23 Maj 2008, 14:44
ComboFix 08-05-21.3 - Maciek 2008-05-23 14:33:23.9 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1616 [GMT 2:00]
Running from: C:\Documents and Settings\Maciek\Pulpit\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.
2008-05-23 14:31 . 2008-05-23 14:31 <DIR> d--hs---- C:\FOUND.005
2008-05-17 20:52 . 2008-05-17 20:52 <DIR> d--hs---- C:\FOUND.004
2008-05-12 17:58 . 2008-05-12 17:58 <DIR> d-------- C:\Documents and Settings\Maciek\Dane aplikacji\DAEMON Tools
2008-05-12 17:58 . 2008-05-12 17:58 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-05-12 14:51 . 2008-05-12 14:51 <DIR> d--hs---- C:\FOUND.003
2008-05-09 14:31 . 2008-05-09 14:31 <DIR> d-------- C:\Documents and Settings\Maciek\Dane aplikacji\Ubisoft
2008-05-09 14:31 . 2008-05-09 14:31 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Ubisoft
2008-05-05 15:58 . 2008-05-05 15:58 <DIR> d--hs---- C:\FOUND.002
2008-05-03 11:26 . 2008-05-03 11:26 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 11:26 . 2008-05-03 11:26 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-05-02 20:27 . 2008-05-02 20:27 <DIR> d--hs---- C:\FOUND.001
2008-05-02 15:59 . 2008-05-02 15:59 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\LightScribe
2008-05-02 15:20 . 2008-05-02 15:20 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-05-02 14:39 . 2008-05-02 14:43 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-04-30 17:45 . 2008-04-30 17:45 <DIR> d--hs---- C:\FOUND.000
2008-04-28 17:53 . 2008-05-01 16:19 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-04-27 19:12 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-04-27 19:12 . 2008-04-27 19:12 385 --a------ C:\WINDOWS\ODBC.INI
2008-04-27 19:11 . 2008-04-27 19:11 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-04-27 19:11 . 2008-04-27 19:11 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-04-27 19:10 . 2008-04-27 19:10 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-04-27 15:53 . 2008-04-27 15:53 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-04-25 13:55 . 2008-04-25 13:55 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-04-25 13:55 . 2008-04-25 13:55 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-25 13:55 . 2008-04-25 13:55 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-04-23 20:01 . 2008-05-22 15:07 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-23 20:01 . 2008-04-23 20:01 22,328 --a------ C:\Documents and Settings\Maciek\Dane aplikacji\PnkBstrK.sys
2008-04-23 20:01 . 2008-04-23 20:01 275 --a------ C:\WINDOWS\game.ini
2008-04-23 19:42 . 2008-04-23 19:42 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-04-23 18:36 . 2008-04-23 18:36 <DIR> d-------- C:\WINDOWS\Sun
2008-04-23 18:36 . 2008-04-23 18:36 <DIR> d-------- C:\Program Files\Java
2008-04-23 18:36 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-23 18:35 . 2008-04-23 18:35 <DIR> d-------- C:\Program Files\Common Files\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 13:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-05-02 15:24 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-04-22 18:58 --------- d-----w C:\Program Files\Ulead Systems
2008-04-22 18:58 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-04-22 18:58 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems
2008-04-22 13:27 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Adobe Systems
2008-04-22 13:26 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-22 12:57 --------- d-----w C:\Program Files\uTorrent
2008-04-22 12:57 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\uTorrent
