Poslao: 16 Feb 2007 11:32
|
offline
- Pridružio: 25 Okt 2006
- Poruke: 276
|
Tek procitah da se za 2. problem otvara 2. tema...
Evo me na poslu i na ovom racunaru imam slican problem kao sto sam gore naveo. E sad, maloprije se NOD32 update-ovao i nasao neke maliciozne fajlove...preskenirao sam komp sa SmitfraudFix-om kao sto si mi rekao i evo njegovog log fajla i log od HijackThis-a, pa mi reci kakvo je stanje i ima li nekih problema.
Hvala
PS(zamolicu te da pogledas i ovo:
http://img412.imageshack.us/img412/7369/untitledjt0.jpg
Svaki jutro, preskeniram komp sa XoftSpySE-om i svaki put mi nadje ovaj ixt0.dll fajl (Vundo troj/agent)..sta je u pitanju? Zasto ga ne obrise vec jednom...ja ga ne mogu naci u ovom folderu...)
Evo vidim da je i SmitfraudFix nasao i obrisao neki ixt?.dll fajl, mozda je to taj, pa mi se mozda vise nece pojavljivati u XoftSpySE-u...
SmitfaudFix log:
SmitFraudFix v2.142
Scan done at 10:50:57.85, Fri 02/16/2007
Run from C:\Documents and Settings\stanimir\Desktop\Smitfraud\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e6adaaf0-79b2-4cf1-a660-50a0b33991a1}"="didymiums"
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\ixt?.dll Deleted
C:\WINDOWS\system32\components\flx?.dll Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 10:58:43 AM, on 2/16/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\issrch.exe
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\TEMP\2CB.tmp
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wuauclt.exe
G:\opera902en\op.com
C:\Documents and Settings\stanimir\Desktop\Hijackthis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {f4d74aaa-a178-4463-846b-b4bc87a024e0} - C:\WINDOWS\System32\ixt0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Skype add-on - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet.....hcImpl.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\MDT6\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\MDT6\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\MDT6\InstFred.ocx
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4958/mcfscan.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\MDT6\AcPreview.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Backbone Service (BBDemon) - Unknown owner - C:\Program Files\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe" -service (file missing)
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Updater (mmupdate) - Unknown owner - C:\WINDOWS\TEMP\2CB.tmp".exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
|
|
|
|
Poslao: 16 Feb 2007 11:45
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Sledeci postupak podrazumeva jedan restart racunara, zato snimi sve radove koji su ti otvoreni u drugim programima i pogasi sve programe koji su ti trenutno otvoreni da ne bi doslo do gubitka podataka:
- skini VundoFix sa http://www.atribune.org/ccount/click.php?id=4
- startuj VundoFix
- selektuj opciju Run VundoFix as a task kada ti to bude ponudjeno
- VundoFix ce sada da se ugasi i startovace se ponovo za od prilike 1 minut
- kada se bude startovao, klikni dugme Scan for Vundo
- kada zavrsi skeniranje klikni na Remove Vundo
- potvrdi brisanje sa Yes
- ovog momenta ce desktop da se ugasi
- kada zavrsi dezinfekciju, pojavice se poruka da ce da ugasi kompjuter
- klikni OK
- ukljuci ponovo kompjuter
- otvori fajl C:\vundofix.txt i iskopiraj nam sadrzaj ovde
|
|
|
|
Poslao: 16 Feb 2007 11:58
|
offline
- Pridružio: 25 Okt 2006
- Poruke: 276
|
Skidam neki veliki fajl, pa cu malo kasniti...a u medjuvremenu sam pokrenuo i ewido i evo upravo skenira, pa cu ti poslati i njegov log.
|
|
|
|
Poslao: 16 Feb 2007 12:07
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Ukoliko je moguce da mi uploadujes sledece fajlove (strpaj sve u jedan ZIP):
C:\WINDOWS\System32\issrch.exe
C:\WINDOWS\TEMP\2CB.tmp
Takodje uploaduj i sledece ukoliko postoje:
C:\WINDOWS\System32\ipv6monl.dll
RSVP32_2.dll
Koristi sledecu formu za upload:
http://www.mycity.rs/ambulanta-upload.php
Nemoj koristiti ovaj standardni upload koji imas kod pisanja poruke.
