ComboFix 07-08-09.3 - "VampirLord" 2007-08-11 18:09:37.1 - NTFSx86
BĄd wejcia: Brak aparatu skrypt˘w dla plik˘w o rozszerzeniu ".vbs".
BĄd wejcia: Brak aparatu skrypt˘w dla plik˘w o rozszerzeniu ".vbs".
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\myglobalsearch
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR
C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL
C:\Program Files\myglobalsearch\bar\1.bin\MGSBAR.DLL
C:\Program Files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL
C:\Program Files\myglobalsearch\bar\2.bin\M9FFXTBR.JAR
C:\Program Files\myglobalsearch\bar\2.bin\M9FFXTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\2.bin\M9NTSTBR.JAR
C:\Program Files\myglobalsearch\bar\2.bin\M9NTSTBR.MANIFEST
C:\Program Files\myglobalsearch\bar\2.bin\M9PLUGIN.DLL
C:\Program Files\myglobalsearch\bar\2.bin\MGSBAR.DLL
C:\Program Files\myglobalsearch\bar\2.bin\NPMYGLSH.DLL
C:\Program Files\myglobalsearch\bar\Cache\04DA2179
C:\Program Files\myglobalsearch\bar\Cache\04DA283F
C:\Program Files\myglobalsearch\bar\Cache\04DA2A04.bin
C:\Program Files\myglobalsearch\bar\Cache\04DA2CE3.bin
C:\Program Files\myglobalsearch\bar\Cache\04DA2E79.bin
C:\Program Files\myglobalsearch\bar\Cache\files.ini
C:\Program Files\myglobalsearch\bar\History\search
C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm
C:\WINDOWS\system32\winsys.exe
((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))
2007-08-11 18:07 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-11 17:32 <DIR> d-------- C:\Program Files\BearShare
2007-08-11 17:32 <DIR> d-------- C:\My Downloads
2007-08-11 07:32 <DIR> d-------- C:\Program Files\ALLPlayer
2007-08-11 06:01 <DIR> d-------- C:\DOCUME~1\VAMPIR~1\DANEAP~1\uTorrent
2007-08-11 05:41 <DIR> d-------- C:\Program Files\Gothic III
2007-08-10 02:57 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-08-09 21:38 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-08-09 21:38 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-08-09 21:38 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-08-09 20:24 271,360 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2007-08-09 20:24 18,048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2007-08-08 20:02 <DIR> d-------- C:\WINDOWS\pss
2007-08-08 19:55 <DIR> d-------- C:\WINDOWS\system32\pl-pl
2007-08-08 19:53 <DIR> d-------- C:\WINDOWS\network diagnostic
2007-08-08 19:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Windows Genuine Advantage
2007-08-08 19:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Pulpit
2007-08-08 15:06 <DIR> d-------- C:\WINDOWS\NV2082752.TMP
2007-08-08 15:05 <DIR> d-------- C:\NVIDIA
2007-08-08 13:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\FLEXnet
2007-08-08 13:26 <DIR> d-------- C:\Program Files\Pcsx2
2007-08-08 07:54 <DIR> d-------- C:\Program Files\Bonjour
2007-08-08 07:44 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-08-08 07:43 <DIR> d-------- C:\Program Files\Photoshop
2007-08-08 06:51 <DIR> d-------- C:\Program Files\SnIco Edit
2007-08-05 19:36 <DIR> d-------- C:\Program Files\Xvid
2007-08-05 17:52 163,840 --a------ C:\WINDOWS\system32\unrar.dll
2007-08-05 17:52 <DIR> d-------- C:\DOCUME~1\VAMPIR~1\DANEAP~1\Media Player Classic
2007-08-05 17:51 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-08-05 17:51 740,442 --a------ C:\WINDOWS\system32\divx.dll
2007-08-05 17:51 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-08-05 17:51 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-08-05 17:51 630,784 --a------ C:\WINDOWS\system32\vp7vfw.dll
2007-08-05 17:51 564,224 --a------ C:\WINDOWS\system32\x264vfw.dll
2007-08-05 17:51 438,272 --a------ C:\WINDOWS\system32\vp6vfw.dll
