
- Kod: Zaznacz wszystko
"a123" - 2007-07-26 15:06:32 - ComboFix 07-07-23.6 - Dodatek Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\drivers\runtime2.sys
((((((((((((((((((((((((( Files Created from 2007-06-26 to 2007-07-26 )))))))))))))))))))))))))))))))
2007-07-26 14:26 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-26 14:16 5,022 --a------ C:\dnsbak.reg
2007-07-26 14:02 <DIR> d-------- C:\WINDOWS\pss
2007-07-24 13:27 <DIR> d-------- C:\KAV
2007-07-24 13:23 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-07-24 13:23 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-24 13:23 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-24 13:23 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-24 13:23 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-24 13:23 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-24 13:23 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-24 12:54 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\DANEAP~1\TEMP
2007-07-18 21:19 <DIR> d-------- C:\winnt
2007-07-18 21:18 <DIR> d-------- C:\apache
2007-07-18 08:52 <DIR> d-------- C:\DOCUME~1\a123\DANEAP~1\Gadu-Gadu
2007-07-18 08:49 <DIR> d-------- C:\Program Files\Gadu-Gadu
2007-07-18 08:49 <DIR> d-------- C:\DOCUME~1\a123\Gadu-Gadu
2007-07-12 16:30 <DIR> d-------- C:\Program Files\Common Files\DirectX
2007-07-12 15:53 <DIR> d-------- C:\Program Files\PowerISO
2007-07-11 20:21 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-07-11 20:21 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-07-11 20:21 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-07-11 20:21 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-07-11 20:21 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2007-07-11 20:21 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2007-07-11 20:21 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-07-11 20:21 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2007-07-11 20:21 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2007-07-10 18:39 3,972 --a------ C:\WINDOWS\system32\drivers\PciBus.sys
2007-07-10 18:39 20,400 --a------ C:\WINDOWS\system32\drivers\Entech.sys
2007-07-10 18:39 <DIR> d-------- C:\WINDOWS\system32\Futuremark
2007-07-10 18:39 <DIR> d-------- C:\Program Files\Futuremark
2007-07-05 20:43 <DIR> d-------- C:\Nowe
2007-06-30 18:20 <DIR> d-------- C:\Filmy
2007-06-30 13:54 65,109 --a------ C:\WINDOWS\BricoPackUninst.cmd
2007-06-30 13:53 6,112 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-06-30 13:53 <DIR> d-------- C:\WINDOWS\BricoPacks
2007-06-30 13:51 <DIR> dr-hs---- C:\Recycled
2007-06-28 22:47 28,672 --a------ C:\WINDOWS\system32\SockModule.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-26 13:13:30 648 ----a-w C:\WINDOWS\system32\msdtmuiu.dat
2007-07-26 13:13:30 5,093 ----a-w C:\WINDOWS\system32\powrpryf.dat
2007-07-26 13:13:30 16,601 ----a-w C:\WINDOWS\system32\wzcdogx.dat
2007-07-26 13:13:30 0 ----a-w C:\WINDOWS\system32\wmvdmje2.dat
2007-07-26 13:12:33 504 ----a-w C:\WINDOWS\system32\msratiog.dat
2007-07-26 13:12:33 42,094 ----a-w C:\WINDOWS\system32\a3dF.dat
2007-07-26 13:12:33 3,709 ----a-w C:\WINDOWS\system32\ifmomwor.dat
2007-07-26 13:12:27 0 ----a-w C:\WINDOWS\system32\duseucw.dat
2007-07-26 12:29:57 -------- d-----w C:\Program Files\eMule
2007-07-26 12:05:19 371 ----a-w C:\WINDOWS\system32\securitk.dat
2007-07-24 13:05:06 -------- d-----w C:\DOCUME~1\a123\DANEAP~1\Skype
2007-07-24 11:17:58 -------- d-----w C:\Program Files\SubEdit-Player
2007-07-23 18:25:33 9,216 --s-a-w C:\WINDOWS\system32\wzhtjqo.dll
2007-07-19 17:10:38 -------- d-----w C:\Program Files\Cartall
2007-07-18 06:12:43 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-12 14:27:49 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-07-08 16:43:12 -------- d-----w C:\Program Files\Webteh
