ComboFix 07-12-09.1 - PC 2007-12-09 20:42:36.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.654 [GMT 1:00]
Running from: C:\Documents and Settings\PC\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.
2007-12-09 16:54 . 2007-12-09 17:05 <DIR> d-------- C:\totalcmd
2007-12-09 16:54 . 2007-09-14 07:02 545 --a------ C:\WINDOWS\UC.PIF
2007-12-09 16:54 . 2007-09-14 07:02 545 --a------ C:\WINDOWS\RAR.PIF
2007-12-09 16:54 . 2007-09-14 07:02 545 --a------ C:\WINDOWS\PKZIP.PIF
2007-12-09 16:54 . 2007-09-14 07:02 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2007-12-09 16:54 . 2007-09-14 07:02 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2007-12-09 16:54 . 2007-09-14 07:02 545 --a------ C:\WINDOWS\LHA.PIF
2007-12-09 16:54 . 2007-09-14 07:02 545 --a------ C:\WINDOWS\ARJ.PIF
2007-12-09 13:18 . 2007-12-09 14:16 <DIR> d-------- C:\Program Files\Encyklopedia Gier 08
2007-12-09 12:53 . 2007-12-09 12:53 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ESET
2007-12-09 10:55 . 2007-12-09 10:55 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-08 15:49 . 2007-12-08 15:49 <DIR> d--h----- C:\WINDOWS\PIF
2007-12-08 13:35 . 2007-02-28 17:04 2,137,600 --a------ C:\WINDOWS\system32\ntoskrnl.exe
2007-12-08 13:35 . 2007-02-28 17:04 2,137,600 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2007-12-07 17:20 . 2007-12-07 17:20 <DIR> d-------- C:\Program Files\SGJ
2007-12-07 17:20 . 2006-03-03 11:02 1,680,896 --a------ C:\WINDOWS\system32\vcl100.bpl
2007-12-07 17:20 . 2006-03-03 11:02 843,264 --a------ C:\WINDOWS\system32\rtl100.bpl
2007-12-07 17:20 . 2007-12-07 17:20 27 --a------ C:\WINDOWS\XTweaker.INI
2007-12-06 22:26 . 2007-12-06 22:26 <DIR> d-------- C:\Program Files\Windows Defender
2007-12-06 13:34 . 2007-12-06 13:34 <DIR> d-------- C:\Program Files\Thomson
2007-12-06 12:54 . 2004-06-11 04:14 396,800 -ra------ C:\WINDOWS\system32\NvRaidWizard.dll
2007-12-06 12:54 . 2004-06-11 04:15 244,224 -ra------ C:\WINDOWS\system32\NvRaidMan.exe
2007-12-06 12:54 . 2004-06-18 07:57 172,032 -ra------ C:\WINDOWS\system32\nvuide.exe
2007-12-06 12:54 . 2004-06-11 04:15 83,968 -ra------ C:\WINDOWS\system32\nvraidservice.exe
2007-12-06 12:54 . 2004-06-11 04:14 74,240 -ra------ C:\WINDOWS\system32\NvRaidWizardEnu.dll
2007-12-06 12:54 . 2004-06-03 03:40 68,224 -ra------ C:\WINDOWS\system32\drivers\nvraid.sys
2007-12-06 12:54 . 2004-06-11 04:14 20,480 -ra------ C:\WINDOWS\system32\NvRaidEnu.dll
2007-12-06 12:54 . 2004-06-03 03:40 18,432 --a------ C:\WINDOWS\system32\nvraidco.dll
2007-12-06 12:54 . 2004-06-11 04:15 6,144 -ra------ C:\WINDOWS\system32\NvRaidSvEnu.dll
2007-12-06 12:54 . 2004-06-17 19:30 464 -ra------ C:\WINDOWS\system32\nvide.nvu
2007-12-06 12:53 . 2004-06-03 03:40 294,400 -ra------ C:\WINDOWS\system32\idecoi.dll
2007-12-06 12:53 . 2004-06-03 03:40 79,360 -ra------ C:\WINDOWS\system32\drivers\nvatabus.sys
2007-12-06 12:52 . 2007-12-06 12:52 <DIR> d-------- C:\Program Files\Realtek AC97
2007-12-06 12:52 . 2001-07-05 17:19 164 -r------- C:\WINDOWS\avrack.ini
2007-12-06 12:51 . 2007-12-06 12:51 <DIR> d-------- C:\Program Files\AMD
2007-12-06 12:51 . 2005-03-09 15:53 43,008 --a------ C:\WINDOWS\system32\drivers\AmdK8.sys
2007-12-06 12:44 . 2007-12-06 12:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-06 12:26 . 2004-12-14 16:55 9,472 -ra------ C:\WINDOWS\system32\drivers\EIO.sys
2007-12-05 17:57 . 2007-12-08 16:05 139,296 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-05 17:57 . 2007-12-08 16:05 4,128 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-05 17:57 . 2007-12-08 16:05 3,752 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-05 17:57 . 2007-12-08 16:05 1,412 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-05 17:56 . 2007-12-05 17:56 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2007-12-05 17:36 . 2007-12-05 17:36 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-04 17:53 . 2007-12-05 18:10 <DIR> d-------- C:\Program Files\WinPcap
2007-12-04 17:52 . 2007-12-07 19:48 <DIR> d-------- C:\Program Files\WMR11
2007-12-04 17:42 . 2007-12-04 17:43 <DIR> d-------- C:\Program Files\Play65
