:\ph.exe
2009-09-09 15:05 118 a------- c:\windows\system32\MRT.INI
2009-09-08 19:00 116,142 ---shr-- C:\10nb.exe
2009-09-07 18:14 217,978 a------- C:\3c.exe
2009-09-07 14:02 217,719 a------- C:\m.exe
2009-09-06 01:50 114,662 ---shr-- C:\y.bat
2009-09-04 17:37 526,753 a------- C:\cj3k.exe
2009-09-04 02:40 <DIR> --d----- c:\program files\Winamp Toolbar
2009-09-03 19:37 215,099 a------- C:\o9bxu.exe
2009-09-02 20:06 112,747 ---shr-- C:\ewqij.bat
2009-09-01 23:34 215,855 a------- C:\i0yva6.exe
2009-09-01 10:34 214,842 a------- C:\mt2.exe
2009-08-30 20:12 215,079 a------- C:\pkkwng.exe
2009-08-21 12:17 209,020 a------- C:\kgji.exe
2009-08-20 19:01 <DIR> --d----- c:\docume~1\jelena\applic~1\GetRightToGo
2009-08-17 02:38 208,391 a------- C:\lcw.exe

==================== Find3M ====================

2009-09-01 10:56 20 ----h--- c:\docume~1\alluse~1\applic~1\PKP_DLdu.DAT
2009-08-17 02:38 208,449 a------- C:\y8.exe
2009-08-14 00:51 209,020 a------- C:\9u.exe
2009-08-12 11:45 209,149 a------- C:\wbj.exe
2009-08-08 22:34 106,496 a------- c:\windows\system32\ATL71.DLL
2009-08-08 20:09 210,091 a------- C:\ktly.exe
2009-08-05 11:11 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-05 02:02 208,510 a------- C:\22yj2fy1.exe
2009-08-03 01:29 210,241 a------- C:\ukfbi3aw.exe
2009-08-02 14:49 106,995 ---shr-- C:\mqhnawe.bat
2009-08-01 11:03 210,394 a------- C:\6rxt26.exe
2009-07-31 18:55 410,984 a------- c:\windows\system32\deploytk.dll
2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll
2009-07-17 20:55 58,880 a------- c:\windows\system32\SET168.tmp
2009-07-17 20:55 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-07-11 10:56 208,386 a------- C:\p.exe
2009-07-10 12:15 306,544 a------- c:\windows\WLXPGSS.SCR
2009-07-10 10:36 209,617 a------- C:\q1alx.exe
2009-07-08 19:51 4,096 a------- c:\windows\d3dx.dat
2009-07-07 13:58 210,530 a------- C:\aphqg.exe
2009-07-05 03:07 211,872 a------- C:\9kretct.exe
2009-07-04 12:32 107,500 ---shr-- C:\3j2h0tf.bat
2009-07-03 10:16 107,546 ---shr-- C:\xmcckw.bat
2009-07-03 10:08 108,920 ---shr-- C:\ukvr.bat
2009-07-03 10:07 92,672 ---shr-- c:\windows\system32\nmdfgds0.dll
2009-06-28 19:53 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-27 19:19 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-06-26 18:18 659,456 a------- c:\windows\system32\wininet.dll
2009-06-26 18:18 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-25 10:44 724,480 a------- c:\windows\system32\lsasrv.dll
2009-06-25 10:44 298,496 a------- c:\windows\system32\kerberos.dll
2009-06-25 10:44 168,448 a------- c:\windows\system32\schannel.dll
2009-06-25 10:44 133,632 a------- c:\windows\system32\msv1_0.dll
2009-06-25 10:44 59,392 a------- c:\windows\system32\wdigest.dll
2009-06-25 10:44 56,320 a------- c:\windows\system32\secur32.dll
2009-06-22 13:49 117,248 a------- c:\windows\system32\SET10C.tmp
2009-06-22 13:49 117,248 a------- c:\windows\system32\mqtgsvc.exe
2009-06-22 13:49 19,968 a------- c:\windows\system32\SET116.tmp
2009-06-22 13:49 19,968 a------- c:\windows\system32\mqbkup.exe
2009-06-22 13:49 4,608 a------- c:\windows\system32\SET10D.tmp
2009-06-22 13:49 4,608 a------- c:\windows\system32\mqsvc.exe
2006-06-23 08:48 32,768 a----r-- c:\windows\inf\UpdateUSB.exe
2008-11-10 19:07 57,394 ---shr-- c:\windows\sqlexec64.exe
2009-05-19 21:24 105,436 ---shr-- c:\windows\system32\olhrwef.exe

============= FINISH: 1:50:45,92 ===============



[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]



rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pozdrav, kazi drugarici da instalira antivirus.

