Drugaricin racunar

Drugaricin racunar

offline
  • Tomica
  • Komitet za bezbednost saobraćaja
  • Pridružio: 22 Jun 2006
  • Poruke: 430
  • Gde živiš: Kragujevac

pozdrav drugari... Drugarica mi se nesto zalila da joj racunar u zadnje vreme se ponasa cudno, pa ako mozete hajde da pogledamo sta je...Hvala puno...

DDS (Ver_09-07-30.01) - NTFSx86
Run by Jelena at 1:50:40,88 on sre 16.09.2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.47 [GMT 2:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Windows\sqlexec64.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\Jelena\LOCALS~1\Temp\owurg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Jelena\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = [Link mogu videti samo ulogovani korisnici]
uURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
uURLSearchHooks: ScreensaversList.com Toolbar: {0b270564-bd36-49cf-9e92-eb349732f0aa} - c:\program files\screensaverslist.com\tbScr1.dll
mURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
BHO: ScreensaversList.com Toolbar: {0b270564-bd36-49cf-9e92-eb349732f0aa} - c:\program files\screensaverslist.com\tbScr1.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask.com Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Ask.com Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: ScreensaversList.com Toolbar: {0b270564-bd36-49cf-9e92-eb349732f0aa} - c:\program files\screensaverslist.com\tbScr1.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [WinFast Schedule] c:\program files\winfast\wfdtv\WFWIZ.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [cdoosoft] c:\docume~1\jelena\locals~1\temp\herss.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [JMB36X IDE Setup] c:\windows\jm\JMInsIDE.exe
mRun: [JMB36X Configure] c:\windows\system32\JMRaidSetup.exe boot
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [WinFast Schedule] c:\program files\winfast\wftvfm\WFWIZ.exe
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [WinFastDTV] c:\program files\winfast\wfdtv\DTVSchdl.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [MSN] c:\windows\sqlexec64.exe
mRun: [run32] c:\win\lsass.exe
StartupFolder: c:\docume~1\jelena\startm~1\programs\startup\nikonm~1.lnk - c:\program files\common files\nikon\monitor\NkMonitor.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Winamp Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
IE: Open in new background tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/229?0492f8bcceec4c138b372c174b0d793c
IE: Open in new foreground tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/230?0492f8bcceec4c138b372c174b0d793c
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - [Link mogu videti samo ulogovani korisnici]
SEH: hook dll rising: {bb4c402f-882a-4526-8c08-51278ea437c1} - c:\windows\system32\e8main0.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jelena\applic~1\mozilla\firefox\profiles\xwqxc4mr.default\
FF - prefs.js: browser.search.defaulturl - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\documents and settings\jelena\application data\mozilla\firefox\profiles\xwqxc4mr.default\extensions\{0b270564-bd36-49cf-9e92-eb349732f0aa}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\jelena\application data\mozilla\firefox\profiles\xwqxc4mr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

FF - user.js: browser.sessionstore.resume_from_crash - false

============= SERVICES / DRIVERS ===============

R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\onghpn.sys --> c:\windows\system32\drivers\onghpn.sys [?]
R3 WFIOCTL;WFIOCTL;c:\program files\winfast\wftvfm\WFIOCTL.sys [2009-6-27 9446]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-9-15 54752]
S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys --> c:\windows\system32\drivers\cdaudio.sys [?]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]

=============== Created Last 30 ================

2009-09-16 01:48 <DIR> --d-h--- c:\windows\PIF
2009-09-16 00:14 <DIR> --d----- c:\documents and settings\jelena\Tracing
2009-09-15 23:35 54,752 a------- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-09-15 23:32 3,426,072 a------- c:\windows\system32\d3dx9_32.dll
2009-09-15 23:32 <DIR> --d----- c:\program files\Microsoft SQL Server Compact Edition
2009-09-15 23:30 <DIR> --d----- c:\program files\Microsoft
2009-09-15 23:30 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-09-15 23:19 <DIR> --d----- c:\program files\common files\Windows Live
2009-09-14 23:15 <DIR> --dshr-- C:\Win
2009-09-14 23:15 57,394 ---shr-- c:\windows\sqlexec64.exe
2009-09-13 23:35 218,137 a------- C:\mjafm.exe
2009-09-13 15:56 218,142 a------- C:\ph.exe
2009-09-09 15:05 118 a------- c:\windows\system32\MRT.INI
2009-09-08 19:00 116,142 ---shr-- C:\10nb.exe
2009-09-07 18:14 217,978 a------- C:\3c.exe
2009-09-07 14:02 217,719 a------- C:\m.exe
2009-09-06 01:50 114,662 ---shr-- C:\y.bat
2009-09-04 17:37 526,753 a------- C:\cj3k.exe
2009-09-04 02:40 <DIR> --d----- c:\program files\Winamp Toolbar
2009-09-03 19:37 215,099 a------- C:\o9bxu.exe
2009-09-02 20:06 112,747 ---shr-- C:\ewqij.bat
2009-09-01 23:34 215,855 a------- C:\i0yva6.exe
2009-09-01 10:34 214,842 a------- C:\mt2.exe
2009-08-30 20:12 215,079 a------- C:\pkkwng.exe
2009-08-21 12:17 209,020 a------- C:\kgji.exe
2009-08-20 19:01 <DIR> --d----- c:\docume~1\jelena\applic~1\GetRightToGo
2009-08-17 02:38 208,391 a------- C:\lcw.exe