2008-04-21 15:40 --------- d-----w C:\Program Files\Trend Micro
2008-04-21 13:35 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-04-21 13:06 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Gadu-Gadu
2008-04-21 12:46 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-04-21 12:45 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Ahead
2008-04-21 12:45 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Ahead
2008-04-21 12:43 --------- d-----w C:\Program Files\Nero
2008-04-21 12:43 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-21 12:43 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-04-21 12:38 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Talkback
2008-04-21 12:31 --------- d-----w C:\Program Files\Lexmark 3300 Series
2008-04-21 12:28 15,600 ----a-w C:\WINDOWS\gdrv.sys
2008-04-21 12:27 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-04-21 12:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-21 12:27 --------- d-----w C:\Program Files\Realtek
2008-04-21 12:26 --------- d-----w C:\Program Files\DIFX
2008-04-21 12:24 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\InstallShield
2008-04-21 12:20 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-21 12:19 --------- d-----w C:\Program Files\VDOTool
2008-04-21 12:12 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-21 12:11 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"Gadu-Gadu"="D:\GG\gg.exe" [2008-03-20 12:04 2127296]
"DAEMON Tools Lite"="D:\DAEMON\daemon.exe" [2008-04-01 11:39 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="D:\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-21 15:41 262401]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-16 19:07 8491008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"WinFast Schedule"="d:\TV\WFWIZ.exe" [2005-03-02 13:21 278528]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 10:08 16380416 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Maciek^Menu Start^Programy^Autostart^Adobe Gamma.lnk]
path=C:\Documents and Settings\Maciek\Menu Start\Programy\Autostart\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 D:\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-01 10:21 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gainward]
--a------ 2007-11-01 13:25 2165272 C:\Program Files\VDOTool\TBPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2007-07-18 17:55 451872 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:55 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-09-16 19:07 81920 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-09-16 19:07 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"WebClient"=2 (0x2)
"SharedAccess"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\Maciek\\COD 4\\iw3mp.exe"=
"D:\\Maciek\\cs\\hl.exe"=
"C:\\WINDOWS\\System32\\PnkBstrA.exe"=
"C:\\WINDOWS\\System32\\PnkBstrB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27050:TCP"= 27050:TCP:*:Disabled:smut
R2 WF23880;WinFast TV2000/DV2000 WDM Video Capture.;C:\WINDOWS\system32\drivers\wf88vcap.sys [2004-10-18 11:25]
R2 WF88XBAR;WinFast TV2000/DV2000 WDM Crossbar.;C:\WINDOWS\system32\drivers\WF88XBAR.sys [2004-10-18 11:25]
R2 WFTUNE;WinFast TV2000/DV2000 WDM Tuner.;C:\WINDOWS\system32\drivers\WF88TUNE.sys [2004-10-18 11:25]
R3 WFIOCTL;WFIOCTL;d:\TV\WFIOCTL.SYS [2005-01-06 16:55]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2008-04-21 14:28]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-23 14:34:02
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-23 14:34:17
ComboFix-quarantined-files.txt 2008-05-23 12:34:16
