pre nego sto sam poceo da skeniram sa ComboFix kaspersky je nasao trojan download i izbrisao ga ja mislim da je sad sve u redu sa kompom ali evo ti log od ComboFix
ComboFix 08-01-23.1C - wizard 2008-01-26 9:09:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.642 [GMT 1:00]
Running from: C:\Documents and Settings\wizard\Desktop\ComboFix(3).exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\svchost.ini
C:\WINDOWS\system32\0_exception.nls
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\kdlre.exe
C:\WINDOWS\system32\systeminfo.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_RUNTIME
-------\runtime
((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.
2008-01-26 09:08 . <DIR> C:\WINDOWS\LastGood.Tmp
2008-01-26 09:08 . 2001-08-23 13:00 375,808 --a------ C:\WINDOWS\system32\cmd.exe
2008-01-26 09:08 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-25 15:47 . 2008-01-25 15:47 <DIR> d-------- C:\VundoFix Backups
2008-01-25 15:27 . 2008-01-25 15:27 88,205 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-01-25 15:27 . 2008-01-25 15:27 84,621 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-01-25 15:26 . 2008-01-26 09:12 3,788,320 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-25 15:26 . 2008-01-26 09:11 54,896 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-25 15:26 . 2008-01-26 09:13 4,128 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-25 15:26 . 2008-01-26 09:11 2,456 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-25 15:20 . 2008-01-25 15:20 <DIR> d-------- C:\kav
2008-01-21 20:20 . 2008-01-21 20:20 65,862 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-01-21 20:19 . 2008-01-21 20:19 5,760,054 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-01-21 20:18 . 2008-01-21 20:20 5,802 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-01-21 20:17 . 2008-01-21 20:17 <DIR> d-------- C:\WINDOWS\BricoPacks
2008-01-21 17:55 . 2008-01-21 17:55 <DIR> d-------- C:\Program Files\Mayoko
2008-01-20 17:24 . 2008-01-20 17:24 0 --a------ C:\WINDOWS\jppc.INI
2008-01-19 16:11 . 2008-01-19 16:11 876 --a------ C:\WINDOWS\$_hpcst$.hpc
2008-01-17 13:46 . 2008-01-17 13:46 <DIR> d-------- C:\WINDOWS\Subtitle Downloader
2008-01-17 13:46 . 2008-01-17 13:46 <DIR> d-------- C:\Program Files\Subtitle Downloader
2008-01-13 00:56 . 2008-01-21 20:40 <DIR> d-------- C:\Program Files\iolo
2008-01-13 00:56 . 2006-03-28 08:54 696,320 --a------ C:\WINDOWS\system32\libeay32.dll
2008-01-13 00:56 . 2006-03-28 08:55 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2008-01-13 00:56 . 2008-01-13 00:56 406 --a------ C:\WINDOWS\system32\ioloBootDefrag.cfg
2008-01-09 22:40 . 2008-01-09 22:40 17,408 --a------ C:\psapi.dll
2008-01-08 13:22 . 2008-01-08 13:22 <DIR> d-------- C:\Program Files\FireTrust
2008-01-07 18:05 . 2008-01-07 18:05 <DIR> d-------- C:\Program Files\Lavasoft RegHance
2008-01-06 16:23 . 2008-01-25 15:32 <DIR> d-a------ C:\Program Files\(HijackThis)
2008-01-06 15:59 . 2008-01-25 15:27 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-05 11:16 . 2008-01-05 11:16 94 ---h----- C:\WINDOWS\system32\spv1_WCssg.ini
2008-01-05 10:20 . 2008-01-05 10:20 <DIR> d-------- C:\Program Files\SkyGrabber275
2008-01-04 12:53 . 2008-01-07 16:49 <DIR> d-------- C:\Program Files\OpenVPN
2008-01-04 11:32 . 2008-01-17 14:17 <DIR> d-------- C:\Program Files\ProgDVB
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 14:32 --------- d---a-w C:\Program Files\(HijackThis)
2008-01-25 13:48 4,078 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-01-22 22:44 --------- d-----w C:\Program Files\Winamp
2008-01-14 12:51 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-01-07 17:03 --------- d-----w C:\Program Files\Lavasoft
2008-01-04 10:26 --------- d-----w C:\Program Files\DVB-S PowerInstall
2008-01-04 10:26 --------- d-----w C:\Program Files\Common Files\Elecard
2008-01-01 23:44 --------- d-----w C:\Program Files\vPlug Files Center
2007-11-30 14:12 --------- d-----w C:\Program Files\GameHouse Games Collection
2007-11-28 17:47 --------- d-----w C:\Program Files\AnGo´s Game Collection
2007-11-14 10:40 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-11-11 06:59 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-11-11 06:59 249,856 ------w C:\WINDOWS\Setup1.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="sm56hlpr.exe" [2004-12-28 23:01 544768 C:\WINDOWS\sm56hlpr.exe]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-09-20 20:52 222472]
C:\Documents and Settings\wizard\Start Menu\Programs\Startup\
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 08:43:08 180224]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Server4PC.lnk - C:\Program Files\TechniSat DVB\bin\Server4PC.exe [2000-11-22 14:39:16 450560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
[HKLM\~\startupfolder\C:^Documents and Settings^wizard^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\wizard\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^wizard^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
path=C:\Documents and Settings\wizard\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
backup=C:\WINDOWS\pss\Sonic CinePlayer Quick Launch.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-03-03 12:00 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-11 16:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-11 16:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
--a------ 2001-11-29 01:00 28672 C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:56 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer]
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskBar]
--a------ 2002-05-08 01:00 122880 C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskTray]
--a------ 2001-06-29 01:00 163840 C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 01:00 90112 C:\WINDOWS\UpdReg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch]
--a------ 2002-07-02 10:56 24576 C:\WINDOWS\system32\CTHELPER.EXE
R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\Cinemsup.sys [2002-07-19 08:10]
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [2005-08-21 21:12]
S3 SIVDRIVER;SIV Kernel Driver;C:\WINDOWS\system32\Drivers\SIVX32.SYS [2006-01-13 15:29]
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 12:07]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8316a8ef-8f6c-11dc-a1c6-00d0d70ec459}]
\shell\Setup\command - H:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 16:17:28 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-26 09:13:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
.
Completion time: 2008-01-26 9:15:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-26 08:15:09
|