==================== Find3M ====================

2009-09-01 10:56 20 ----h--- c:\docume~1\alluse~1\applic~1\PKP_DLdu.DAT
2009-08-17 02:38 208,449 a------- C:\y8.exe
2009-08-14 00:51 209,020 a------- C:\9u.exe
2009-08-12 11:45 209,149 a------- C:\wbj.exe
2009-08-08 22:34 106,496 a------- c:\windows\system32\ATL71.DLL
2009-08-08 20:09 210,091 a------- C:\ktly.exe
2009-08-05 11:11 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-05 02:02 208,510 a------- C:\22yj2fy1.exe
2009-08-03 01:29 210,241 a------- C:\ukfbi3aw.exe
2009-08-02 14:49 106,995 ---shr-- C:\mqhnawe.bat
2009-08-01 11:03 210,394 a------- C:\6rxt26.exe
2009-07-31 18:55 410,984 a------- c:\windows\system32\deploytk.dll
2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll
2009-07-17 20:55 58,880 a------- c:\windows\system32\SET168.tmp
2009-07-17 20:55 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-07-11 10:56 208,386 a------- C:\p.exe
2009-07-10 12:15 306,544 a------- c:\windows\WLXPGSS.SCR
2009-07-10 10:36 209,617 a------- C:\q1alx.exe
2009-07-08 19:51 4,096 a------- c:\windows\d3dx.dat
2009-07-07 13:58 210,530 a------- C:\aphqg.exe
2009-07-05 03:07 211,872 a------- C:\9kretct.exe
2009-07-04 12:32 107,500 ---shr-- C:\3j2h0tf.bat
2009-07-03 10:16 107,546 ---shr-- C:\xmcckw.bat
2009-07-03 10:08 108,920 ---shr-- C:\ukvr.bat
2009-07-03 10:07 92,672 ---shr-- c:\windows\system32\nmdfgds0.dll
2009-06-28 19:53 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-27 19:19 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-06-26 18:18 659,456 a------- c:\windows\system32\wininet.dll
2009-06-26 18:18 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-25 10:44 724,480 a------- c:\windows\system32\lsasrv.dll
2009-06-25 10:44 298,496 a------- c:\windows\system32\kerberos.dll
2009-06-25 10:44 168,448 a------- c:\windows\system32\schannel.dll
2009-06-25 10:44 133,632 a------- c:\windows\system32\msv1_0.dll
2009-06-25 10:44 59,392 a------- c:\windows\system32\wdigest.dll
2009-06-25 10:44 56,320 a------- c:\windows\system32\secur32.dll
2009-06-22 13:49 117,248 a------- c:\windows\system32\SET10C.tmp
2009-06-22 13:49 117,248 a------- c:\windows\system32\mqtgsvc.exe
2009-06-22 13:49 19,968 a------- c:\windows\system32\SET116.tmp
2009-06-22 13:49 19,968 a------- c:\windows\system32\mqbkup.exe
2009-06-22 13:49 4,608 a------- c:\windows\system32\SET10D.tmp
2009-06-22 13:49 4,608 a------- c:\windows\system32\mqsvc.exe
2006-06-23 08:48 32,768 a----r-- c:\windows\inf\UpdateUSB.exe
2008-11-10 19:07 57,394 ---shr-- c:\windows\sqlexec64.exe
2009-05-19 21:24 105,436 ---shr-- c:\windows\system32\olhrwef.exe

============= FINISH: 1:50:45,92 ===============



[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]



rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pozdrav, kazi drugarici da instalira antivirus.

