skeniraj sa Spybot seach&destroy, Ad-aware, CWShreedder i kopiraj tu log od hijack this
edit: jbmu kad ne citam do kraja...
makni:
O2 - BHO: (no name) - {112650C4-0A01-5CFA-890E-03CB4BBF4C1D} - C:\WINDOWS\system32\ndptbzc.dll
O2 - BHO: (no name) - {648592A3-44B7-9AF8-BACA-02859776A1CD} - C:\WINDOWS\system32\llkyzqd.dl
O3 - Toolbar: Safety Bar - {fbea0445-4c4a-4136-864a-c72a4a182a84} - C:\Program Files\Safety Bar\SafetyBar.dll (file missing)
O4 - HKLM\..\Run: [WinFast2KLoadDefault] "rundll32.exe" C:\WINDOWS\system32\wf2kcpl.dll,DllLoadDefaultSettings
O4 - HKLM\..\Run: [jrukc.dll] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\jrukc.dll,rezxbg
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O8 - Extra context menu item: &Search -
http://kn.bar.need2find.com/KN/menusearch.html?p=KN
ak neznas od cega je ova ip adresa makni:
O17 - HKLM\System\CCS\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220
17 - HKLM\System\CS1\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220