Pre-Run: 16,437,624,832 bajtów wolnych
Post-Run: 16,430,497,792 bajtów wolnych
151
23 Maj 2008, 15:18
Folder::
C:\FOUND.005
C:\FOUND.004
C:\FOUND.003
C:\FOUND.002
C:\FOUND.001
C:\FOUND.000
23 Maj 2008, 15:25
ComboFix 08-05-21.3 - Maciek 2008-05-23 15:22:47.10 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1655 [GMT 2:00]
Running from: C:\Documents and Settings\Maciek\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Maciek\Pulpit\CFScript.txt
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\FOUND.000
C:\FOUND.000\FILE0000.CHK
C:\FOUND.001
C:\FOUND.001\FILE0000.CHK
C:\FOUND.001\FILE0001.CHK
C:\FOUND.001\FILE0002.CHK
C:\FOUND.001\FILE0003.CHK
C:\FOUND.001\FILE0004.CHK
C:\FOUND.002
C:\FOUND.002\FILE0000.CHK
C:\FOUND.003
C:\FOUND.003\FILE0000.CHK
C:\FOUND.003\FILE0001.CHK
C:\FOUND.003\FILE0002.CHK
C:\FOUND.003\FILE0003.CHK
C:\FOUND.003\FILE0004.CHK
C:\FOUND.003\FILE0005.CHK
C:\FOUND.003\FILE0006.CHK
C:\FOUND.003\FILE0007.CHK
C:\FOUND.004
C:\FOUND.004\FILE0000.CHK
C:\FOUND.004\FILE0001.CHK
C:\FOUND.004\FILE0002.CHK
C:\FOUND.004\FILE0003.CHK
C:\FOUND.004\FILE0004.CHK
C:\FOUND.004\FILE0005.CHK
C:\FOUND.004\FILE0006.CHK
C:\FOUND.004\FILE0007.CHK
C:\FOUND.004\FILE0008.CHK
C:\FOUND.004\FILE0009.CHK
C:\FOUND.004\FILE0010.CHK
C:\FOUND.004\FILE0011.CHK
C:\FOUND.004\FILE0012.CHK
C:\FOUND.004\FILE0013.CHK
C:\FOUND.004\FILE0014.CHK
C:\FOUND.004\FILE0015.CHK
C:\FOUND.004\FILE0016.CHK
C:\FOUND.004\FILE0017.CHK
C:\FOUND.004\FILE0018.CHK
C:\FOUND.004\FILE0019.CHK
C:\FOUND.004\FILE0020.CHK
C:\FOUND.004\FILE0021.CHK
C:\FOUND.004\FILE0022.CHK
C:\FOUND.004\FILE0023.CHK
C:\FOUND.004\FILE0024.CHK
C:\FOUND.004\FILE0025.CHK
C:\FOUND.004\FILE0026.CHK
C:\FOUND.004\FILE0027.CHK
C:\FOUND.004\FILE0028.CHK
C:\FOUND.004\FILE0029.CHK
C:\FOUND.004\FILE0030.CHK
C:\FOUND.004\FILE0031.CHK
C:\FOUND.004\FILE0032.CHK
C:\FOUND.004\FILE0033.CHK
C:\FOUND.004\FILE0034.CHK
C:\FOUND.004\FILE0035.CHK
C:\FOUND.004\FILE0036.CHK
C:\FOUND.004\FILE0037.CHK
C:\FOUND.004\FILE0038.CHK
C:\FOUND.004\FILE0039.CHK
C:\FOUND.004\FILE0040.CHK
C:\FOUND.004\FILE0041.CHK
C:\FOUND.004\FILE0042.CHK
C:\FOUND.004\FILE0043.CHK
C:\FOUND.004\FILE0044.CHK
C:\FOUND.004\FILE0045.CHK
C:\FOUND.004\FILE0046.CHK
C:\FOUND.004\FILE0047.CHK
C:\FOUND.004\FILE0048.CHK
C:\FOUND.004\FILE0049.CHK
C:\FOUND.004\FILE0050.CHK
C:\FOUND.004\FILE0051.CHK
C:\FOUND.004\FILE0052.CHK
C:\FOUND.004\FILE0053.CHK
C:\FOUND.004\FILE0054.CHK
C:\FOUND.004\FILE0055.CHK
C:\FOUND.004\FILE0056.CHK
C:\FOUND.004\FILE0057.CHK
C:\FOUND.004\FILE0058.CHK
C:\FOUND.004\FILE0059.CHK
C:\FOUND.004\FILE0060.CHK
C:\FOUND.004\FILE0061.CHK
C:\FOUND.004\FILE0062.CHK
C:\FOUND.004\FILE0063.CHK
C:\FOUND.004\FILE0064.CHK
C:\FOUND.004\FILE0065.CHK
C:\FOUND.004\FILE0066.CHK
C:\FOUND.004\FILE0067.CHK
C:\FOUND.004\FILE0068.CHK
C:\FOUND.004\FILE0069.CHK
C:\FOUND.004\FILE0070.CHK
C:\FOUND.004\FILE0071.CHK
C:\FOUND.004\FILE0072.CHK
C:\FOUND.004\FILE0073.CHK
C:\FOUND.004\FILE0074.CHK
C:\FOUND.004\FILE0075.CHK
C:\FOUND.004\FILE0076.CHK
C:\FOUND.004\FILE0077.CHK
C:\FOUND.005
C:\FOUND.005\FILE0000.CHK
C:\FOUND.005\FILE0001.CHK
C:\FOUND.005\FILE0002.CHK
C:\FOUND.005\FILE0003.CHK
C:\FOUND.005\FILE0004.CHK
C:\FOUND.005\FILE0005.CHK
C:\FOUND.005\FILE0006.CHK
C:\FOUND.005\FILE0007.CHK
C:\FOUND.005\FILE0008.CHK
C:\FOUND.005\FILE0009.CHK
C:\FOUND.005\FILE0010.CHK
C:\FOUND.005\FILE0011.CHK
C:\FOUND.005\FILE0012.CHK
C:\FOUND.005\FILE0013.CHK
C:\FOUND.005\FILE0014.CHK
C:\FOUND.005\FILE0015.CHK
C:\FOUND.005\FILE0016.CHK
C:\FOUND.005\FILE0017.CHK
C:\FOUND.005\FILE0018.CHK
.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.