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.



offline
  • Tomica
  • Komitet za bezbednost saobraćaja
  • Pridružio: 22 Jun 2006
  • Poruke: 430
  • Gde živiš: Kragujevac

ComboFix 09-09-16.01 - Jelena 16.09.2009 23:10.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.393 [GMT 2:00]
Running from: c:\documents and settings\Jelena\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\10nb.exe
C:\22yj2fy1.exe
C:\3c.exe
C:\3j2h0tf.bat
C:\6rxt26.exe
C:\9kretct.exe
C:\9u.exe
C:\aphqg.exe
C:\autorun.inf
C:\cj3k.exe
c:\docume~1\Jelena\LOCALS~1\Temp\cvasds0.dll
c:\docume~1\Jelena\LOCALS~1\Temp\cvasds1.dll
c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{E9757890-7EC5-46C8-99AB-B00F07B6525C}\NewShortcut2_E97578907EC546C899ABB00F07B6525C.exe
C:\ewqij.bat
C:\I0yva6.exe
C:\kgji.exe
C:\ktly.exe
C:\lcw.exe
C:\M.exe
C:\mqhnawe.bat
C:\mt2.exe
C:\o9bxu.exe
C:\p.exe
C:\Pkkwng.exe
C:\q1alx.exe
C:\ukfbi3aw.exe
C:\ukvr.bat
C:\wbj.exe
c:\win\lsass.exe
c:\windows\AhnRpta.exe
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000111_.tmp.dll
c:\windows\system32\Dvbpws.dll
c:\windows\system32\e8main0.dll
c:\windows\system32\e8main1.dll
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\olhrwef.exe
C:\xmcckw.bat
C:\y.bat
C:\y8.exe
D:\0xuc.com
D:\22yj2fy1.exe
D:\2h60k.cmd
D:\300y.cmd
D:\30c0e.cmd
D:\3c.exe
D:\3j2h0tf.bat
D:\6rxt26.exe
D:\8.bat
D:\9kretct.exe
D:\9u.exe
D:\abqk2c3i.bat
D:\aphqg.exe
D:\autorun.inf
D:\boyedt.com
D:\cj3k.exe
D:\d.bat
D:\e.cmd
D:\e2.cmd
D:\ej10fkdo.bat
D:\ewqij.bat
D:\eyt.exe
D:\fbak.exe
D:\g1ljsm.com
D:\gyn.cmd
D:\hkn6k.bat
D:\husyu8n.exe
D:\i0yva6.exe
D:\iok.exe
D:\iw.bat
D:\jm3cx96.bat
D:\kgji.exe
D:\ktly.exe
D:\lc.exe
D:\lcw.exe
D:\luk1ylq.com
D:\m.exe
D:\mqhnawe.bat
D:\mt.bat
D:\mt2.exe
D:\npee.com
D:\nu.cmd
D:\o9bxu.exe
D:\p.exe
D:\pkkwng.exe
D:\q0dhfjf.exe
D:\q1alx.exe
D:\qwtb.com
D:\r8.bat
D:\rbj9jn1n.bat
D:\rwj0.cmd
D:\ukfbi3aw.exe
D:\ukvr.bat
D:\uvsqfgwd.cmd
D:\vwewav8.com
D:\w.com
D:\w98.com
D:\wbj.exe
D:\xcisvxl.com
D:\xmcckw.bat
D:\xsia.bat
D:\y.bat
D:\y8.exe
D:\yb12j.cmd
D:\yh.cmd
D:\ymxf2.exe
D:\ysep1.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_AVPsys


((((((((((((((((((((((((( Files Created from 2009-08-16 to 2009-09-16 )))))))))))))))))))))))))))))))
.

