pomoc u vezi trojana

2

pomoc u vezi trojana

offline
  • Pridružio: 16 Okt 2007
  • Poruke: 18
  • Gde živiš: Novi Sad

hvala vam mnogo na strpljenju...problem je i dalje isti,atacan naziv fajla:C:DOCUME~1\MILICA~1\LOCA...\sch 16.dll

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

OK... Postavi logove...

offline
  • Pridružio: 16 Okt 2007
  • Poruke: 18
  • Gde živiš: Novi Sad

uradila sam ono sto je trebalo prvo,ali ne mogu da obrisem fajl commaddi.dll,a pise:cannot delete comaddi:acces is denied Make sure the disk is not full or write-protected and that file is not currently in use

Dopuna: 17 Okt 2007 8:02

jel da nastavim po uputstvu redom?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Nije bitno. Rešićemo to na drugi način.
Odradi ostalo...

Dopuna: 17 Okt 2007 8:09

Još nešto... Pokušala si ući u My Documents pre pokretanja programa Flash_Disinfector?
Ako je tako, onda probaj opet ući u My Doc. kada sve završiš i napiši da li je problem i dalje prisutan.

offline
  • Pridružio: 16 Okt 2007
  • Poruke: 18
  • Gde živiš: Novi Sad

flash_disinfector.exe,kliknula da preuzmem ali nemam opcijuda sacuvam samo cancel

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Desni klik na link i izaberi opciju Save as ili Save target as pa ga sačuvaj na Desktop...

offline
  • Pridružio: 16 Okt 2007
  • Poruke: 18
  • Gde živiš: Novi Sad

uradila Nolop,nije trazio da se restartuje pise da su pronadjeni inficirani fajlovi,sad cu da posaljem log,klik na HIJACK-opet izbaci onog trojana

Dopuna: 17 Okt 2007 8:46

Logfile of HijackThis v1.99.1
Scan saved at 8:43:21 AM, on 10/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Terminator\Quick TV\Scheduled.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Terminator\TV7131 Utilities\P3XRCtl.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\milica i dule\Desktop\TR3.exe\TR3.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35AA28DE-EE02-42AE-BFD6-BBC25238462A} - C:\WINDOWS\system32\comaddi.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Quick TV Agent] C:\Program Files\Terminator\Quick TV\Scheduled.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TIxDSL] C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [Mp4 Player] "C:\Program Files\Mp4 Player\Mp4Player.exe" hmw
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: TV Remote Control.lnk = C:\Program Files\Terminator\TV7131 Utilities\P3XRCtl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8E3358B-5796-492D-BDBD-D0BCDBBF337B}: NameServer = 80.74.164.249 80.74.160.38
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)

Dopuna: 17 Okt 2007 8:49

hm....neznam da postujem C:Nolop

Dopuna: 17 Okt 2007 8:54

NoLop! Log by Skate_Punk_21

Fix running from: C:\Documents and Settings\milica i dule\Desktop
[10/17/2007]
[8:37:43 AM]

---Infection Files Found/Removed---
NO INFECTION FILES FOUND - Cleaning Aborted.

---Listing AppData sub directories---

C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Azureus
C:\Documents and Settings\All Users\Application Data\Google
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Playfirst
C:\Documents and Settings\All Users\Application Data\Sandlot Games
C:\Documents and Settings\All Users\Application Data\Screenseven
C:\Documents and Settings\All Users\Application Data\That Face Camp Shim -- EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Trymedia
C:\Documents and Settings\All Users\Application Data\Yahoo!
C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
C:\Documents and Settings\All Users\Application Data\Zylom
C:\Documents and Settings\Default User\Application Data\Microsoft
C:\Documents and Settings\Localservice\Application Data\Microsoft
C:\Documents and Settings\Milica I Dule\Application Data\Adobe
C:\Documents and Settings\Milica I Dule\Application Data\Alawar
C:\Documents and Settings\Milica I Dule\Application Data\Ati
C:\Documents and Settings\Milica I Dule\Application Data\Azureus
C:\Documents and Settings\Milica I Dule\Application Data\Funwebproducts
C:\Documents and Settings\Milica I Dule\Application Data\Google
C:\Documents and Settings\Milica I Dule\Application Data\Identities
C:\Documents and Settings\Milica I Dule\Application Data\Intervideo
C:\Documents and Settings\Milica I Dule\Application Data\Limewire
C:\Documents and Settings\Milica I Dule\Application Data\Macromedia
C:\Documents and Settings\Milica I Dule\Application Data\Microsoft
C:\Documents and Settings\Milica I Dule\Application Data\More Book Meta
C:\Documents and Settings\Milica I Dule\Application Data\Mozilla
C:\Documents and Settings\Milica I Dule\Application Data\Playfirst
C:\Documents and Settings\Milica I Dule\Application Data\Real
C:\Documents and Settings\Milica I Dule\Application Data\Sandlot Games
C:\Documents and Settings\Milica I Dule\Application Data\Sun
C:\Documents and Settings\Milica I Dule\Application Data\Winrar -- EMPTY Directory
C:\Documents and Settings\Milica I Dule\Application Data\Yahoo!
C:\Documents and Settings\Networkservice\Application Data\Microsoft

