ComboFix 08-06-08.2 - Tomek 2008-06-09 10:56:04.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.527 [GMT 2:00]
Running from: C:\Documents and Settings\Tomek\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tomek\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\DOCUME~1\Tomek\USTAWI~1\Temp\RarSFX0\_start.exe
C:\DOCUME~1\Tomek\USTAWI~1\Temp\RarSFX0\setup.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-09 to 2008-06-09 )))))))))))))))))))))))))))))))
.
2008-06-09 00:17 . 2008-06-09 00:17 <DIR> d-------- C:\Documents and Settings\Tomek\DoctorWeb
2008-06-08 23:03 . 2008-06-08 23:32 <DIR> d-a------ C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-06-02 17:01 . 2008-06-02 17:01 <DIR> d-------- C:\Program Files\A4Tech
2008-06-02 16:53 . 2008-06-02 16:53 <DIR> d-------- C:\ster_10250
2008-06-02 16:53 . 2007-02-10 22:17 36,864 --a------ C:\WINDOWS\system32\Amhooker.dll
2008-06-02 16:53 . 2007-02-10 02:04 14,336 --a------ C:\WINDOWS\system32\drivers\Amps2prt.sys
2008-06-02 16:53 . 2007-02-10 23:55 13,824 --a------ C:\WINDOWS\system32\drivers\Amusbprt.sys
2008-06-02 16:53 . 2006-04-11 13:56 10,240 --a------ C:\WINDOWS\system32\drivers\Arfumx86.sys
2008-06-02 16:53 . 2007-01-24 17:46 8,704 --a------ C:\WINDOWS\system32\drivers\Amfilter.sys
2008-05-26 03:13 . 2008-05-26 03:13 <DIR> d-------- C:\Program Files\Atomic Alarm Clock
2008-05-26 02:25 . 2008-05-26 02:25 <DIR> d-------- C:\Documents and Settings\Tomek\Dane aplikacji\Desktopicon
2008-05-22 10:50 . 47,616 C:\WINDOWS\system32\fsmgmt.dll.tmp
2008-05-22 10:50 . 47,616 C:\WINDOWS\system32\fsmgmt.dll
2008-05-21 23:15 . 2008-05-25 11:33 <DIR> d-------- C:\Program Files\IrfanView
2008-05-14 15:58 . 2008-05-14 15:58 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-05-14 13:06 . 2008-06-07 13:39 <DIR> d-------- C:\Program Files\Jewel Quest 2
2008-05-14 10:15 . 2008-05-28 15:17 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-05-13 00:39 . 2008-05-18 22:59 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-13 00:39 . 2008-05-13 00:39 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 08:42 --------- d-----w C:\Documents and Settings\Tomek\Dane aplikacji\uTorrent
2008-06-07 22:06 47,616 ----a-w C:\WINDOWS\system32\ fsmgmt.dll
2008-06-07 21:40 --------- d-----w C:\Program Files\MP3 Player Utilities 4.00
2008-06-07 08:30 47,616 ----a-w C:\WINDOWS\system32\ fsmgmt.dll.tmp
2008-06-06 10:27 --------- d-----w C:\Program Files\uTorrent
2008-06-02 19:34 --------- d-----w C:\Documents and Settings\Tomek\Dane aplikacji\Skype
2008-06-02 19:07 --------- d-----w C:\Documents and Settings\Tomek\Dane aplikacji\skypePM
2008-05-30 16:47 --------- d-----w C:\Program Files\GameJack4
2008-05-25 09:33 --------- d-----w C:\Program Files\Belt Generator
2008-05-18 21:01 --------- d-----w C:\Documents and Settings\Tomek\Dane aplikacji\Corel
2008-05-18 20:59 2,516 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-05-11 17:57 --------- d-----w C:\Program Files\Gadu-Gadu
2008-05-09 19:33 --------- d-----w C:\Documents and Settings\Tomek\Dane aplikacji\gtk-2.0
2008-05-01 09:04 --------- d-----w C:\Program Files\Tapeter
2008-04-30 17:59 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\nView_Profiles
2008-04-30 08:23 --------- d-----w C:\Program Files\Odkurzacz
2008-04-27 13:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-26 22:09 --------- d-----w C:\Documents and Settings\Tomek\Dane aplikacji\RaimaRadio
2008-04-26 13:53 --------- d-----w C:\Documents and Settings\Gość\Dane aplikacji\Corel
2008-04-24 17:16 --------- d-----w C:\Program Files\TesterM
2008-04-20 15:08 --------- d-----w C:\Program Files\GIMP-2.0
2008-04-18 19:55 --------- d-----w C:\Program Files\SkanerOnline
2008-04-11 13:55 --------- d-----w C:\Program Files\NAPI-PROJEKT
2008-04-11 13:55 --------- d-----w C:\Program Files\Luxor
2008-04-09 16:34 --------- d-----w C:\Program Files\Skype
2008-04-09 16:34 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-04-07 22:02 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-03-25 04:52 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:52 178,976 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-09 14:53 2,368 ----a-w C:\WINDOWS\system32\SVKP.sys
2007-12-26 21:34 87,608 ----a-w C:\Documents and Settings\Tomek\Dane aplikacji\ezpinst.exe
2007-12-26 21:34 47,360 ----a-w C:\Documents and Settings\Tomek\Dane aplikacji\pcouffin.sys
2007-11-22 10:13 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-30 16:05 139264]
"Dzieńdobry!"="C:\Program Files\VSD Software\Dzieńdobry!\ddsched.exe" [2005-03-16 23:04 10240]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 20:53 68856]
"SkinClock"="C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-02-20 14:29 524800]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-01-31 15:22 219952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WireLessKeyboard "="C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2005-08-02 23:45 253952]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
"Gainward"="C:\Program Files\VDOTool\TBPanel.exe" [2007-11-01 14:25 2165272]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2006-03-02 14:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-02 14:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2006-03-02 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2006-03-02 14:00 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-16 19:07 8491008]