2009-09-15 21:30 . 2009-09-15 21:30 -------- d-----w- c:\program files\Microsoft
2009-09-15 21:30 . 2009-09-15 21:30 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-15 21:30 . 2009-09-15 21:35 -------- d-----w- c:\program files\Windows Live
2009-09-15 21:19 . 2009-09-15 21:19 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-14 21:15 . 2009-09-16 21:12 -------- d-----r- C:\Win
2009-09-14 21:15 . 2008-11-10 17:07 139314 --sh--r- c:\windows\sqlexec64.exe
2009-09-13 21:35 . 2009-09-13 21:35 218137 ----a-w- C:\mjafm.exe
2009-09-13 13:56 . 2009-09-13 13:55 218142 ----a-w- C:\ph.exe
2009-09-04 00:40 . 2009-09-04 00:40 -------- d-----w- c:\program files\Winamp Toolbar
2009-08-20 17:01 . 2009-08-20 17:09 -------- d-----w- c:\documents and settings\Jelena\Application Data\GetRightToGo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-16 11:05 . 2009-09-15 21:35 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-15 22:14 . 2009-06-27 17:29 12912 ----a-w- c:\documents and settings\Jelena\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-15 21:33 . 2009-07-04 20:03 -------- d-----w- c:\program files\Windows Live Toolbar
2009-09-15 21:33 . 2009-09-15 21:33 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-15 21:32 . 2009-09-15 21:32 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-11 15:15 . 2009-06-27 18:19 -------- d-----w- c:\documents and settings\Jelena\Application Data\Winamp
2009-09-04 00:41 . 2009-06-27 18:19 -------- d-----w- c:\program files\Winamp
2009-09-01 08:56 . 2009-08-08 20:34 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-08-14 10:21 . 2009-07-08 17:51 -------- d-----w- c:\documents and settings\Jelena\Application Data\Wildfire
2009-08-10 10:31 . 2009-08-10 10:31 -------- d-----w- c:\program files\MSXML 4.0
2009-08-08 20:54 . 2009-08-08 20:54 -------- d-----w- c:\documents and settings\Jelena\Application Data\Apple Computer
2009-08-08 20:38 . 2009-08-08 20:37 -------- d-----w- c:\documents and settings\Jelena\Application Data\Nikon
2009-08-08 20:38 . 2009-08-08 20:33 -------- d-----w- c:\program files\Common Files\Nikon
2009-08-08 20:35 . 2009-08-08 20:35 8854 ----a-r- c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{E9757890-7EC5-46C8-99AB-B00F07B6525C}\New_Shortcut_E97578907EC546C899ABB00F07B6525C_1.exe
2009-08-08 20:35 . 2009-08-08 20:35 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-08-08 20:35 . 2009-08-08 20:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Nikon
2009-08-08 20:35 . 2009-08-08 20:35 -------- d-----w- c:\program files\Nikon
2009-08-08 20:34 . 2009-08-08 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Ultima_T15
2009-08-08 20:34 . 2009-08-08 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\EnterNHelp
2009-08-08 20:34 . 2003-03-19 10:05 106496 ----a-w- c:\windows\system32\ATL71.DLL
2009-08-08 20:32 . 2009-08-08 20:32 -------- d-----w- c:\program files\QuickTime
2009-08-08 20:32 . 2009-08-08 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-08 20:32 . 2009-08-08 20:32 -------- d-----w- c:\program files\ArcSoft
2009-08-08 20:31 . 2009-06-27 17:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-08 17:51 . 2009-08-07 01:27 -------- d-----w- c:\program files\ScreensaversList.com
2009-08-07 01:27 . 2009-08-07 01:27 -------- d-----w- c:\program files\Conduit
2009-08-07 01:27 . 2009-08-07 01:27 -------- d-----w- c:\program files\BoxScreenSaver.com
2009-08-05 20:48 . 2009-09-15 21:35 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-08-05 09:11 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 16:55 . 2009-07-31 16:55 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-31 16:55 . 2009-07-31 16:55 -------- d-----w- c:\program files\Java
2009-07-31 16:55 . 2009-07-07 22:40 152576 ----a-w- c:\documents and settings\Jelena\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 18:55 . 2009-07-17 18:55 58880 ----a-w- c:\windows\system32\SET168.tmp
2009-07-17 18:55 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 17:35 . 2009-07-15 17:35 62760 ----a-w- c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
2009-07-13 00:18 . 2004-08-04 12:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 10:15 . 2009-07-10 10:15 306544 ----a-w- c:\windows\WLXPGSS.SCR
