ComboFix 08-07-27.5 - Andrzej Lis 2008-07-28 14:00:40.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1575 [GMT 2:00]
Running from: C:\Documents and Settings\Andrzej Lis\Moje dokumenty\Nowy folder\ComboFix.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Andrzej Lis\Dane aplikacji\macromedia\Flash Player\#SharedObjects\ZZ2CF4D7\interclick.com
C:\Documents and Settings\Andrzej Lis\Dane aplikacji\macromedia\Flash Player\#SharedObjects\ZZ2CF4D7\interclick.com\ud.sol
C:\Documents and Settings\Andrzej Lis\Dane aplikacji\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Andrzej Lis\Dane aplikacji\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{DEF85C80-216A-43AB-AF70-1665EDBE2780}
-------\Service_{DEF85C80-216A-43ab-AF70-1665EDBE2780}
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))
.
2008-07-06 16:06 . 2008-07-06 16:06 <DIR> d-------- C:\Documents and Settings\Andrzej Lis\Dane aplikacji\Sony Corporation
2008-06-30 17:11 . 2008-06-30 17:11 <DIR> d-------- C:\Program Files\Sony
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 10:09 2,309 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-07-27 22:32 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-07-26 19:46 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\AdobeUM
2008-06-30 15:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-16 20:52 1,114,891 ----a-w C:\Program Files\szachy.exe
2008-06-16 20:52 --------- d-----w C:\Program Files\Armageddon
2008-06-16 14:59 --------- d-----w C:\Program Files\Opera
2008-06-16 14:58 8,926,832 ----a-w C:\Opera_950_in_Setup.exe
2008-06-15 16:59 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-06-15 14:13 --------- d-----w C:\Program Files\BearShare
2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 19:45 --------- d-----w C:\Program Files\Edgard
2008-06-10 19:24 --------- d-----w C:\Program Files\EasyLanguage
2008-06-10 14:39 --------- d-----w C:\Program Files\MyPlayCity.com
2008-06-10 14:39 --------- d-----w C:\Program Files\MyPlayCity
2008-06-10 14:39 --------- d-----w C:\Program Files\Conduit
2008-06-09 16:08 --------- d-----w C:\Program Files\IrfanView
2008-06-09 14:42 65,790 ----a-w C:\iranf wiew polski.zip
2008-06-09 12:53 6,666,408 ----a-w C:\Program Files\Opera_9.27_International_Setup.exe
2008-06-09 12:44 --------- d-----w C:\Program Files\Google
2008-06-06 12:58 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\AdobeAUM
2008-06-03 21:21 --------- d-----w C:\Program Files\Avira
2008-06-03 21:21 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-06-03 21:05 --------- d-----w C:\Program Files\Sunbelt Software
2008-06-03 17:49 --------- d-----w C:\Documents and Settings\Monika Lis\Dane aplikacji\Winamp
2008-06-01 14:48 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\Media Player Classic
2008-06-01 14:47 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-30 17:58 --------- d-----w C:\Documents and Settings\Andrzej Lis\Dane aplikacji\Winamp
2008-05-30 17:56 --------- d-----w C:\Program Files\Winamp
2008-05-13 22:05 3,663,208 ----a-w C:\BSPL_5.2.5_[www.POBIERALNIA.org].exe
2008-05-09 06:15 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-05-09 06:15 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-05-09 05:14 65 ----a-w C:\Program Files\Common Files\appop.log
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}"= "C:\Program Files\MyPlayCity\tbMyPl.dll" [2008-03-04 13:44 1470488]
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
2008-03-04 13:44 1470488 --a------ C:\Program Files\MyPlayCity\tbMyPl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}"= "C:\Program Files\MyPlayCity\tbMyPl.dll" [2008-03-04 13:44 1470488]
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4724C5D8-DFA7-417A-A2F5-1EABFEE9B4AC}"= "C:\Program Files\MyPlayCity\tbMyPl.dll" [2008-03-04 13:44 1470488]
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2007-10-29 14:00 15360]
"Gadu-Gadu"="D:\Gadu-Gadu\gg.exe" [2008-03-20 12:04 2127296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-11-06 11:30 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-11-06 11:30 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ScreenManager Pro for LCD"="C:\Program Files\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe" [2006-06-08 10:33 8953856]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 20:49 36352]
"KAVPersonal50"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" [2006-03-27 17:55 94350]
"DIRECTCD"="C:\Program Files\COMPANY_NAME\Disc Master 2.5\DirectCD.exe" [2005-10-25 00:49 299008]
"WINCINEMAMGR"="C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe" [2005-01-21 02:47 270336]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-10-05 14:25 868352]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.16\AsRunHelp.exe" [2006-11-14 08:25 363008]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"nwiz"="nwiz.exe" [2007-11-06 11:30 1626112 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-10-29 14:00 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
COMPANY_NAME WinCinema Manager.lnk - C:\Program Files\COMPANY_NAME\Common\Bin\WinCinemaMgr.exe [2008-05-09 07:11:28 229376]
InterVideo WinCinema Manager.lnk - C:\Program Files\COMPANY_NAME\Common\Bin\WinCinemaMgr.exe [2008-05-09 07:11:28 229376]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\mohpa.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
R0 ivicd;Ivi CDVD Filter Driver;C:\WINDOWS\system32\drivers\ivicd.sys [2005-01-12 06:29]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [2006-03-20 19:22]
R3 iviudf;iviudf;C:\WINDOWS\system32\drivers\IviUdf.sys [2005-06-23 02:09]
S2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 10:21]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11712b1d-9965-11db-af56-806d6172696f}]
\Shell\AutoRun\command - E:\.\Bin\ASSETUP.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-eMuleAutoStart - C:\Program Files\eMule\emule.exe
HKLM-Run-BearShare - C:\Program Files\BearShare\BearShare.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
hxxp://google.bearshare.com/pl
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-28 14:04:56
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-28 14:06:45
ComboFix-quarantined-files.txt 2008-07-28 12:06:40
Pre-Run: 215,583,723,520 bajtów wolnych
Post-Run: 215,294,439,424 bajtów wolnych
146 --- E O F --- 2008-07-09 12:56:49