|
|
|
|
Poslao: 16 Feb 2007 12:51
|
offline
- Pridružio: 25 Okt 2006
- Poruke: 276
|
OK. A evo i Ewido log:
ewido anti-spyware online scanner
http://www.ewido.net
__________________________________________________
Name: TrackingCookie.Adbrite
Path: C:\Documents and Settings\stanimir\Cookies\stanimir@adbrite[2].txt
Risk: Medium
Name: TrackingCookie.Burstnet
Path: C:\Documents and Settings\stanimir\Cookies\stanimir@burstnet[2].txt
Risk: Medium
Name: TrackingCookie.Cpvfeed
Path: C:\Documents and Settings\stanimir\Cookies\stanimir@cpvfeed[2].txt
Risk: Medium
Name: TrackingCookie.Burstnet
Path: C:\Documents and Settings\stanimir\Cookies\stanimir@www.burstnet[2].txt
Risk: Medium
Name: TrackingCookie.Yadro
Path: C:\Documents and Settings\stanimir\Cookies\stanimir@yadro[1].txt
Risk: Medium
Name: Adware.Generic
Path: HKLM\SOFTWARE\Classes\CLSID\{f4d74aaa-a178-4463-846b-b4bc87a024e0}
Risk: Medium
Name: Adware.Generic
Path: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f4d74aaa-a178-4463-846b-b4bc87a024e0}
Risk: Medium
Name: Backdoor.Small.oa
Path: [340] C:\WINDOWS\TEMP\2CB.tmp
Risk: High
Name: Downloader.Agent.bga
Path: C:\WINDOWS\system32\alldr.dll
Risk: High
Name: Backdoor.Small.oa
Path: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8967YP4N\mb3[1].exe
Risk: High
Name: Trojan.Agent.ncm
Path: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ATOHK52J\v30_crab_106[1].exe
Risk: High
Name: Downloader.Agent.bga
Path: C:\WINDOWS\system32\usrldr.dll
Risk: High
Name: Backdoor.Agent.fo
Path: C:\WINDOWS\system32\wofyjv32.dll
Risk: High
Name: Backdoor.Small.oa
Path: C:\WINDOWS\Temp\2CB.tmp
Risk: High
Dopuna: 16 Feb 2007 12:51
Uploadovao sam samo 2CB.tmp jer sam samo njega nasao. A vidjeces da je ime fajla __delete_on_reboot__2_C_B_._t_m_p_, vjerovatno ga je ewido spremio za brisanje ili sl...
|
|
|
|
Poslao: 16 Feb 2007 13:01
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Odradi i VundoFix, pa mi posle restarta postavi log VudnoFix-a i nov HJT log.
Naravno, kada budes mogao, znam da si rekao da je racunar zauzet.
Sto se tice onog "delete on reboot" najverovatnije je tvoja pretpostavka tacna da ce biti obrisan posle restarta racunara.
|
|
|
|
Poslao: 16 Feb 2007 14:05
|
offline
- Pridružio: 25 Okt 2006
- Poruke: 276
|
VundoFix V6.3.6
Checking Java version...
Sun Java not detected
Scan started at 1:00:32 PM 2/16/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.3.6
Checking Java version...
Sun Java not detected
Scan started at 1:36:31 PM 2/16/2007
Listing files found while scanning....
No infected files were found.
Beginning removal...
Dopuna: 16 Feb 2007 14:05
Logfile of HijackThis v1.99.1
Scan saved at 2:08:14 PM, on 2/16/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\issrch.exe
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\DU Meter\DUMeter.exe
G:\opera902en\op.com
C:\Documents and Settings\stanimir\Desktop\New Folder (2)\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {f4d74aaa-a178-4463-846b-b4bc87a024e0} - C:\WINDOWS\System32\ixt0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Skype add-on - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet.....hcImpl.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\MDT6\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\MDT6\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\MDT6\InstFred.ocx
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4958/mcfscan.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\MDT6\AcPreview.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Backbone Service (BBDemon) - Unknown owner - C:\Program Files\Dassault Systemes\B17\intel_a\code\bin\CATSysDemon.exe" -service (file missing)
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Updater (mmupdate) - Unknown owner - C:\WINDOWS\TEMP\2CB.tmp".exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
|
|
|
|
Poslao: 16 Feb 2007 14:33
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Proveri rucno da li je fajl C:\WINDOWS\System32\ixt0.dll jos uvek prisutan?
Ime moze da se razlikuje za nijansu, ali pocinje na ix
|
|
|
|
Poslao: 18 Feb 2007 19:39
|
offline
- Pridružio: 25 Okt 2006
- Poruke: 276
|
Pa i prije sam ga rucno trazio, nije ga bilo. Samo ixsso.dll....taj je i sada.
Ja mislim da je poslije svih ovih programcica, komp koliko toliko ociscen, a?
Sad se bacam na onaj prvi, upravo ga propustam kroz sake Ewida, pa cu mu pustiti Vunda, da mu i on koju progovori, pa ti saljem log fajlove zajedno sa HijackThis-ovim...
|
|
|
|
Poslao: 02 Mar 2007 16:01
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Mozes li da mi posaljes taj ixsso.dll da ga proverim?
Dokle god bude postojala sledeca linija, do tada jos nismo zavrsili posao:
O2 - BHO: (no name) - {f4d74aaa-a178-4463-846b-b4bc87a024e0} - C:\WINDOWS\System32\ixt0.dll
Probaj ponovo SmitFraudFix. Cudi me kako ga nije obrisao pri prvom pokusaju.
Dopuna 26.02.2007: Tema zakljucana zbog nejavljanja.
Dopuna: 02 Mar 2007 16:01
Otkljucano.
Ajmo ovako:
Pokreni ponovo VundoFix koji si vec skinuo ranije.
Desni klik na ListBox (beli kvadrad u kojem se ispisuje tekst) i odaberi opciju Add more files.
U sledecem koraku upisi C:\WINDOWS\System32\ixt0.dll pa nakon toga klikni na Add files, pa na Close Window.
Nakon toga klikni na Scan for Vundo i odradi ostatak procedure kao sto si je odradio i prosli put.
|
|
|
|