@bobby
Uradim ovo u ponedeljak/utorak, cim dodjem kuci. Hvala na pomoci
P.S. nista ne pitaj za sp2..... stoji mi cd na stolu jos od prosle godine i eto....
Dopuna: 15 Apr 2008 11:31
Eto to je to
ComboFix 08-04-14.2 - Administrator 2008-04-15 11:23:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.133 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\poludecu\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-15 to 2008-04-15 )))))))))))))))))))))))))))))))
.
2008-04-09 20:44 . 2008-04-10 19:58 <DIR> d-------- C:\Temp\Love in the Time of Cholera
2008-04-09 13:24 . 2008-04-09 13:27 <DIR> d-------- C:\Temp\The Five People You Meet in Heaven - prevod!
2008-04-09 13:22 . 2008-04-09 13:24 <DIR> d-------- C:\Temp\Music Within - prevod!
2008-04-05 18:06 . 2008-04-06 15:29 <DIR> d-------- C:\Temp\The Good Night - prevod
2008-04-05 18:05 . 2008-04-09 20:44 <DIR> d-------- C:\Temp
2008-03-30 22:30 . 2008-04-10 19:57 49 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-30 18:09 . 2008-04-15 11:26 5,872,416 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-30 18:09 . 2008-04-15 11:26 97,312 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-30 18:09 . 2008-04-11 11:38 73,748 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-30 18:09 . 2008-04-11 11:38 11,072 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-30 18:00 . 2008-03-30 18:16 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-03-30 18:00 . 2008-03-30 18:00 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-03-30 17:57 . 2008-03-30 17:57 81,701 --a------ C:\WINDOWS\system32\drivers\klif.cab
2008-03-30 17:55 . 2008-03-30 17:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-03-30 15:46 . 2008-03-30 15:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ahead
2008-03-30 15:44 . 2004-03-03 20:30 125,184 --a------ C:\WINDOWS\system32\drivers\imagesrv.sys
2008-03-30 15:44 . 2004-03-03 20:30 5,504 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2008-03-30 15:43 . 2008-03-30 15:44 <DIR> d-------- C:\Program Files\Ahead
2008-03-30 15:43 . 2001-07-06 13:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll
2008-03-30 15:43 . 2001-07-06 11:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll
2008-03-30 15:43 . 2001-07-06 17:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-03-30 15:43 . 2001-07-09 10:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-03-30 15:43 . 2000-06-26 10:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-03-30 15:43 . 2001-06-26 07:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
2008-03-30 15:42 . 2008-03-30 15:42 75 --a------ C:\WINDOWS\pdf2rtf.INI
2008-03-30 15:41 . 2008-03-30 21:41 1,024 --a------ C:\WINDOWS\system32\pdf2word.DAT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-15 09:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-30 19:38 --------- d-s---w C:\Program Files\PTBSync
2008-03-30 19:34 --------- d-----w C:\Program Files\ICQToolbar
2008-03-30 15:57 --------- d-----w C:\Program Files\Kaspersky Lab
2008-03-30 13:44 --------- d-----w C:\Documents and Settings\Administrator\Application Data\POP Peeper
2008-03-30 13:43 --------- d-----w C:\Program Files\Common Files\Ahead
2008-03-18 10:46 --------- d-----w C:\Program Files\Java
2008-03-08 13:53 454,656 ----a-w C:\Program Files\putty.exe
2008-03-08 13:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-08 13:41 --------- d-----w C:\Program Files\Common Files\Deterministic Networks
2008-03-08 13:41 --------- d-----w C:\Program Files\Cisco Systems
2008-02-28 09:32 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ICQ Toolbar
2008-02-28 07:25 --------- d-----w C:\Program Files\ICQ6
2008-02-26 11:26 --------- d-----w C:\Program Files\Opera
2008-02-23 08:48 --------- d-----w C:\Program Files\POP Peeper
2008-02-19 15:50 --------- d-----w C:\Program Files\Google
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 09:41 13312]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"MECA"="C:\Program Files\Meca\\Meca.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-11 05:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-11-04 06:15 163840 C:\WINDOWS\system32\VTTrayp.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 05:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 03:58 16264192 C:\WINDOWS\RTHDCPL.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 17:35 32768]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20 227328]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 23:22 3739648]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-12-18 00:43 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 09:41 13312]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2007-04-22 14:44:13 20992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\strkjhk]
C:\WINDOWS\bdir\sdflkj3.exe
R3 ham50;Intel V92 HaM Data Fax Voice;C:\WINDOWS\System32\DRIVERS\IntelH51.sys [2001-08-06 15:11]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\System32\DRIVERS\klim5.sys [2007-12-13 13:28]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-15 11:26:56
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 2
**************************************************************************
.
Completion time: 2008-04-15 11:28:26
ComboFix-quarantined-files.txt 2008-04-15 09:28:21
Pre-Run: 5,932,122,112 bytes free
Post-Run: 6,054,363,136 bytes free
|