ComboFix 08-07-24.3 - klezmer 2008-07-25 15:07:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.730 [GMT 2:00]
Running from: C:\Documents and Settings\klezmer\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))
.
2008-07-25 14:27 . 2008-07-25 14:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-25 12:39 . 2008-07-25 12:39 <DIR> d-------- C:\Documents and Settings\klezmer\Dane aplikacji\TuneUp Software
2008-07-25 11:41 . 2008-07-25 11:41 <DIR> d-------- C:\Documents and Settings\klezmer\Dane aplikacji\Avira
2008-07-25 11:38 . 2008-07-25 11:38 <DIR> d-------- C:\Program Files\Avira
2008-07-25 11:38 . 2008-07-25 11:38 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-07-21 15:07 . 2003-06-19 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-07-21 15:07 . 2008-07-21 15:07 421 --a------ C:\WINDOWS\ODBC.INI
2008-07-21 15:06 . 2008-07-21 15:06 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-07-21 15:02 . 2008-07-21 15:02 <DIR> d-------- C:\Program Files\Alcohol Soft
2008-07-21 15:00 . 2008-07-21 15:00 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-21 14:35 . 2008-07-21 14:35 <DIR> d-------- C:\Program Files\Odkurzacz
2008-07-21 07:58 . 2008-07-21 07:59 <DIR> d-------- C:\WINDOWS\system32\MsDtc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-25 10:39 --------- d-----w C:\Documents and Settings\klezmer\Dane aplikacji\uTorrent
2008-07-24 18:11 --------- d-----w C:\Documents and Settings\klezmer\Dane aplikacji\Skype
2008-07-21 12:39 --------- d-----w C:\Program Files\NAPI-PROJEKT
2008-07-21 07:59 --------- d-----w C:\Program Files\InstallShield Installation Information
2008-07-21 07:59 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-21 07:58 --------- d-----w C:\Program Files\PowerQuest
2008-07-21 07:52 --------- d-----w C:\Program Files\CCleaner
2008-07-21 07:33 306,432 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-07-21 07:33 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-21 07:28 --------- d-----w C:\Program Files\RegDoctor
2008-07-21 07:28 --------- d-----w C:\Documents and Settings\klezmer\Dane aplikacji\TuneUp SoftwareBackup
2008-07-21 07:27 --------- d-----w C:\Documents and Settings\klezmer\Dane aplikacji\Thinstall
2008-07-21 07:14 --------- d-----w C:\Program Files\uTorrent
2008-07-21 06:52 --------- d-----w C:\Program Files\RaimaRadioPro
2008-07-21 06:52 --------- d-----w C:\Documents and Settings\klezmer\Dane aplikacji\RaimaRadioPro
2008-07-21 06:47 --------- d-----w C:\Program Files\Spik
2008-07-21 06:46 --------- d-----w C:\Documents and Settings\klezmer\Dane aplikacji\Spik
2008-07-21 06:40 --------- d-----w C:\Program Files\Skype
2008-07-21 06:39 --------- d-----w C:\Program Files\ESTsoft
2008-07-21 06:39 --------- d-----w C:\Documents and Settings\klezmer\Dane aplikacji\ESTSoft
2008-07-21 06:39 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ESTsoft
2008-07-21 06:37 --------- d-----w C:\Program Files\SubEdit-Player
2008-07-21 06:37 --------- d-----w C:\Program Files\Real Alternative
2008-07-21 06:37 --------- d-----w C:\Program Files\ffdshow
2008-07-21 06:33 --------- d-----w C:\Program Files\Your Uninstaller 2006
2008-07-21 06:33 --------- d-----w C:\Program Files\OO Software
2008-07-21 06:32 --------- d-----w C:\Documents and Settings\klezmer\Dane aplikacji\URSoft
2008-07-21 06:01 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-21 06:00 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07 8491008]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-07-25 11:49 266497]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 01:44 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiscSpaceChecks"= 000000000000f03f
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-09-17 01:07 81920 C:\WINDOWS\system32\nvmctray.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Spik\\Spik.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 viasraid;viasraid;C:\WINDOWS\system32\drivers\viasraid.sys [2003-10-31 13:22]
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [2008-07-25 11:49]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE [2008-07-25 11:49]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [2008-07-25 11:49]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-21 09:33]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
O8 -: E&ksport do programu Microsoft Excel - C:\PROGRA~1\Microsoft Office\OFFICE11\EXCEL.EXE/3000
O18 -: Handler: wpmsg - {2E0AC5A0-3597-11D6-B3ED-0001021DC1C3} - C:\Program Files\Spik\url_wpmsg.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-25 15:08:18
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-25 15:08:35
ComboFix-quarantined-files.txt 2008-07-25 13:08:33
Pre-Run: 12,095,057,920 bajtów wolnych
Post-Run: 12,086,693,888 bajtów wolnych
100