2007-08-05 17:51 39,936 --a------ C:\WINDOWS\system32\huffyuv.dll
2007-08-05 17:51 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-08-05 17:51 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-08-05 17:51 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-08-05 17:51 144,384 --a------ C:\WINDOWS\system32\Iacenc.dll
2007-08-05 17:51 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-08-05 17:33 <DIR> d-------- C:\Program Files\cFosSpeed
2007-08-04 17:24 21,840 --a----t- C:\WINDOWS\system32\SIntfNT.dll
2007-08-04 17:24 17,212 --a----t- C:\WINDOWS\system32\SIntf32.dll
2007-08-04 17:24 12,067 --a----t- C:\WINDOWS\system32\SIntf16.dll
2007-07-30 15:42 <DIR> d--hs---- C:\WINDOWS\ftpcache
2007-07-30 00:22 86,016 --a------ C:\WINDOWS\unvise32.exe
2007-07-30 00:16 <DIR> d-------- C:\Program Files\EdHTMLv5.0
2007-07-28 16:59 <DIR> d-------- C:\Anime
2007-07-26 00:57 <DIR> d-------- C:\Program Files\eSkiMoS R2
2007-07-26 00:57 <DIR> d-------- C:\DOCUME~1\VAMPIR~1\DANEAP~1\eSkiMoS R2
2007-07-24 20:00 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-07-24 12:54 <DIR> d-------- C:\Program Files\GoD
2007-07-22 23:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\nView_Profiles
2007-07-19 22:11 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-07-19 17:31 845,312 --a------ C:\WINDOWS\system32\Smab.dll
2007-07-19 17:31 66,560 --a------ C:\WINDOWS\MOTA113.exe
2007-07-19 17:31 502,784 --a------ C:\WINDOWS\x2.64.exe
2007-07-19 17:31 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2007-07-19 17:31 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2007-07-19 17:31 217,088 --a------ C:\WINDOWS\system32\i420vfw.dll
2007-07-19 17:31 217,073 --a------ C:\WINDOWS\meta4.exe
2007-07-19 17:31 <DIR> d--hs---- C:\WINDOWS\system32\ShellDHCP
2007-07-19 00:32 23 --ahs---- C:\WINDOWS\system32\cbfc0_r.dll
2007-07-19 00:31 <DIR> d-------- C:\Program Files\jv16 PowerTools 2007
2007-07-19 00:21 5 --ahs---- C:\WINDOWS\system32\cfdba6_g.dll
2007-07-16 00:54 <DIR> d-------- C:\Program Files\WMV to AVI MPEG DVD WMV Converter
2007-07-16 00:50 <DIR> d-------- C:\Program Files\WMV To VCD DVD MPEG Converter Pro
2007-07-16 00:38 <DIR> d-------- C:\Program Files\VirtualDubMod
2007-07-16 00:19 <DIR> d-------- C:\Program Files\IP CHECK
2007-07-15 22:47 <DIR> d-------- C:\Program Files\Scan Port
2007-07-14 19:03 <DIR> d-------- C:\Program Files\MarBit
2007-07-14 19:00 <DIR> d--hs---- C:\DOCUME~1\VAMPIR~1\UserData
2007-07-14 18:53 <DIR> d-------- C:\Program Files\DivX
2007-07-14 18:44 <DIR> d-------- C:\DOCUME~1\VAMPIR~1\DANEAP~1\Crystal Player
2007-07-12 16:13 <DIR> d-------- C:\Program Files\NetMeter
2007-07-12 14:28 <DIR> d-------- C:\Program Files\CCleaner
2007-07-11 22:09 <DIR> d-------- C:\DOCUME~1\VAMPIR~1\DANEAP~1\Canon
2007-07-11 22:04 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2007-07-11 22:04 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-07-11 22:03 <DIR> d-------- C:\Program Files\Common Files\ScanSoft Shared
2007-07-11 22:03 <DIR> d-------- C:\DOCUME~1\VAMPIR~1\DANEAP~1\ScanSoft
2007-07-11 22:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\ScanSoft
2007-07-11 21:57 <DIR> d-------- C:\Program Files\OmniPageSE4.0
2007-07-11 21:55 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2007-07-11 21:55 <DIR> d-------- C:\Program Files\PhotoStudio 5.5
2007-07-11 21:53 307,200 --a------ C:\WINDOWS\IsUn0415.exe
2007-07-11 21:53 <DIR> d--h----- C:\DOCUME~1\ALLUSE~1\DANEAP~1\CanonBJ
2007-07-11 21:52 57,344 --a------ C:\WINDOWS\system32\CNCI510.DLL
2007-07-11 21:52 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-07-11 21:52 197,632 --a------ C:\WINDOWS\system32\CNMLM85.DLL
2007-07-11 21:52 135,168 --a------ C:\WINDOWS\system32\CNCL510.DLL