2007-06-30 11:55:52 -------- d-----w C:\Program Files\Movie Maker
2007-06-30 11:54:55 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-06-29 12:49:10 -------- d-----w C:\DOCUME~1\a123\DANEAP~1\Real
2007-06-17 15:22:45 4,096 ----a-w C:\WINDOWS\system32\popupapap5.dll
2007-06-17 15:04:39 4,096 ----a-w C:\WINDOWS\system32\popupapap3.dll
2007-06-17 14:54:41 -------- d-----w C:\DOCUME~1\a123\DANEAP~1\Media Player Classic
2007-06-17 14:49:51 -------- d-----w C:\Program Files\PowerQuest
2007-06-17 14:46:33 4,096 ----a-w C:\WINDOWS\system32\popupapap1.dll
2007-06-17 14:45:57 -------- d-----w C:\Program Files\K-Lite Codec Pack
2007-06-17 14:45:23 -------- d-----w C:\DOCUME~1\a123\DANEAP~1\Vso
2007-06-17 14:45:17 87,608 ----a-w C:\DOCUME~1\a123\DANEAP~1\inst.exe
2007-06-17 14:45:17 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2007-06-17 14:45:17 47,360 ----a-w C:\DOCUME~1\a123\DANEAP~1\pcouffin.sys
2007-06-17 14:45:17 -------- d-----w C:\Program Files\DVDFab Platinum 3
2007-06-17 14:43:32 -------- d-----w C:\Program Files\DAEMON Tools
2007-06-17 14:42:13 682,232 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-06-17 14:29:45 -------- d-----w C:\Program Files\EVEREST Ultimate Edition
2007-05-11 04:37:16 740,442 ----a-w C:\WINDOWS\system32\divx.dll
2007-05-08 18:23:10 10,752 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-05-02 18:04:20 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-05-02 18:02:08 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-04-28 12:54:36 593,920 ----a-w C:\WINDOWS\system32\xvidcore.dll
2007-04-27 18:59:08 4,096 ----a-w C:\WINDOWS\system32\popupapap1027.dll
2007-04-27 18:44:01 4,096 ----a-w C:\WINDOWS\system32\popupapap1025.dll
2007-04-27 18:28:53 4,096 ----a-w C:\WINDOWS\system32\popupapap1023.dll
2007-04-27 18:13:45 4,096 ----a-w C:\WINDOWS\system32\popupapap1021.dll
2007-04-27 17:58:36 4,096 ----a-w C:\WINDOWS\system32\popupapap1019.dll
2007-04-27 17:43:29 4,096 ----a-w C:\WINDOWS\system32\popupapap1017.dll
2007-04-27 17:28:21 4,096 ----a-w C:\WINDOWS\system32\popupapap1015.dll
2007-04-27 17:13:11 4,096 ----a-w C:\WINDOWS\system32\popupapap1013.dll
2007-04-27 16:58:04 4,096 ----a-w C:\WINDOWS\system32\popupapap1011.dll
2007-04-27 16:42:57 4,096 ----a-w C:\WINDOWS\system32\popupapap1009.dll
2007-04-27 16:27:49 4,096 ----a-w C:\WINDOWS\system32\popupapap1007.dll
2007-04-27 16:12:41 4,096 ----a-w C:\WINDOWS\system32\popupapap1005.dll
2007-04-27 15:57:34 4,096 ----a-w C:\WINDOWS\system32\popupapap1003.dll
2007-04-27 15:42:27 4,096 ----a-w C:\WINDOWS\system32\popupapap1001.dll
2007-04-27 15:27:19 4,096 ----a-w C:\WINDOWS\system32\popupapap999.dll
2007-04-27 15:12:11 4,096 ----a-w C:\WINDOWS\system32\popupapap997.dll
2007-04-27 14:57:04 4,096 ----a-w C:\WINDOWS\system32\popupapap995.dll
2007-04-27 14:41:56 4,096 ----a-w C:\WINDOWS\system32\popupapap993.dll
2007-04-27 14:26:49 4,096 ----a-w C:\WINDOWS\system32\popupapap991.dll
2007-04-27 14:11:39 4,096 ----a-w C:\WINDOWS\system32\popupapap989.dll
2007-04-27 13:56:32 4,096 ----a-w C:\WINDOWS\system32\popupapap987.dll
2007-04-27 13:41:24 4,096 ----a-w C:\WINDOWS\system32\popupapap985.dll
2007-04-27 13:26:17 4,096 ----a-w C:\WINDOWS\system32\popupapap983.dll
2007-04-27 13:11:09 4,096 ----a-w C:\WINDOWS\system32\popupapap981.dll
2007-04-27 12:56:01 4,096 ----a-w C:\WINDOWS\system32\popupapap979.dll
2007-04-27 12:40:48 4,096 ----a-w C:\WINDOWS\system32\popupapap977.dll
2007-04-27 12:25:41 4,096 ----a-w C:\WINDOWS\system32\popupapap975.dll
2007-04-27 12:10:28 4,096 ----a-w C:\WINDOWS\system32\popupapap973.dll
2007-04-27 11:55:16 4,096 ----a-w C:\WINDOWS\system32\popupapap971.dll
2007-04-27 11:40:08 4,096 ----a-w C:\WINDOWS\system32\popupapap969.dll
