Ok ovo cu da uradim veceras posto mi je taj comp u selu. Inace, posto nema pristup internetu i mali HD sluzi samo za prženje CD-a i gledanje filmova vikendom, ponekad za neku aplikaciju u Wordu. Nisam ni imao namjeru da instaliram Anti Virus zato sto ne mogu da uradim update.
Dopuna: 13 Mar 2008 21:12
ComboFix 08-03-10.1 - miki 2008-03-13 18:22:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1250.381.1033.18.73 [GMT 1:00]
Running from: C:\Documents and Settings\miki\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\svchost.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_POWERMANAGER
-------\PowerManager
((((((((((((((((((((((((( Files Created from 2008-02-13 to 2008-03-13 )))))))))))))))))))))))))))))))
.
2008-03-13 18:00 . 2008-03-13 18:00 376 --a------ C:\WINDOWS\ODBC.INI
2008-03-13 17:59 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-03-13 17:57 . 2008-03-13 17:57 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-03-13 17:57 . 2008-03-13 17:57 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-03-13 17:54 . 2008-03-13 17:57 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-13 17:50 . 2008-03-13 17:50 <DIR> dr-h----- C:\MSOCache
2008-03-11 18:31 . 2002-08-29 01:32 21,760 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-03-10 17:38 . 2008-03-10 18:29 87 --a------ C:\WINDOWS\SYMGAMES.INI
2008-03-09 17:05 . 2008-03-09 17:09 57 --a------ C:\WINDOWS\boxworld.ini
2008-03-06 20:15 . 2008-03-06 20:15 1,409 --a------ C:\WINDOWS\system32\tmpDFB6C.FOT
2008-03-05 23:27 . 2008-03-05 23:29 <DIR> d-------- C:\Program Files\Solve Elec 2.1
2008-03-05 23:12 . 2008-03-06 12:51 <DIR> d-------- C:\Program Files\The KMPlayer
2008-03-05 22:08 . 2002-08-29 02:32 159,360 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-03-05 22:08 . 2002-08-29 00:16 142,208 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-03-05 22:08 . 2002-08-29 03:00 77,440 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-03-05 22:08 . 2001-08-17 15:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-03-05 22:08 . 2001-08-17 14:59 50,048 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-03-05 22:08 . 2002-08-29 02:27 7,040 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2008-03-05 22:08 . 2002-08-29 02:32 5,888 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-03-05 22:08 . 2001-08-17 14:48 4,608 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2008-03-05 22:08 . 2002-08-29 02:32 2,816 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2008-03-05 22:07 . 2002-08-29 03:01 56,832 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-03-05 22:07 . 2002-08-29 02:27 56,576 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-03-05 22:07 . 2001-08-17 14:48 5,120 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-03-05 22:07 . 2001-08-17 14:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-03-05 22:05 . 2008-03-05 22:05 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-03-05 22:04 . 2008-03-05 21:39 356,120 --a------ C:\WINDOWS\system32\PerfStringBackup.INI
2008-03-05 22:04 . 2001-08-23 13:00 77,824 --a--c--- C:\WINDOWS\system32\dllcache\spcommon.dll
2008-03-05 22:04 . 2001-08-23 13:00 61,440 --a--c--- C:\WINDOWS\system32\dllcache\spcplui.dll
2008-03-05 22:04 . 2008-03-05 21:23 4,161 --a------ C:\WINDOWS\ODBCINST.INI
2008-03-05 22:03 . 2008-03-05 21:18 <DIR> dr------- C:\Documents and Settings\All Users\Documents
2008-03-05 22:02 . 2008-03-13 17:59 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-03-05 22:02 . 2008-03-05 22:02 <DIR> d-------- C:\WINDOWS\system32\CatRoot
2008-03-05 22:01 . 2008-03-05 21:32 261 --a------ C:\WINDOWS\system32\$winnt$.inf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-05 20:24 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-05 20:23 558,142 ----a-w C:\WINDOWS\java\Packages\4YSX3ZP7.ZIP
2008-03-05 20:23 155,995 ----a-w C:\WINDOWS\java\Packages\JB7XZTRV.ZIP
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 04:41 13312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 04:41 13312]
R3 G200;G200;C:\WINDOWS\System32\DRIVERS\G200m.sys [2001-08-17 13:49]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-13 18:26:07
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\devldr32.exe
.
**************************************************************************
.
Completion time: 2008-03-13 18:27:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-13 17:27:29
|