"nwiz"="nwiz.exe" [2007-09-16 19:07 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-09-16 19:07 81920 C:\WINDOWS\system32\nvmctray.dll]
"Hidder"="C:\PROGRA~1\G DATA Software\SekretNIK\Hidder.exe" [2002-06-03 14:36 565248]
"Tapeter"="C:\Program Files\Tapeter\Tapeter.exe" [2005-07-09 18:22 434176]
"WheelMouse"="C:\Program Files\A4Tech\Mouse\Amoumain.exe" [2007-02-10 23:33 188416]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"msacm.imc"= imc32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BlueSoleil VoIP Plugin.lnk]
backup=C:\WINDOWS\pss\BlueSoleil VoIP Plugin.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BlueSoleil.lnk]
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^InterVideo WinCinema Manager.lnk]
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^PC Alert 4.lnk]
backup=C:\WINDOWS\pss\PC Alert 4.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Tomek^Menu Start^Programy^Autostart^Registration SETTLERS - Dziedzictwo Królów.LNK]
backup=C:\WINDOWS\pss\Registration SETTLERS - Dziedzictwo Królów.LNKStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Tomek^Menu Start^Programy^Autostart^UniSpiker-2.6.lnk]
backup=C:\WINDOWS\pss\UniSpiker-2.6.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Tomek^Menu Start^Programy^Autostart^Yahoo! Widget Engine.lnk]
backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
--a------ 2007-05-04 02:32 961024 C:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CBitSpirit]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
D:\Daemon Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dzieńdobry!]
--a------ 2006-09-24 11:50 330752 C:\Program Files\VSD Software\Dzieńdobry!\dziendobry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hidder]
--a------ 2002-06-03 14:36 565248 C:\PROGRA~1\G DATA Software\SekretNIK\Hidder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InstalkiLite]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveMonitor]
--a------ 2006-09-05 17:45 497152 C:\Program Files\MSI\Live Update 3\LMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2005-02-22 09:55 1611488 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 17:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Odkurzacz-MCD]
--a------ 2008-02-04 19:13 266240 C:\Program Files\Odkurzacz\odk_mcd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-09-01 15:57 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkinClock]
--a------ 2008-02-20 14:29 524800 C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-03-14 03:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-13 20:53 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Twoje TVN24]
--a------ 2007-11-27 18:06 2744400 C:\Program Files\Pasek TVN24\tvn-ustawienia.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
C:\Program Files\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
--a------ 2008-01-31 15:22 219952 C:\Program Files\uTorrent\utorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-05-25 19:35 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WireLessMouse ]
--a------ 2004-06-27 16:38 503808 C:\Program Files\Multimedia Combo Set\MouseDrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\µTorrent]
--a------ 2008-01-31 15:22 219952 C:\Program Files\uTorrent\utorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"C:\\WINDOWS\\system32\\javaw.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\NAPI-PROJEKT\\napisy.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\Program Files\\WapSter\\AQQ\\AQQ.exe"=
"C:\\Documents and Settings\\Tomek\\Pulpit\\Radio Internauty.lnk"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Dzony-Loker\\mirc.exe"=
"C:\\Program Files\\Winamp\\winamp.exe"=
"C:\\Program Files\\Team17\\Worms 3D\\bin\\worms3d.exe"=
"C:\\Documents and Settings\\Tomek\\Pulpit\\Dżony Łoker 5.0.lnk"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7573:TCP"= 7573:TCP:onet.skype
R0 AFPAnsi;G-DATA UkrywaczAnsi;C:\WINDOWS\system32\Drivers\AFPAnsi.sys [2001-10-26 01:40]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [2008-03-09 16:53]
R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2005-05-12 14:39]
R3 uscsc108;uscsc108;C:\WINDOWS\system32\DRIVERS\uscsc108.sys [2003-03-09 19:41]
S3 CoolerXPDriver;CoolerXPDriver;C:\Program Files\MSI\PC Alert 4\NTCooler.sys [2006-08-09 15:29]
S3 MemStPCI;Kontroler modułów pamięci Memory Stick Sony (PCI);C:\WINDOWS\system32\DRIVERS\MemStPCI.SYS [2004-08-04 00:00]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02fc0f70-c6d5-11db-b296-00110927ff82}]
\Shell\AutoRun\command - J:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23fe0b9e-f7c5-11db-b371-00110927ff82}]
\Shell\Auto\command - H:\UFO.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2e01a8be-de30-11db-b2fb-00110927ff82}]
\Shell\AutoRun\command - I:\RunGame.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{af7b1724-ce8d-11dc-b5a4-00110927ff82}]
\Shell\Auto\command - UFO.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{faa73d7c-2825-11dc-b413-00110927ff82}]
\Shell\Auto\command - H:\UFO.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-09 10:58:24
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-09 10:59:20
ComboFix-quarantined-files.txt 2008-06-09 08:59:11
Pre-Run: 18,557,472,768 bajtów wolnych
Post-Run: 18,683,564,032 bajtów wolnych
221 --- E O F --- 2008-05-29 13:32:08