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.



offline
  • Tomica
  • Komitet za bezbednost saobraćaja
  • Pridružio: 22 Jun 2006
  • Poruke: 430
  • Gde živiš: Kragujevac

ComboFix 09-09-16.01 - Jelena 16.09.2009 23:10.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.393 [GMT 2:00]
Running from: c:\documents and settings\Jelena\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\10nb.exe
C:\22yj2fy1.exe
C:\3c.exe
C:\3j2h0tf.bat
C:\6rxt26.exe
C:\9kretct.exe
C:\9u.exe
C:\aphqg.exe
C:\autorun.inf
C:\cj3k.exe
c:\docume~1\Jelena\LOCALS~1\Temp\cvasds0.dll
c:\docume~1\Jelena\LOCALS~1\Temp\cvasds1.dll
c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{E9757890-7EC5-46C8-99AB-B00F07B6525C}\NewShortcut2_E97578907EC546C899ABB00F07B6525C.exe
C:\ewqij.bat
C:\I0yva6.exe
C:\kgji.exe
C:\ktly.exe
C:\lcw.exe
C:\M.exe
C:\mqhnawe.bat
C:\mt2.exe
C:\o9bxu.exe
C:\p.exe
C:\Pkkwng.exe
C:\q1alx.exe
C:\ukfbi3aw.exe
C:\ukvr.bat
C:\wbj.exe
c:\win\lsass.exe
c:\windows\AhnRpta.exe
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000111_.tmp.dll
c:\windows\system32\Dvbpws.dll
c:\windows\system32\e8main0.dll
c:\windows\system32\e8main1.dll
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\olhrwef.exe
C:\xmcckw.bat
C:\y.bat
C:\y8.exe
D:\0xuc.com
D:\22yj2fy1.exe
D:\2h60k.cmd
D:\300y.cmd
D:\30c0e.cmd
D:\3c.exe
D:\3j2h0tf.bat
D:\6rxt26.exe
D:\8.bat
D:\9kretct.exe
D:\9u.exe
D:\abqk2c3i.bat
D:\aphqg.exe
D:\autorun.inf
D:\boyedt.com
D:\cj3k.exe
D:\d.bat
D:\e.cmd
D:\e2.cmd
D:\ej10fkdo.bat
D:\ewqij.bat
D:\eyt.exe
D:\fbak.exe
D:\g1ljsm.com
D:\gyn.cmd
D:\hkn6k.bat
D:\husyu8n.exe
D:\i0yva6.exe
D:\iok.exe
D:\iw.bat
D:\jm3cx96.bat
D:\kgji.exe
D:\ktly.exe
D:\lc.exe
D:\lcw.exe
D:\luk1ylq.com
D:\m.exe
D:\mqhnawe.bat
D:\mt.bat
D:\mt2.exe
D:\npee.com
D:\nu.cmd
D:\o9bxu.exe
D:\p.exe
D:\pkkwng.exe
D:\q0dhfjf.exe
D:\q1alx.exe
D:\qwtb.com
D:\r8.bat
D:\rbj9jn1n.bat
D:\rwj0.cmd
D:\ukfbi3aw.exe
D:\ukvr.bat
D:\uvsqfgwd.cmd
D:\vwewav8.com
D:\w.com
D:\w98.com
D:\wbj.exe
D:\xcisvxl.com
D:\xmcckw.bat
D:\xsia.bat
D:\y.bat
D:\y8.exe
D:\yb12j.cmd
D:\yh.cmd
D:\ymxf2.exe
D:\ysep1.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_AVPsys


((((((((((((((((((((((((( Files Created from 2009-08-16 to 2009-09-16 )))))))))))))))))))))))))))))))
.

