ComboFix 08-06-20.4 - Michał 2008-06-26 12:32:54.2 - NTFSx86
Running from: C:\Documents and Settings\Michał\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Michał\Pulpit\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\dbrtpbtg.exe
C:\WINDOWS\system32\rykprusx.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dbrtpbtg.exe
C:\WINDOWS\system32\rykprusx.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-26 to 2008-06-26 )))))))))))))))))))))))))))))))
.
2008-06-26 12:27 . 2008-06-26 12:27 389,120 ---hs---- C:\WINDOWS\system32\winsro.exe
2008-06-26 12:27 . 2008-06-26 12:27 0 --a------ C:\adware.exe
2008-06-26 11:32 . 2008-06-26 11:32 9,216 --a------ C:\WINDOWS\system32\gqxl.exe
2008-06-26 10:37 . 2008-06-26 10:37 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-26 10:37 . 2008-06-26 10:37 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-06-26 09:47 . 2008-06-26 09:47 <DIR> d-------- C:\My Downloads
2008-06-25 16:49 . 2008-06-25 16:49 <DIR> d-------- C:\Program Files\SAGEM
2008-06-25 16:49 . 2008-06-25 16:49 <DIR> d-------- C:\Documents and Settings\Michał\Dane aplikacji\InstallShield
2008-06-25 10:50 . 2008-06-26 09:48 <DIR> d-------- C:\Programy
2008-06-25 01:37 . 2002-09-20 18:18 57,856 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-06-25 01:37 . 2001-08-17 22:46 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2008-06-25 01:37 . 2001-08-17 22:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-06-25 01:35 . 2008-06-26 12:32 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-06-25 01:35 . 2008-06-25 01:35 <DIR> dr-h----- C:\Documents and Settings\Default User\Ustawienia lokalne
2008-06-25 01:35 . 2008-06-25 01:35 <DIR> d-------- C:\Documents and Settings\Default User\Ulubione
2008-06-25 01:35 . 2008-06-25 00:39 <DIR> d--h----- C:\Documents and Settings\Default User\Szablony
2008-06-25 01:35 . 2008-06-25 01:35 <DIR> d-------- C:\Documents and Settings\Default User\Pulpit
2008-06-25 01:35 . 2008-06-25 01:35 <DIR> d-------- C:\Documents and Settings\Default User\Moje dokumenty
2008-06-25 01:35 . 2008-06-25 01:35 <DIR> dr------- C:\Documents and Settings\Default User\Menu Start
2008-06-25 01:35 . 2008-06-25 01:35 <DIR> dr-h----- C:\Documents and Settings\Default User\Dane aplikacji
2008-06-25 01:35 . 2008-06-25 01:35 <DIR> d-------- C:\Documents and Settings\All Users\Ulubione
2008-06-25 01:35 . 2008-06-25 01:35 <DIR> d--h----- C:\Documents and Settings\All Users\Szablony
2008-06-25 01:35 . 2008-06-25 16:50 <DIR> d-------- C:\Documents and Settings\All Users\Pulpit
2008-06-25 01:35 . 2008-06-25 00:44 <DIR> dr------- C:\Documents and Settings\All Users\Menu Start
2008-06-25 01:35 . 2008-06-25 00:40 <DIR> dr------- C:\Documents and Settings\All Users\Dokumenty
2008-06-25 01:35 . 2008-06-26 10:37 <DIR> dr-h----- C:\Documents and Settings\All Users\Dane aplikacji
2008-06-25 01:02 . 2008-06-25 01:03 <DIR> d-------- C:\WINDOWS\nview
2008-06-25 01:02 . 2006-06-01 11:22 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-06-25 01:02 . 2008-06-26 12:25 63,804 --a------ C:\WINDOWS\system32\nvapps.xml
2008-06-25 01:02 . 2006-06-01 11:22 16,960 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-06-25 01:01 . 2006-06-01 19:09 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-06-25 01:00 . 2004-05-02 10:47 23,040 -ra------ C:\WINDOWS\system32\drivers\GVCplDrv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 14:50 33 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-06-25 14:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-24 22:56 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-24 22:56 --------- d-----w C:\Documents and Settings\Michał\Dane aplikacji\InterTrust
2008-06-24 22:55 --------- d-----w C:\Program Files\Intel
2008-06-24 22:54 --------- d-----w C:\Program Files\Intel Audio Studio
2008-06-24 22:53 --------- d-----w C:\Program Files\SigmaTel
2008-06-24 22:53 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-24 22:49 --------- d-----w C:\Program Files\MSXML 4.0
2008-06-24 22:42 558,142 ----a-w C:\WINDOWS\java\Packages\TV31V1B3.ZIP
2008-06-24 22:42 155,995 ----a-w C:\WINDOWS\java\Packages\XNZF9F9V.ZIP
2008-06-24 22:42 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-24 22:40 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((( snapshot@2008-06-26_11.32.56,67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-26 07:33:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-26 10:25:37 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-06-25 14:39:02 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-26 10:27:39 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-06-25 14:39:02 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2008-06-26 10:27:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
- 2008-06-25 14:39:02 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-26 10:27:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-24 23:09:04 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-06-26 10:26:58 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-06-24 23:09:04 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat
+ 2008-06-26 10:26:58 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat
- 2008-06-24 23:09:04 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-06-26 10:26:58 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-06-24 23:09:04 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2008-06-26 10:26:58 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2008-06-26 10:25:40 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_4cc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-20 18:05 13312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelAudioStudio"="C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [2006-08-02 17:17 9134080]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-06-01 11:22 7618560]
"nwiz"="nwiz.exe" [2006-06-01 11:22 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 11:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"avast!"="C:\Programy\avast\ashDisp.exe" [2008-05-16 01:19 79224]
"BearShare"="C:\Programy\BearShare.exe" [2006-08-01 17:04 3313664]
"WinDLL (winsro.exe)"="C:\WINDOWS\System32\winsro.exe,start" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-09-20 18:05 13312]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-06-25 16:50:11 1205840]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-26 12:33:33
Windows 5.1.2600 Dodatek Service Pack. 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-26 12:33:48
ComboFix-quarantined-files.txt 2008-06-26 10:33:46
ComboFix2.txt 2008-06-26 09:33:16
Pre-Run: 36,011,016,192 bajtów wolnych
Post-Run: 36,006,772,736 bajtów wolnych
122