Dopuna: 17 Okt 2007 8:55

izvinjavam se gora sam od male bebe,snasla sam se ,polako ucim....

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Kada pokreneš HijackThis, KAV nešto detektuje?
Potvrdi mi ovo, molim te.

Još ComboFix log...

offline
  • Pridružio: 16 Okt 2007
  • Poruke: 18
  • Gde živiš: Novi Sad

da isto ono kao pre

Dopuna: 17 Okt 2007 9:17

ComboFix 07-10-17.8 - milica i dule 2007-10-17 8:57:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.106 [GMT 2:00]
Running from: C:\Documents and Settings\milica i dule\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\milica i dule\Application Data\FunWebProducts
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\00CB674A.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\00D0C947.urr
C:\Program Files\FunWebProducts\ScreenSaver\Images\00D6C3BC.dat
C:\Program Files\FunWebProducts\ScreenSaver\Images\wrkparam.lst
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\WINDOWS\system32\comaddi.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_NPF
-------\NPF


((((((((((((((((((((((((( Files Created from 2007-09-17 to 2007-10-17 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-17 07:10 5,514,016 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-17 07:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-17 07:08 90,912 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2007-10-17 07:08 9,572 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-17 07:08 74,612 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-17 06:37 106 ----a-w C:\delete.bat
2007-10-16 22:40 --------- d-----w C:\Documents and Settings\milica i dule\Application Data\Azureus
2007-10-12 18:29 --------- d-----w C:\Program Files\Mystery Case Files - Prime Suspects
2007-10-12 15:24 --------- d-----w C:\Program Files\eMule
2007-10-11 12:45 --------- d-----w C:\Program Files\BFG
2007-10-11 11:59 --------- d-----w C:\Program Files\Italian Championships
2007-10-06 20:43 --------- d-----w C:\Program Files\SaveNow
2007-10-05 07:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\That Face Camp Shim
2007-10-04 19:39 --------- d-----w C:\Program Files\Azureus
2007-09-26 11:10 82,061 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2007-09-26 11:10 81,549 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2007-09-26 10:59 --------- d-----w C:\Program Files\Kaspersky Lab
2007-09-25 10:24 --------- d-----w C:\Documents and Settings\milica i dule\Application Data\Yahoo!
2007-09-24 07:02 --------- d-----w C:\Program Files\Codec Pack - All In 1
2007-09-23 19:55 --------- d-----w C:\Documents and Settings\milica i dule\Application Data\LimeWire
2007-09-23 08:13 --------- d-----w C:\Program Files\Common Files\xing shared
2007-09-23 08:12 --------- d-----w C:\Program Files\Real
2007-09-23 08:12 --------- d-----w C:\Program Files\Common Files\Real
2007-09-23 08:11 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-09-23 08:11 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2007-09-20 12:02 --------- d-----w C:\Program Files\LimeWire
2007-09-19 09:55 --------- d-----w C:\Documents and Settings\milica i dule\Application Data\PlayFirst
2007-09-19 09:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-09-19 07:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
2007-09-18 11:45 --------- d-----w C:\Documents and Settings\milica i dule\Application Data\MORE BOOK META
2007-09-17 16:34 8,464 ----a-w C:\WINDOWS\system32\sporder.dll
2007-09-17 16:34 --------- d-----w C:\Program Files\RadLight
2007-09-14 13:54 --------- d-----w C:\Documents and Settings\milica i dule\Application Data\Sandlot Games
2007-09-14 13:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2007-09-14 11:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2007-09-13 19:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-13 19:14 --------- d-----w C:\Program Files\TI ADSL
2007-09-13 19:09 --------- d-----w C:\Program Files\ActionTec
2007-08-26 16:00 --------- d-----w C:\Program Files\Don't Get Angry 2
2007-08-22 14:12 --------- d-----w C:\Program Files\Common Files\NSV
2007-08-21 19:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-08-21 18:48 --------- d-----w C:\Program Files\Torrent Harvester
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-20 19:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-08-20 19:27 --------- d-----w C:\Program Files\Yahoo!
2007-08-20 18:58 --------- d-----w C:\Program Files\Google
2007-08-20 18:28 --------- d-----w C:\Program Files\Java
2007-08-20 18:25 --------- d-----w C:\Program Files\Common Files\Java
2007-08-20 18:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2007-08-20 18:01 --------- d-----w C:\Program Files\Common Files\InterVideo
2007-08-20 17:46 --------- d-----w C:\Program Files\InterVideo
2007-08-20 16:21 --------- d-----w C:\Program Files\GustoSoft
2007-08-20 15:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2007-08-06 09:47 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
1998-08-24 10:09 10,000 ----a-w C:\WINDOWS\inf\unregpn.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 09:12]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 11:21 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 C:\WINDOWS\SkyTel.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"Quick TV Agent"="C:\Program Files\Terminator\Quick TV\Scheduled.exe" [2004-10-11 10:46]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"TIxDSL"="C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe" [2002-08-27 12:37]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-23 10:11]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mp4 Player"="C:\Program Files\Mp4 Player\Mp4Player.exe" []
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-17 12:46]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-08-20 20:01:42]
TV Remote Control.lnk - C:\Program Files\Terminator\TV7131 Utilities\P3XRCtl.exe [2007-07-01 19:45:15]