2008-05-12 17:58 . 2008-05-12 17:58 <DIR> d-------- C:\Documents and Settings\Maciek\Dane aplikacji\DAEMON Tools
2008-05-12 17:58 . 2008-05-12 17:58 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-05-09 14:31 . 2008-05-09 14:31 <DIR> d-------- C:\Documents and Settings\Maciek\Dane aplikacji\Ubisoft
2008-05-09 14:31 . 2008-05-09 14:31 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Ubisoft
2008-05-03 11:26 . 2008-05-03 11:26 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 11:26 . 2008-05-03 11:26 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-05-02 15:59 . 2008-05-02 15:59 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\LightScribe
2008-05-02 15:20 . 2008-05-02 15:20 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-05-02 14:39 . 2008-05-02 14:43 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-04-28 17:53 . 2008-05-01 16:19 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-04-27 19:12 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-04-27 19:12 . 2008-04-27 19:12 385 --a------ C:\WINDOWS\ODBC.INI
2008-04-27 19:11 . 2008-04-27 19:11 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-04-27 19:11 . 2008-04-27 19:11 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-04-27 19:10 . 2008-04-27 19:10 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-04-27 15:53 . 2008-04-27 15:53 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-04-25 13:55 . 2008-04-25 13:55 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-04-25 13:55 . 2008-04-25 13:55 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-25 13:55 . 2008-04-25 13:55 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-04-23 20:01 . 2008-05-22 15:07 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-23 20:01 . 2008-04-23 20:01 22,328 --a------ C:\Documents and Settings\Maciek\Dane aplikacji\PnkBstrK.sys
2008-04-23 20:01 . 2008-04-23 20:01 275 --a------ C:\WINDOWS\game.ini
2008-04-23 19:42 . 2008-04-23 19:42 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-04-23 18:36 . 2008-04-23 18:36 <DIR> d-------- C:\WINDOWS\Sun
2008-04-23 18:36 . 2008-04-23 18:36 <DIR> d-------- C:\Program Files\Java
2008-04-23 18:36 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-23 18:35 . 2008-04-23 18:35 <DIR> d-------- C:\Program Files\Common Files\Java
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 13:06 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-05-02 15:24 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-04-22 18:58 --------- d-----w C:\Program Files\Ulead Systems
2008-04-22 18:58 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-04-22 18:58 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems
2008-04-22 13:27 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Adobe Systems
2008-04-22 13:26 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-22 12:57 --------- d-----w C:\Program Files\uTorrent
2008-04-22 12:57 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\uTorrent
2008-04-21 15:40 --------- d-----w C:\Program Files\Trend Micro
2008-04-21 13:35 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-04-21 13:06 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Gadu-Gadu
2008-04-21 12:46 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-04-21 12:45 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Ahead
2008-04-21 12:45 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Ahead
2008-04-21 12:43 --------- d-----w C:\Program Files\Nero
2008-04-21 12:43 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-21 12:43 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Nero
2008-04-21 12:38 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\Talkback
2008-04-21 12:31 --------- d-----w C:\Program Files\Lexmark 3300 Series
2008-04-21 12:28 15,600 ----a-w C:\WINDOWS\gdrv.sys
2008-04-21 12:27 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-04-21 12:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-21 12:27 --------- d-----w C:\Program Files\Realtek
2008-04-21 12:26 --------- d-----w C:\Program Files\DIFX
2008-04-21 12:24 --------- d-----w C:\Documents and Settings\Maciek\Dane aplikacji\InstallShield
2008-04-21 12:20 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-21 12:19 --------- d-----w C:\Program Files\VDOTool
2008-04-21 12:12 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-21 12:11 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"Gadu-Gadu"="D:\GG\gg.exe" [2008-03-20 12:04 2127296]
"DAEMON Tools Lite"="D:\DAEMON\daemon.exe" [2008-04-01 11:39 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="D:\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-21 15:41 262401]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-16 19:07 8491008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"WinFast Schedule"="d:\TV\WFWIZ.exe" [2005-03-02 13:21 278528]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 10:08 16380416 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Maciek^Menu Start^Programy^Autostart^Adobe Gamma.lnk]
path=C:\Documents and Settings\Maciek\Menu Start\Programy\Autostart\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 D:\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-01 10:21 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gainward]
--a------ 2007-11-01 13:25 2165272 C:\Program Files\VDOTool\TBPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2007-07-18 17:55 451872 C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:55 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-09-16 19:07 81920 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-09-16 19:07 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"WebClient"=2 (0x2)