2007-12-04 17:30 . 2007-12-04 17:30 <DIR> d-------- C:\Program Files\BlueSprite
2007-12-04 17:30 . 2001-01-14 02:16 176,128 --a------ C:\WINDOWS\system32\lame_dshow.ax
2007-12-04 17:30 . 2003-02-03 01:45 106,496 --a------ C:\WINDOWS\system32\FileDump.ax
2007-12-04 17:30 . 2003-02-03 01:45 73,728 --a------ C:\WINDOWS\system32\wavdest.ax
2007-12-04 17:29 . 2007-12-04 17:29 <DIR> d-------- C:\Documents and Settings\PC\WINDOWS
2007-12-04 17:29 . 1998-10-01 15:22 299,520 --a------ C:\WINDOWS\uninst.exe
2007-12-03 11:21 . 2007-12-03 11:51 249,856 --------- C:\WINDOWS\Setup1.exe
2007-12-03 11:21 . 2007-12-03 11:51 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2007-12-02 22:17 . 2007-12-02 22:17 <DIR> d-------- C:\Program Files\MarBit
2007-11-27 14:39 . 2007-11-27 14:39 0 --ah----- C:\WINDOWS\83914241
2007-11-27 11:25 . 2007-11-27 11:25 <DIR> d-------- C:\WINDOWS\Sun
2007-11-27 11:24 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-11-27 11:23 . 2007-11-27 11:24 <DIR> d-------- C:\Program Files\Java
2007-11-27 11:20 . 2007-11-27 11:20 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-27 10:31 . 2007-11-27 10:31 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-11-25 21:57 . 2003-12-22 08:20 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2007-11-24 17:19 . 2004-12-11 18:00 13,866 --a------ C:\Program Files\data.dat
2007-11-24 16:02 . 2007-11-24 16:02 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-11-23 21:52 . 2007-11-23 21:52 30,728 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-11-23 21:50 . 2007-11-23 21:50 33,800 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2007-11-23 21:50 . 2007-11-23 21:50 27,656 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2007-11-21 22:06 . 2007-11-21 22:07 <DIR> d-------- C:\Program Files\NewLive All Media To Mp3 Converter
2007-11-21 22:00 . 2003-05-12 20:25 503,808 --a------ C:\WINDOWS\system32\mpeg2dmx.ax
2007-11-21 22:00 . 2001-08-18 20:00 262,144 --a------ C:\WINDOWS\system32\mpg4ds32.axu
2007-11-21 22:00 . 2003-05-21 01:10 210,432 --a------ C:\WINDOWS\system32\mpgdec.ax
2007-11-21 22:00 . 2004-04-30 21:46 28,672 --a------ C:\WINDOWS\system32\t3odm.dll
2007-11-14 16:52 . 2007-11-14 16:52 <DIR> d-------- C:\Documents and Settings\PC\Dane aplikacji\Ashampoo Photo Commander 4
2007-11-14 16:43 . 2007-11-14 16:47 222 --a------ C:\WINDOWS\VOGEL.INI
2007-11-14 16:19 . 2007-11-14 16:19 804 --a------ C:\WINDOWS\unins001.dat
2007-11-10 22:21 . 2007-12-05 11:27 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Symantec
2007-11-09 22:00 . 2007-11-09 22:00 <DIR> dr------- C:\Documents and Settings\LocalService\Ulubione
2007-11-09 17:37 . 2007-11-09 17:37 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Grisoft
2007-11-09 16:47 . 2007-11-09 16:47 <DIR> d-------- C:\Program Files\Common Files\PC Tools
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-09 18:00 --------- d-----w C:\Program Files\eMule
2007-12-06 12:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-06 11:52 --------- d-----w C:\Program Files\AvRack
2007-12-05 10:29 --------- d-----w C:\Program Files\Nokia
2007-12-05 10:23 --------- d-----w C:\Program Files\Odkurzacz
2007-12-04 20:58 --------- d-----w C:\Documents and Settings\PC\Dane aplikacji\Skype
2007-12-02 19:18 --------- d-----w C:\Documents and Settings\PC\Dane aplikacji\Nokia Multimedia Player
2007-11-22 20:18 --------- d-----w C:\Program Files\Live_TV
2007-11-14 20:17 --------- d-----w C:\Program Files\Ashampoo
2007-11-05 14:54 --------- d-----w C:\Program Files\Google
2007-11-02 20:18 --------- d-----w C:\Documents and Settings\PC\Dane aplikacji\poleng
2007-11-02 20:16 --------- d-----w C:\Program Files\poleng
2007-10-29 17:34 --------- d-----w C:\Program Files\TubeMaster
2007-10-28 11:19 --------- d-----w C:\Program Files\JLC's Software
2007-10-28 11:19 --------- d-----w C:\Documents and Settings\PC\Dane aplikacji\JLC's Software
2007-10-21 20:10 --------- d-----w C:\Program Files\Real
2007-10-21 20:10 --------- d-----w C:\Program Files\Common Files\xing shared
2007-10-21 20:10 --------- d-----w C:\Program Files\Common Files\Real