2009-09-15 21:30 . 2009-09-15 21:30 -------- d-----w- c:\program files\Microsoft
2009-09-15 21:30 . 2009-09-15 21:30 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-15 21:30 . 2009-09-15 21:35 -------- d-----w- c:\program files\Windows Live
2009-09-15 21:19 . 2009-09-15 21:19 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-14 21:15 . 2009-09-16 21:12 -------- d-----r- C:\Win
2009-09-14 21:15 . 2008-11-10 17:07 139314 --sh--r- c:\windows\sqlexec64.exe
2009-09-13 21:35 . 2009-09-13 21:35 218137 ----a-w- C:\mjafm.exe
2009-09-13 13:56 . 2009-09-13 13:55 218142 ----a-w- C:\ph.exe
2009-09-04 00:40 . 2009-09-04 00:40 -------- d-----w- c:\program files\Winamp Toolbar
2009-08-20 17:01 . 2009-08-20 17:09 -------- d-----w- c:\documents and settings\Jelena\Application Data\GetRightToGo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-16 11:05 . 2009-09-15 21:35 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-15 22:14 . 2009-06-27 17:29 12912 ----a-w- c:\documents and settings\Jelena\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-15 21:33 . 2009-07-04 20:03 -------- d-----w- c:\program files\Windows Live Toolbar
2009-09-15 21:33 . 2009-09-15 21:33 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-15 21:32 . 2009-09-15 21:32 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-11 15:15 . 2009-06-27 18:19 -------- d-----w- c:\documents and settings\Jelena\Application Data\Winamp
2009-09-04 00:41 . 2009-06-27 18:19 -------- d-----w- c:\program files\Winamp
2009-09-01 08:56 . 2009-08-08 20:34 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-08-14 10:21 . 2009-07-08 17:51 -------- d-----w- c:\documents and settings\Jelena\Application Data\Wildfire
2009-08-10 10:31 . 2009-08-10 10:31 -------- d-----w- c:\program files\MSXML 4.0
2009-08-08 20:54 . 2009-08-08 20:54 -------- d-----w- c:\documents and settings\Jelena\Application Data\Apple Computer
2009-08-08 20:38 . 2009-08-08 20:37 -------- d-----w- c:\documents and settings\Jelena\Application Data\Nikon
2009-08-08 20:38 . 2009-08-08 20:33 -------- d-----w- c:\program files\Common Files\Nikon
2009-08-08 20:35 . 2009-08-08 20:35 8854 ----a-r- c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{E9757890-7EC5-46C8-99AB-B00F07B6525C}\New_Shortcut_E97578907EC546C899ABB00F07B6525C_1.exe
2009-08-08 20:35 . 2009-08-08 20:35 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-08-08 20:35 . 2009-08-08 20:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Nikon
2009-08-08 20:35 . 2009-08-08 20:35 -------- d-----w- c:\program files\Nikon
2009-08-08 20:34 . 2009-08-08 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Ultima_T15
2009-08-08 20:34 . 2009-08-08 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\EnterNHelp
2009-08-08 20:34 . 2003-03-19 10:05 106496 ----a-w- c:\windows\system32\ATL71.DLL
2009-08-08 20:32 . 2009-08-08 20:32 -------- d-----w- c:\program files\QuickTime
2009-08-08 20:32 . 2009-08-08 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-08 20:32 . 2009-08-08 20:32 -------- d-----w- c:\program files\ArcSoft
2009-08-08 20:31 . 2009-06-27 17:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-08 17:51 . 2009-08-07 01:27 -------- d-----w- c:\program files\ScreensaversList.com
2009-08-07 01:27 . 2009-08-07 01:27 -------- d-----w- c:\program files\Conduit
2009-08-07 01:27 . 2009-08-07 01:27 -------- d-----w- c:\program files\BoxScreenSaver.com
2009-08-05 20:48 . 2009-09-15 21:35 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-08-05 09:11 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 16:55 . 2009-07-31 16:55 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-31 16:55 . 2009-07-31 16:55 -------- d-----w- c:\program files\Java
2009-07-31 16:55 . 2009-07-07 22:40 152576 ----a-w- c:\documents and settings\Jelena\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 18:55 . 2009-07-17 18:55 58880 ----a-w- c:\windows\system32\SET168.tmp
2009-07-17 18:55 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 17:35 . 2009-07-15 17:35 62760 ----a-w- c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
2009-07-13 00:18 . 2004-08-04 12:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 10:15 . 2009-07-10 10:15 306544 ----a-w- c:\windows\WLXPGSS.SCR
