ComboFix 08-04-27.3 - Łukasz 2008-04-28 20:25:21.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1532 [GMT 2:00]
Running from: H:\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
H:\WINDOWS\system32\kdmek.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-28 )))))))))))))))))))))))))))))))
.
2008-04-28 19:22 . 2008-04-28 19:22 <DIR> d-------- H:\Program Files\Trend Micro
2008-04-28 19:13 . 2008-04-28 19:13 812,344 --a------ H:\HJTInstall.exe
2008-04-25 08:45 . 2008-01-06 14:44 140,288 --a------ H:\WINDOWS\system32\COMDLG32.OCX
2008-04-22 18:38 . 2008-04-22 18:38 <DIR> d-------- H:\Program Files\Kaspersky Lab
2008-04-22 18:38 . 2008-04-28 20:29 6,599,968 --ahs---- H:\WINDOWS\system32\drivers\fidbox.dat
2008-04-22 18:38 . 2008-04-22 18:45 96,645 --a------ H:\WINDOWS\system32\drivers\klin.dat
2008-04-22 18:38 . 2008-04-28 20:27 92,552 --ahs---- H:\WINDOWS\system32\drivers\fidbox.idx
2008-04-22 18:38 . 2008-04-22 18:45 87,941 --a------ H:\WINDOWS\system32\drivers\klick.dat
2008-04-22 18:38 . 2008-04-28 20:29 33,824 --ahs---- H:\WINDOWS\system32\drivers\fidbox2.dat
2008-04-22 18:38 . 2008-04-28 20:27 5,192 --ahs---- H:\WINDOWS\system32\drivers\fidbox2.idx
2008-04-22 18:36 . 2008-04-22 18:36 <DIR> d-------- H:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-04-20 13:51 . 2008-04-20 13:51 276 --a------ H:\WINDOWS\BeatBox.INI
2008-04-20 13:41 . 2008-04-20 16:22 67 --a------ H:\WINDOWS\musicmaker.INI
2008-04-20 13:35 . 2008-04-20 13:35 <DIR> d-------- H:\Program Files\Common Files\MAGIX Shared
2008-04-20 12:34 . 2005-09-15 16:55 458,752 --a------ H:\WINDOWS\system32\mgxoschk.dll
2008-04-20 12:34 . 2005-09-07 18:08 2,446 --a------ H:\WINDOWS\mgxoschk.ini
2008-04-20 12:25 . 1998-10-01 15:22 299,520 --a------ H:\WINDOWS\uninst.exe
2008-04-20 12:25 . 1998-05-20 21:36 254,976 --a------ H:\WINDOWS\system32\xaudio.dll
2008-04-20 12:19 . 2008-04-20 12:21 270 --a------ H:\WINDOWS\Muma50dm.INI
2008-04-20 12:19 . 2008-04-20 12:19 97 --a------ H:\WINDOWS\MAGIX.INI
2008-04-20 12:14 . 2008-04-20 12:14 720,896 --a------ H:\WINDOWS\iun6002.exe
2008-04-10 21:52 . 2008-04-10 21:56 <DIR> d-------- H:\Program Files\DAEMON Tools Lite
2008-04-02 12:38 . 2008-04-18 17:28 4,096 --a------ H:\WINDOWS\system32\crash
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-28 18:29 --------- d-----w H:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-04-28 18:24 1,778,287 ----a-w H:\ComboFix.exe
2008-04-22 16:47 --------- d-----w H:\Program Files\lg_fwupdate
2008-04-10 17:53 717,296 ----a-w H:\WINDOWS\system32\drivers\sptd.sys
2008-03-19 21:22 --------- d-----w H:\Program Files\Java
2008-03-19 21:21 --------- d-----w H:\Program Files\Common Files\Java
2008-03-19 15:58 --------- d-----w H:\Program Files\Reference Assemblies
2008-03-19 15:58 --------- d-----w H:\Program Files\MSBuild
2008-03-19 15:53 --------- d-----w H:\Program Files\MSXML 6.0
2008-03-12 07:56 --------- d--h--w H:\Program Files\InstallShield Installation Information
2008-03-11 18:40 --------- d-----w H:\Program Files\BearShare Applications
2008-03-08 15:56 --------- d-----w H:\Program Files\Gadu-Gadu
2008-03-07 21:59 --------- d-----w H:\Program Files\Common Files\Blizzard Entertainment