2007-07-11 21:52 106,496 --a------ C:\WINDOWS\system32\cnco510.dll
2007-07-11 21:52 1,298,432 --a------ C:\WINDOWS\system32\CNCC510.DLL
2007-07-11 21:52 <DIR> d--h----- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2007-07-11 21:52 <DIR> d--h----- C:\Program Files\CanonBJ
2007-07-11 21:51 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-07-11 21:51 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-07-11 21:51 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2007-07-11 21:51 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-11 18:13 480032 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-08-11 18:13 43592 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-08-11 18:13 139196 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-11 18:13 10517280 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-10 14:54 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-05 09:33 --------- d-------- C:\Program Files\SkanerOnline
2007-07-19 09:38 74230 --a------ C:\WINDOWS\system32\perfc015.dat
2007-07-19 09:38 448004 --a------ C:\WINDOWS\system32\perfh015.dat
2007-07-11 21:56 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-07-11 02:10 --------- d-------- C:\Program Files\Messenger
2007-07-11 00:05 82258 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-07-11 00:05 82258 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-07-10 23:29 --------- d-------- C:\DOCUME~1\VAMPIR~1\DANEAP~1\Gadu-Gadu
2007-07-10 23:26 --------- d-------- C:\Program Files\Gadu-Gadu
2007-07-10 23:24 --------- d-------- C:\Program Files\Kaspersky Anti-Virus 6.0
2007-07-10 23:15 --------- d-------- C:\Program Files\Nero
2007-07-10 23:14 --------- d-------- C:\Program Files\Common Files\Ahead
2007-07-10 23:00 --------- d-------- C:\Program Files\Realtek
2007-07-10 22:46 0 -rahs---- C:\MSDOS.SYS
2007-07-10 22:46 0 -rahs---- C:\IO.SYS
2007-07-10 22:46 0 --a------ C:\CONFIG.SYS
2007-07-10 22:46 0 --a------ C:\AUTOEXEC.BAT
2007-07-10 22:46 --------- d-------- C:\Program Files\microsoft frontpage
2007-07-10 22:45 --------- d--h----- C:\Program Files\WindowsUpdate
2007-07-10 22:44 --------- d-------- C:\Program Files\Movie Maker
2007-07-10 22:44 --------- d-------- C:\Program Files\Common Files\MSSoap
2007-07-10 22:43 21856 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-07-10 22:43 --------- d-------- C:\Program Files\Windows NT
2007-07-10 22:43 --------- d-------- C:\Program Files\MSN Gaming Zone
2007-05-16 17:19 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 17:19 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 17:19 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-16 17:18 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 17:18 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 17:18 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
--------- C:\Program Files\Usługi online
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Anti-Virus 6.0\avp.exe" [2007-03-09 20:50]
"CBitSpirit"="C:\Program Files\BitSpirit\BitSpirit.exe" [2006-11-07 01:13]
"BearShare"="C:\Program Files\BearShare\BearShare.exe" [2006-08-01 17:04]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-12 17:44]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00]
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
Contents of the 'Scheduled Tasks' folder
2007-08-10 15:15:40 C:\WINDOWS\Tasks\1-Click Maintenance.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-11 18:15:06
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}]
"DisplayName"="Alcohol 120"
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-11 18:16:45 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-11 18:16
--- E O F ---