2009-07-08 17:51 . 2009-07-08 17:51 4096 ----a-w- c:\windows\d3dx.dat
2009-07-04 20:04 . 2009-07-04 20:04 23558 ----a-r- c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{8A62A068-3FD6-495A-9F66-26FE94F32EC9}\_294823.exe
2009-07-04 20:04 . 2009-07-04 20:04 22926 ----a-r- c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{8A62A068-3FD6-495A-9F66-26FE94F32EC9}\_18be6784.exe
2009-07-01 12:33 . 2009-08-07 01:27 114688 ----a-w- c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b270564-bd36-49cf-9e92-eb349732f0aa}\components\npmozax.dll
2009-07-01 12:33 . 2009-08-07 01:27 52224 ----a-w- c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b270564-bd36-49cf-9e92-eb349732f0aa}\components\FFExternalAlert.dll
2009-06-27 18:55 . 2009-06-27 18:55 0 ----a-w- c:\windows\nsreg.dat
2009-06-27 17:19 . 2009-06-27 17:19 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-26 16:18 . 2004-08-04 12:00 659456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 08:44 . 2004-08-04 12:00 724480 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:44 . 2004-08-04 12:00 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:44 . 2004-08-04 12:00 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:44 . 2004-08-04 12:00 298496 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:44 . 2004-08-04 12:00 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:44 . 2004-08-04 12:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:49 . 2009-06-22 11:49 19968 ----a-w- c:\windows\system32\SET116.tmp
2009-06-22 11:49 . 2009-06-22 11:49 117248 ----a-w- c:\windows\system32\SET10C.tmp
2009-06-22 11:49 . 2004-08-04 12:00 19968 ----a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-04 12:00 117248 ----a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2009-06-22 11:49 4608 ----a-w- c:\windows\system32\SET10D.tmp
2009-06-22 11:49 . 2004-08-04 12:00 4608 ----a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2009-06-22 11:48 91776 ----a-w- c:\windows\system32\drivers\SET118.tmp
2009-06-22 11:48 . 2004-08-04 12:00 91776 ----a-w- c:\windows\system32\drivers\mqac.sys
2009-06-22 11:34 . 2004-08-04 12:00 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2008-11-10 17:07 . 2009-09-14 21:15 139314 --sh--r- c:\windows\sqlexec64.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
"{0b270564-bd36-49cf-9e92-eb349732f0aa}"= "c:\program files\ScreensaversList.com\tbScr1.dll" [2009-08-08 2215960]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CLASSES_ROOT\clsid\{0b270564-bd36-49cf-9e92-eb349732f0aa}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0b270564-bd36-49cf-9e92-eb349732f0aa}]
2009-08-08 17:52 2215960 ----a-w- c:\program files\ScreensaversList.com\tbScr1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-04-02 17:50 809864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-04-02 809864]
"{0b270564-bd36-49cf-9e92-eb349732f0aa}"= "c:\program files\ScreensaversList.com\tbScr1.dll" [2009-08-08 2215960]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{0b270564-bd36-49cf-9e92-eb349732f0aa}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-04-02 809864]
"{0B270564-BD36-49CF-9E92-EB349732F0AA}"= "c:\program files\ScreensaversList.com\tbScr1.dll" [2009-08-08 2215960]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{0b270564-bd36-49cf-9e92-eb349732f0aa}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinFast Schedule"="c:\program files\WinFast\WFDTV\WFWIZ.exe" [2009-01-12 2908160]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3965776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 106496]
"JMB36X Configure"="c:\windows\system32\JMRaidSetup.exe" [2006-10-30 2031616]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-14 7323648]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-14 86016]
"WinFast Schedule"="c:\program files\WinFast\WFTVFM\WFWIZ.exe" [2006-10-24 446464]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 225280]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2009-01-16 90112]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 230808]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-12-14 1593344]

