@blade
Briši sve pod
01 i :
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKUS\S-1-5-18\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\NetworkService\Local Settings\Application Data\smss.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\NetworkService\Local Settings\Application Data\smss.exe" (User 'Default user')
Što se tiće ovih 04 entry-a
Morat ćeš ih ručno brisat, sa HJT-om napraviš samo da se ne pokreću u startup-u
Added by the
RONTOKBRO.B WORM! - NOTE - this file is placed in the UserProfile%\Application Data folder, and should NOT be confused with the legitimate Windows
smss.exe process, always located in the Winnt\System32 or Windows\System32 folder, and which moreover should NOT figure in Msconfig/Startup!
Znaći brišeš:
"C:\Documents and Settings\NetworkService\Local Settings\Application Data\
smss.exe"