2007-10-20 09:55 --------- d-----w C:\Program Files\DivX
2007-10-16 14:20 --------- d-----w C:\Documents and Settings\PC\Dane aplikacji\Ashampoo
2007-10-16 14:04 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ashampoo
2007-10-15 16:28 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\BufferZone
2007-10-14 13:14 --------- d-----w C:\Program Files\CCleaner
2007-10-14 12:00 --------- d-----w C:\Program Files\Common Files\PCSuite
2007-10-14 12:00 --------- d-----w C:\Program Files\Common Files\Nokia
2007-10-14 12:00 --------- d-----w C:\Documents and Settings\PC\Dane aplikacji\Nokia
2007-10-14 12:00 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\PC Suite
2007-10-14 11:59 --------- d-----w C:\Program Files\PC Connectivity Solution
2007-10-14 11:59 --------- d-----w C:\Program Files\DIFX
2007-10-14 11:59 --------- d-----w C:\Documents and Settings\PC\Dane aplikacji\PC Suite
2007-10-14 11:59 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Downloaded Installations
2007-10-14 11:50 --------- d-----w C:\Program Files\Mozilla ActiveX Control v1.7.1
2007-10-14 09:57 --------- d-----w C:\Documents and Settings\PC\Dane aplikacji\MegauploadToolbar
2007-10-14 09:42 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-10-11 19:29 --------- d-----w C:\Program Files\MegauploadToolbar
2007-10-10 18:24 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Adobe Systems
2007-09-26 18:03 98,304 ----a-w C:\WINDOWS\system32\qttask.exe
2007-09-25 12:56 71,609,184 ----a-w C:\162.18_forceware_winxp_international_whql.exe
2007-09-25 11:45 1,164,456 ----a-w C:\install_flash_player.exe
.
((((((((((((((((((((((((((((( snapshot@2007-12-09_12.43.43.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-11-21 10:14:20 32,768 ----a-w C:\WINDOWS\$hf_mig$\KB926247\SP2QFE\snmp.exe
+ 2005-10-12 23:21:28 16,096 ----a-w C:\WINDOWS\$hf_mig$\KB926247\spmsg.dll
+ 2005-10-12 23:21:30 216,288 ----a-w C:\WINDOWS\$hf_mig$\KB926247\spuninst.exe
+ 2005-10-12 23:21:27 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB926247\update\spcustom.dll
+ 2005-10-12 23:21:33 723,680 ----a-w C:\WINDOWS\$hf_mig$\KB926247\update\update.exe
+ 2005-10-12 23:21:40 386,784 ----a-w C:\WINDOWS\$hf_mig$\KB926247\update\updspapi.dll
+ 2007-12-09 11:53:39 10,134 ----a-r C:\WINDOWS\Installer\{7A39DABB-8519-4272-81AB-7186AEE2F88C}\callmsi.exe
+ 2007-12-09 11:53:39 136,448 ----a-r C:\WINDOWS\Installer\{7A39DABB-8519-4272-81AB-7186AEE2F88C}\egui.exe
- 2006-03-02 12:00:00 32,256 -c--a-w C:\WINDOWS\system32\dllcache\snmp.exe
+ 2006-11-21 10:26:48 32,768 -c--a-w C:\WINDOWS\system32\dllcache\snmp.exe
- 2006-03-02 12:00:00 32,256 ----a-w C:\WINDOWS\system32\snmp.exe
+ 2006-11-21 10:26:48 32,768 ----a-w C:\WINDOWS\system32\snmp.exe
+ 2007-12-09 19:40:49 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_500.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2006-03-02 13:00 C:\WINDOWS\system32\rundll32.exe]
"NvMediaCenter"="RUNDLL32.exe" [2006-03-02 13:00 C:\WINDOWS\system32\rundll32.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 21:10]
"SoundMan"="SOUNDMAN.EXE" [2005-06-20 14:42 C:\WINDOWS\soundman.exe]
"NVRaidService"="C:\WINDOWS\system32\nvraidservice.exe" [2004-06-11 04:15]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-03-23 12:06]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-11-23 21:51]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 18:19]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 13:00]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 16:15]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoShellSearchButton"= 0 (0x0)
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys
R2 ekrn;Eset Service;"C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"
S3 EhttpSrv;Eset HTTP Server;"C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe"
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-12-09 19:43:51 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-12-09 20:44:41
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-09 20:45:16
C:\ComboFix2.txt ... 2007-12-09 12:44
.
--- E O F ---