2008-03-04 18:55 22,328 ----a-w H:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-03-04 02:32 --------- d-----w H:\Program Files\MSXML 4.0
2006-07-30 20:20 959 --sha-r H:\WINDOWS\system32\autorun.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2007-12-02 16:13 394680 --a------ H:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="H:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 12:54 2131392]
"swg"="H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-09 18:44 68856]
"BitComet"="I:\QUAKE 3\BitComet\BitComet.exe" [2007-12-07 17:03 1913656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyTuneV"="H:\Program Files\Gigabyte\ET5\ETcall.exe" [2006-12-15 15:13 31552]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 10:08 16380416 H:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-06-15 10:45 1826816 H:\WINDOWS\SkyTel.exe]
"ISUSPM Startup"="H:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 08:15 221184]
"ISUSScheduler"="H:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 08:15 81920]
"TkBellExe"="H:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-03 14:51 180269]
"SunJavaUpdateSched"="H:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"AVP"="H:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 18:36 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="H:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 01:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winbue32]
winbue32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"H:\\WINDOWS\\system32\\PnkBstrA.exe"=
"H:\\WINDOWS\\system32\\PnkBstrB.exe"=
"I:\\Nowy folder\\iw3mp.exe"=
"H:\\Program Files\\Gadu-Gadu\\gg.exe"=
"I:\\QUAKE 3\\QuakeIIIArena 1.32 + OSP\\quake3.exe"=
"I:\\QUAKE 3\\BitComet\\BitComet.exe"=
"I:\\programy\\BearShare.exe"=
"I:\\wow\\World of Warcraft\\BackgroundDownloader.exe"=
"H:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\Polish\\setup.exe"=
"H:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"18524:TCP"= 18524:TCP:BitComet 18524 TCP
"18524:UDP"= 18524:UDP:BitComet 18524 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"57568:TCP"= 57568:TCP:BitComet 57568 TCP
"57568:UDP"= 57568:UDP:BitComet 57568 UDP
"11851:TCP"= 11851:TCP:BitComet 11851 TCP
"11851:UDP"= 11851:UDP:BitComet 11851 UDP
R3 klim5;Kaspersky Anti-Virus NDIS Filter;H:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
R3 MarkFun_NT;MarkFun_NT;H:\Program Files\Gigabyte\ET5\markfun.w32 [2006-11-21 21:20]
*Newly Created Service* - MARKFUN_NT
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-28 20:29:34
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MarkFun_NT]
"ImagePath"="\??\H:\Program Files\Gigabyte\ET5\markfun.w32"
.
------------------------ Other Running Processes ------------------------
.
H:\WINDOWS\system32\ati2evxx.exe
H:\WINDOWS\system32\ati2evxx.exe
H:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
H:\WINDOWS\system32\PnkBstrA.exe
H:\WINDOWS\system32\PnkBstrB.exe
H:\Program Files\CyberLink\Shared Files\RichVideo.exe
H:\WINDOWS\system32\wdfmgr.exe
H:\Program Files\Gigabyte\ET5\GUI.exe
H:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-04-28 20:31:12 - machine was rebooted [ťukasz]
ComboFix-quarantined-files.txt 2008-04-28 18:31:09
Pre-Run: 20,889,313,280 bajtów wolnych
Post-Run: 21,766,193,152 bajt˘w wolnych
139 --- E O F --- 2008-04-09 21:42:20