"SharedAccess"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\Maciek\\COD 4\\iw3mp.exe"=
"D:\\Maciek\\cs\\hl.exe"=
"C:\\WINDOWS\\System32\\PnkBstrA.exe"=
"C:\\WINDOWS\\System32\\PnkBstrB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27050:TCP"= 27050:TCP:*:Disabled:smut
R2 WF23880;WinFast TV2000/DV2000 WDM Video Capture.;C:\WINDOWS\system32\drivers\wf88vcap.sys [2004-10-18 11:25]
R2 WF88XBAR;WinFast TV2000/DV2000 WDM Crossbar.;C:\WINDOWS\system32\drivers\WF88XBAR.sys [2004-10-18 11:25]
R2 WFTUNE;WinFast TV2000/DV2000 WDM Tuner.;C:\WINDOWS\system32\drivers\WF88TUNE.sys [2004-10-18 11:25]
R3 WFIOCTL;WFIOCTL;d:\TV\WFIOCTL.SYS [2005-01-06 16:55]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2008-04-21 14:28]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-23 15:23:25
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-23 15:23:39
ComboFix-quarantined-files.txt 2008-05-23 13:23:38
Pre-Run: 16,394,502,144 bajtów wolnych
Post-Run: 16,384,770,048 bajtów wolnych
267
23 Maj 2008, 15:28
23 Maj 2008, 17:29
23 maj 2008 17:26:26
System operacyjny: Microsoft Windows XP Professional, Dodatek Service Pack 2 (Build 2600)
Kaspersky Online Scanner wersja: 5.0.98.0
Ostatnia aktualizacja Kaspersky Anti-Virus23/05/2008
Liczba wpisów w bazie danych Kaspersky Anti-Virus798905
Ustawienia skanowania
Skanowanie przy użyciu następujących baz danych rozszerzone
Skanuj archiwa tak
Skanuj pocztowe bazy danych tak
Obszar skanowania Mój komputer
A:\
C:\
D:\
E:\
F:\
G:\
Statystyki skanowania
Liczba skanowanych obiektów 55247
Liczba wykrytych wirusów 0
Liczba zainfekowanych obiektów 0
Liczba podejrzanych obiektów 0
Czas trwania skanowania 01:01:03
Nazwa zainfekowanego obiektu Nazwa wirusa Ostatnie działanie
C:\WINDOWS\system32\config\system.LOG Object is locked pominięty
C:\WINDOWS\system32\config\software.LOG Object is locked pominięty
C:\WINDOWS\system32\config\default.LOG Object is locked pominięty
C:\WINDOWS\system32\config\SECURITY Object is locked pominięty
C:\WINDOWS\system32\config\SAM Object is locked pominięty
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked pominięty
C:\WINDOWS\system32\config\SAM.LOG Object is locked pominięty
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked pominięty
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked pominięty
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked pominięty
C:\WINDOWS\system32\config\SYSTEM Object is locked pominięty
C:\WINDOWS\system32\config\SOFTWARE Object is locked pominięty
C:\WINDOWS\system32\config\DEFAULT Object is locked pominięty
C:\WINDOWS\system32\drivers\sptd.sys Object is locked pominięty
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked pominięty
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked pominięty
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked pominięty
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked pominięty
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked pominięty
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked pominięty
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked pominięty
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked pominięty
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked pominięty
C:\WINDOWS\system32\h323log.txt Object is locked pominięty
C:\WINDOWS\Debug\PASSWD.LOG Object is locked pominięty
C:\WINDOWS\Sti_Trace.log Object is locked pominięty
C:\WINDOWS\wiaservc.log Object is locked pominięty
C:\WINDOWS\wiadebug.log Object is locked pominięty
C:\WINDOWS\SchedLgU.Txt Object is locked pominięty
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked pominięty
C:\Documents and Settings\NetworkService\Ustawienia lokalne\Historia\History.IE5\index.dat Object is locked pominięty
C:\Documents and Settings\NetworkService\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat Object is locked pominięty
C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked pominięty
C:\Documents and Settings\NetworkService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked pominięty
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked pominięty
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked pominięty
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked pominięty
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked pominięty
C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked pominięty
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked pominięty
C:\Documents and Settings\Maciek\NTUSER.DAT Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Historia\History.IE5\index.dat Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Historia\History.IE5\MSHist012008052320080524\index.dat Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Dane aplikacji\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows Media\10.0\WMSDKNSD.XML Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Dane aplikacji\Microsoft\Windows\UsrClass.dat.LOG Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\7kuki25u.default\Cache\_CACHE_MAP_ Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\7kuki25u.default\Cache\_CACHE_001_ Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\7kuki25u.default\Cache\_CACHE_002_ Object is locked pominięty
C:\Documents and Settings\Maciek\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\7kuki25u.default\Cache\_CACHE_003_ Object is locked pominięty
C:\Documents and Settings\Maciek\Cookies\index.dat Object is locked pominięty
C:\Documents and Settings\Maciek\ntuser.dat.LOG Object is locked pominięty
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked pominięty
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked pominięty
Proces skanowania został zakończony.
23 Maj 2008, 17:39