c:\documents and settings\Jelena\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-5-15 479232]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-28 187392]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"=
"c:\\WINDOWS\\JM\\JMInsIDE.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=
"c:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Ask.com\\UpdateTask.exe"=
"c:\\Program Files\\WinFast\\WFDTV\\WFWIZ.exe"=
"c:\\Program Files\\WinFast\\WFTVFM\\WFCPUUSE.EXE"=
"c:\\WINDOWS\\system32\\CF3311.exe"=
"c:\\WINDOWS\\system32\\JMRaidSetup.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jusched.exe"=

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [15.9.2009 23:35 54752]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\onghpn.sys --> c:\windows\system32\drivers\onghpn.sys [?]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFTVFM\WFIOCTL.sys [27.6.2009 19:55 9446]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [5.8.2009 22:48 786784]
.
Contents of the 'Scheduled Tasks' folder

2009-09-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-04-02 17:50]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?0492f8bcceec4c138b372c174b0d793c
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?0492f8bcceec4c138b372c174b0d793c
FF - ProfilePath - c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\
FF - prefs.js: browser.search.defaulturl - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b270564-bd36-49cf-9e92-eb349732f0aa}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- FIREFOX POLICIES ----

FF - user.js: browser.sessionstore.resume_from_crash - false
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-run32 - c:\win\lsass.exe
AddRemove-Adobe Photoshop 7.0 - c:\windows\ISUNINST.EXE -fc:\program files\Adobe\Photoshop 7.0\Uninst.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-09-16 23:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\docume~1\Jelena\LOCALS~1\Temp\RGI1.tmp 7075 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2488-)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\windows\ATKKBService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2009-09-16 23:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-16 21:15

Pre-Run: 51.935.772.672 bytes free
Post-Run: 52.508.594.176 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

355 --- E O F --- 2009-09-16 11:06

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Ovde je rec o Sality infekciji. Najoptimalnije resenje je format C.
Moram ti naglasiti da su inficirani svi exe i scr na svim particijama i da nikako ne pokusavas da pristupis D particiji.

Resenje posle formatiranja je sledece:

Preuzmi Dr.Web CureIt (~13 MB).
Restartuj kompjuter u Safe Mode (uputstvo za Safe Mode)

Dvoklikom pokreni launch.exe, nakon čega će se pojaviti uvodni prozor - klikni Start

Pojaviće se obaveštenje o započinjanju uvodnog skeniranja - klikni OK

Sačekaj nekoliko minuta da Dr.Web CureIt izvrši Express Scan; ukoliko malware bude pronađen, klikom na taster Yes to All u prozoru koji se pojavi dozvoli programu da izvrši dezinfekciju

Klikni Options > Change settings F9; u prozoru koji će se otvoriti, dečekiraj opciju Heuristic Analysis a zatim klikni OK

U glavnom prozoru obeleži opciju Complete scan a zatim klikni i Dr.Web CureIt će započeti skeniranje

Ukoliko malware bude pronađen, klikom na taster Yes to All u prozoru koji se pojavi dozvoli programu da izvrši dezinfekciju

Kada skeniranje bude završeno, klikni Select all taster (ukoliko je dostupan), a zatim klikni Cure i,
u meniju koji se otvori, klikni Move incurable:


Po završetku procesa, klikni File > Save report list i sačuvaj log na Desktopu


Iskopiraj sadržaj Dr.Web CureIt loga u temu na forumu.

offline
  • Tomica
  • Komitet za bezbednost saobraćaja
  • Pridružio: 22 Jun 2006
  • Poruke: 430
  • Gde živiš: Kragujevac

evo loga...

[Link mogu videti samo ulogovani korisnici]

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Koliko vidim nisi formatirao, Sality je jos uvek tu. Tako da ja ne mogu da ti dajem dodatna uputstva sem onoga sto sam vec napisao.

offline
  • Tomica
  • Komitet za bezbednost saobraćaja
  • Pridružio: 22 Jun 2006
  • Poruke: 430
  • Gde živiš: Kragujevac

ok.. sacu da ponovim drugarici da sve detaljno uradi ispocetka...

Ko je trenutno na forumu
 

Ukupno su 6959 korisnika na forumu :: 43 registrovanih, 4 sakrivenih i 6912 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 015, 10x10.9, A.R.Chafee.Jr., amonsrb, Apis Dr, aramis s, Asteker, Belac91, blatruc82, Bosnjo, cojapop, Darko Jovanovic, debeli, Dr Lobotom, dukajov, Džekson, ElGenius, Gheljda, goran.vvv, Gosha101980, Jakonjveliki, Jan, jodzula, jon istvan, kinderpingvin, komsija1, lelemud, ljuba.b, maCvele, mat, mikrimaus, MIKULENCE, nekdo, nnovakis, PlayerOne, raptorsi, raso76, renvoi, sosko, Stod, Szigetwar, Vanderx, VBoss