R3 AtmElan;ATM Emulated LAN;C:\WINDOWS\system32\DRIVERS\atmlane.sys
R3 Cap713x;Philips Cap713x Video Capture;C:\WINDOWS\system32\DRIVERS\Cap713x.sys
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys
R3 TIAU5CO;Actiontec Home DSL Modem(WAN) Service;C:\WINDOWS\system32\DRIVERS\TIAU5CO.sys
S3 AtmLane;ATM LAN Emulation;C:\WINDOWS\system32\DRIVERS\atmlane.sys
S3 TIAu5Bt;Actiontec Home DSL Modem Boot Device Service;C:\WINDOWS\system32\Drivers\tiau5bt.sys

.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2007-10-17 09:09:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-17 9:12:01 - machine was rebooted
.
--- E O F ---

Dopuna: 17 Okt 2007 9:18

a ovo zadnje kad sam radila ComboFix,kasperski je stalno izbacivao neki alert ali sam stiskala da dopusti da se nastavi

Dopuna: 17 Okt 2007 9:19

valda nisam napravila neko zlo?

Dopuna: 17 Okt 2007 9:20

e i zaboravila sam da kazem restartovao se sam

Dopuna: 17 Okt 2007 9:23

sad sam kliknula my documents i niiiiiiijjjjjjjjeeeeeee se javio!!!!!

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Ukljucivanje prikaza skrivenih fajlova i foldera:
Otvorite My Computer.
Odaberite Tools meni i kliknite Folder Options.
Odaberite View Tab.
U grupi Hidden files and folders stiklirajte Show hidden files and folders.
Destiklirajte Hide protected operating system files (recommended).
Kliknite Yes da bi ste potvrdili izbor.
Kliknite OK.



-------------------------------------------------------------------------------------


Obriši sledeće foldere:
C:\Documents and Settings\All Users\Application Data\That Face Camp Shim
C:\Program Files\SaveNow


-------------------------------------------------------------------------------------

Restartuj kompjuter i napravi novi HijackThis log.
Napiši mi i kakvo je sada stanje (nakon restartovanja).

Ko je trenutno na forumu
 

Ukupno su 341 korisnika na forumu :: 4 registrovanih, 2 sakrivenih i 335 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3028 - dana 22 Nov 2019 07:47

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Arhiv, nenad812, Oluj2.1, TRANSPORTER2