2009-07-08 17:51 . 2009-07-08 17:51 4096 ----a-w- c:\windows\d3dx.dat
2009-07-04 20:04 . 2009-07-04 20:04 23558 ----a-r- c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{8A62A068-3FD6-495A-9F66-26FE94F32EC9}\_294823.exe
2009-07-04 20:04 . 2009-07-04 20:04 22926 ----a-r- c:\documents and settings\Jelena\Application Data\Microsoft\Installer\{8A62A068-3FD6-495A-9F66-26FE94F32EC9}\_18be6784.exe
2009-07-01 12:33 . 2009-08-07 01:27 114688 ----a-w- c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b270564-bd36-49cf-9e92-eb349732f0aa}\components\npmozax.dll
2009-07-01 12:33 . 2009-08-07 01:27 52224 ----a-w- c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b270564-bd36-49cf-9e92-eb349732f0aa}\components\FFExternalAlert.dll
2009-06-27 18:55 . 2009-06-27 18:55 0 ----a-w- c:\windows\nsreg.dat
2009-06-27 17:19 . 2009-06-27 17:19 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-26 16:18 . 2004-08-04 12:00 659456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 08:44 . 2004-08-04 12:00 724480 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:44 . 2004-08-04 12:00 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:44 . 2004-08-04 12:00 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:44 . 2004-08-04 12:00 298496 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:44 . 2004-08-04 12:00 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:44 . 2004-08-04 12:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:49 . 2009-06-22 11:49 19968 ----a-w- c:\windows\system32\SET116.tmp
2009-06-22 11:49 . 2009-06-22 11:49 117248 ----a-w- c:\windows\system32\SET10C.tmp
2009-06-22 11:49 . 2004-08-04 12:00 19968 ----a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-04 12:00 117248 ----a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2009-06-22 11:49 4608 ----a-w- c:\windows\system32\SET10D.tmp
2009-06-22 11:49 . 2004-08-04 12:00 4608 ----a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2009-06-22 11:48 91776 ----a-w- c:\windows\system32\drivers\SET118.tmp
2009-06-22 11:48 . 2004-08-04 12:00 91776 ----a-w- c:\windows\system32\drivers\mqac.sys
2009-06-22 11:34 . 2004-08-04 12:00 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2008-11-10 17:07 . 2009-09-14 21:15 139314 --sh--r- c:\windows\sqlexec64.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
"{0b270564-bd36-49cf-9e92-eb349732f0aa}"= "c:\program files\ScreensaversList.com\tbScr1.dll" [2009-08-08 2215960]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CLASSES_ROOT\clsid\{0b270564-bd36-49cf-9e92-eb349732f0aa}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0b270564-bd36-49cf-9e92-eb349732f0aa}]
2009-08-08 17:52 2215960 ----a-w- c:\program files\ScreensaversList.com\tbScr1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-04-02 17:50 809864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-04-02 809864]
"{0b270564-bd36-49cf-9e92-eb349732f0aa}"= "c:\program files\ScreensaversList.com\tbScr1.dll" [2009-08-08 2215960]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{0b270564-bd36-49cf-9e92-eb349732f0aa}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-04-02 809864]
"{0B270564-BD36-49CF-9E92-EB349732F0AA}"= "c:\program files\ScreensaversList.com\tbScr1.dll" [2009-08-08 2215960]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CLASSES_ROOT\clsid\{0b270564-bd36-49cf-9e92-eb349732f0aa}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinFast Schedule"="c:\program files\WinFast\WFDTV\WFWIZ.exe" [2009-01-12 2908160]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3965776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 106496]
"JMB36X Configure"="c:\windows\system32\JMRaidSetup.exe" [2006-10-30 2031616]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-14 7323648]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-14 86016]
"WinFast Schedule"="c:\program files\WinFast\WFTVFM\WFWIZ.exe" [2006-10-24 446464]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 225280]
"WinFastDTV"="c:\program files\WinFast\WFDTV\DTVSchdl.exe" [2009-01-16 90112]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 230808]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-12-14 1593344]

