Evo sta sam nasao na nekom 4umu , pa i ti probaj :
Your infected with Trojan.Vundo...
Please download Process Explorer by Systernals from here:
http://www.sysinternals.com/Utilitie...sExplorer.htmlNext, download Pocket Killbox from here:
http://www.bleepingcomputer.com/files/killbox.phpUnzip both files to your Desktop and have them ready to use.
Also go here and download Vundo.reg to your Desktop but dont do anything with it yet.
http://www.bleepingcomputer.com/file...e/fixvundo.regNext, boot into Safe Mode (restart your PC and tap F8 as it restarts) and double click on procexp.exe (Process Explorer).
In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top. Once you see this screen click on each instance of ddabc.dll once and then click the kill button. After you have killed all of the ddabc.dll's under winlogon click OK.
Also look for any .ini or bak files or other dll's with either the same name or the file name in reverse & kill them as well (eg ddabc.bak or cbadd.ini etc). Record the name of any of these files found so you can remove them in the steps below.
Next double click on explorer.exe and again click once on each instance of ddabc.dll then click the kill button.
Also look for any .ini or bak files or reverse named dll's with either the same name or the file name in reverse & kill them as well. Record the name of any of these files found so you can remove them in the steps below.
Click on the Threads tab at the top. Once you have done that click OK again.
Next, still in Safe Mode, run HijackThis and place a check beside each of the following and click 'fix checked'.
O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:WINDOWSSystem32ddabc.dll
O4 - HKLM..RunServices: [p2pnetworking] p2pnetworking.exe
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} -
http://winfixer.com/pages/scanner/releases/WFXScanR.cabO20 - Winlogon Notify: ddabc - C:WINDOWSSystem32ddabc.dll
Doubleclick on Vundo.reg now and ok the prompt to merge with your registry but do not reboot yet.
Run Killbox now. Copy and paste the full file path of the below files in the box and click on Delete on Reboot. Next click on the button with the red circle and an X in the middle. You will get a message saying "File with be deleted on next reboot, click "Yes". Process and Reboot now?" Click "Yes" to reboot only after the last file you enter.
C:WINDOWSSystem32ddabc.dll
Also type in the full name and filepath of of any of the reverse named .bak or .ini or other files that you discovered in using Process Explorer.
Reboot now and disable your antivirus program and go here and run an online scan with BitDefender.
http://www.bitdefender.com/scan8/ie.htmlWhen the ActiveX Control has loaded, click on "Click here to scan" and grab a coffee. Post back and let us know what it found (post the log).
Run Hijack This again and post a new log (if any viruses are detected and removed, reboot first)