c:\documents and settings\Jelena\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-5-15 479232]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-28 187392]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"=
"c:\\WINDOWS\\JM\\JMInsIDE.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=
"c:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Ask.com\\UpdateTask.exe"=
"c:\\Program Files\\WinFast\\WFDTV\\WFWIZ.exe"=
"c:\\Program Files\\WinFast\\WFTVFM\\WFCPUUSE.EXE"=
"c:\\WINDOWS\\system32\\CF3311.exe"=
"c:\\WINDOWS\\system32\\JMRaidSetup.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jusched.exe"=

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [15.9.2009 23:35 54752]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\onghpn.sys --> c:\windows\system32\drivers\onghpn.sys [?]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFTVFM\WFIOCTL.sys [27.6.2009 19:55 9446]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [5.8.2009 22:48 786784]
.
Contents of the 'Scheduled Tasks' folder

2009-09-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-04-02 17:50]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?0492f8bcceec4c138b372c174b0d793c
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?0492f8bcceec4c138b372c174b0d793c
FF - ProfilePath - c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\
FF - prefs.js: browser.search.defaulturl - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b270564-bd36-49cf-9e92-eb349732f0aa}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Jelena\Application Data\Mozilla\Firefox\Profiles\xwqxc4mr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

---- FIREFOX POLICIES ----

FF - user.js: browser.sessionstore.resume_from_crash - false
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-run32 - c:\win\lsass.exe
AddRemove-Adobe Photoshop 7.0 - c:\windows\ISUNINST.EXE -fc:\program files\Adobe\Photoshop 7.0\Uninst.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-09-16 23:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\docume~1\Jelena\LOCALS~1\Temp\RGI1.tmp 7075 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2488-)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\windows\ATKKBService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2009-09-16 23:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-16 21:15

Pre-Run: 51.935.772.672 bytes free
Post-Run: 52.508.594.176 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

355 --- E O F --- 2009-09-16 11:06

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Ovde je rec o Sality infekciji. Najoptimalnije resenje je format C.
Moram ti naglasiti da su inficirani svi exe i scr na svim particijama i da nikako ne pokusavas da pristupis D particiji.

Resenje posle formatiranja je sledece:

Preuzmi Dr.Web CureIt (~13 MB).
Restartuj kompjuter u Safe Mode (uputstvo za Safe Mode)

Dvoklikom pokreni launch.exe, nakon čega će se pojaviti uvodni prozor - klikni Start

Pojaviće se obaveštenje o započinjanju uvodnog skeniranja - klikni OK

Sačekaj nekoliko minuta da Dr.Web CureIt izvrši Express Scan; ukoliko malware bude pronađen, klikom na taster Yes to All u prozoru koji se pojavi dozvoli programu da izvrši dezinfekciju

Klikni Options > Change settings F9; u prozoru koji će se otvoriti, dečekiraj opciju Heuristic Analysis a zatim klikni OK

U glavnom prozoru obeleži opciju Complete scan a zatim klikni i Dr.Web CureIt će započeti skeniranje

Ukoliko malware bude pronađen, klikom na taster Yes to All u prozoru koji se pojavi dozvoli programu da izvrši dezinfekciju

Kada skeniranje bude završeno, klikni Select all taster (ukoliko je dostupan), a zatim klikni Cure i,
u meniju koji se otvori, klikni Move incurable:


Po završetku procesa, klikni File > Save report list i sačuvaj log na Desktopu


Iskopiraj sadržaj Dr.Web CureIt loga u temu na forumu.

offline
  • Tomica
  • Komitet za bezbednost saobraćaja
  • Pridružio: 22 Jun 2006
  • Poruke: 430
  • Gde živiš: Kragujevac

evo loga...

[Link mogu videti samo ulogovani korisnici]

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Koliko vidim nisi formatirao, Sality je jos uvek tu. Tako da ja ne mogu da ti dajem dodatna uputstva sem onoga sto sam vec napisao.

offline
  • Tomica
  • Komitet za bezbednost saobraćaja
  • Pridružio: 22 Jun 2006
  • Poruke: 430
  • Gde živiš: Kragujevac

ok.. sacu da ponovim drugarici da sve detaljno uradi ispocetka...

Ko je trenutno na forumu
 

Ukupno su 822 korisnika na forumu :: 67 registrovanih, 5 sakrivenih i 750 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: advokat84, airsuba, ALEKSICMILE, aleksmajstor, Avalon015, Bbbggg1979, Bojke549, Boris90, Brankojle, carinko, Cirkon, Clouseau, cole77, crnogorac, d.arsenal321, dejan71, dj.ape, djboj, DragoslavS, dunavzed, goran.vvv, Hans Gajger, HawX, jalos, Jecmendo, Jeremiah, JimmyNapoli, Jonbonjovi, JOntra, K a s p e r, kenny74, klepesina, Lance Guest, louderik, m94j, Malahit, Marko Marković, markolopin, mean_machine, milanpb, Milometer, Milos ZA, MiroslavD, nenooo, nnovakis, opt1, Pero, Petjan, Piicoki, Pilence, pirke96, probisic, radza1, samp1389, sap, sarma, sekretar, Shinobi, stefan95, toni061, v82, Valter071, VanZan, vathra, VJ, voja64, yufighter