2007-04-27 11:24:56 4,096 ----a-w C:\WINDOWS\system32\popupapap967.dll
2007-04-27 11:09:49 4,096 ----a-w C:\WINDOWS\system32\popupapap965.dll
2007-04-27 10:54:42 4,096 ----a-w C:\WINDOWS\system32\popupapap963.dll
2007-04-27 10:39:30 4,096 ----a-w C:\WINDOWS\system32\popupapap961.dll
2007-04-27 10:24:23 4,096 ----a-w C:\WINDOWS\system32\popupapap959.dll
2007-04-27 10:09:16 4,096 ----a-w C:\WINDOWS\system32\popupapap957.dll
2007-04-27 09:54:08 4,096 ----a-w C:\WINDOWS\system32\popupapap955.dll
2007-04-27 09:39:01 4,096 ----a-w C:\WINDOWS\system32\popupapap953.dll
2007-04-27 09:23:54 4,096 ----a-w C:\WINDOWS\system32\popupapap951.dll
2007-04-27 09:08:47 4,096 ----a-w C:\WINDOWS\system32\popupapap949.dll
2007-04-27 08:53:40 4,096 ----a-w C:\WINDOWS\system32\popupapap947.dll
2007-04-27 08:38:32 4,096 ----a-w C:\WINDOWS\system32\popupapap945.dll
2007-04-27 08:23:25 4,096 ----a-w C:\WINDOWS\system32\popupapap943.dll
2007-04-27 08:08:18 4,096 ----a-w C:\WINDOWS\system32\popupapap941.dll
2007-04-27 07:53:11 4,096 ----a-w C:\WINDOWS\system32\popupapap939.dll
2007-04-27 07:38:03 4,096 ----a-w C:\WINDOWS\system32\popupapap937.dll
2007-04-27 07:22:54 4,096 ----a-w C:\WINDOWS\system32\popupapap935.dll
2007-04-27 07:07:47 4,096 ----a-w C:\WINDOWS\system32\popupapap933.dll
2007-04-27 06:52:40 4,096 ----a-w C:\WINDOWS\system32\popupapap931.dll
2007-04-27 06:37:33 4,096 ----a-w C:\WINDOWS\system32\popupapap929.dll
2007-04-27 06:22:25 4,096 ----a-w C:\WINDOWS\system32\popupapap927.dll
2007-04-27 06:07:18 4,096 ----a-w C:\WINDOWS\system32\popupapap925.dll
2007-04-27 05:52:10 4,096 ----a-w C:\WINDOWS\system32\popupapap923.dll
2007-04-27 05:37:02 4,096 ----a-w C:\WINDOWS\system32\popupapap921.dll
2007-04-27 05:21:55 4,096 ----a-w C:\WINDOWS\system32\popupapap919.dll
2007-04-27 05:06:46 4,096 ----a-w C:\WINDOWS\system32\popupapap917.dll
2007-04-27 04:51:38 4,096 ----a-w C:\WINDOWS\system32\popupapap915.dll
2007-04-27 04:36:31 4,096 ----a-w C:\WINDOWS\system32\popupapap913.dll
2007-04-27 04:21:24 4,096 ----a-w C:\WINDOWS\system32\popupapap911.dll
2007-04-27 04:06:17 4,096 ----a-w C:\WINDOWS\system32\popupapap909.dll
2007-04-27 03:51:10 4,096 ----a-w C:\WINDOWS\system32\popupapap907.dll
2005-06-22 06:37:42 45,568 --sha-r C:\WINDOWS\system32\cygz.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 04:07]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 09:19]
"nwiz"="nwiz.exe" [2007-03-22 04:50 C:\WINDOWS\system32\nwiz.exe]
"Resume copy"="copyfstq.exe" [2002-03-24 12:54 C:\WINDOWS\COPYFSTQ.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2006-10-05 16:31]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 22:57]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 11:09]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-11-21 19:38]
"Vistadrv"="C:\Program Files\Vista\systool\Vistadrive\vsdrv.exe" []
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 14:23]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-03-22 04:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [2006-06-23 19:00]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-04 00:29]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2006-09-14 16:15]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2006-11-15 22:30:15]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{aa6d4f53-4c8d-4549-84d2-02d584acc4e9}"= C:\WINDOWS\system32\wzhtjqo.dll [2007-07-23 20:25 9216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\arm32reg]
C:\Documents and Settings\All Users\Dokumenty\Settings\arm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVCHOST]
C:\WINDOWS\MDM.EXE
R1 AmdK8;Sterownik procesora AMD;C:\WINDOWS\system32\DRIVERS\AmdK8.sys
R1 PQNTDrv;PQNTDrv;C:\WINDOWS\system32\drivers\PQNTDrv.sys
R1 SCDEmu;SCDEmu;C:\WINDOWS\system32\drivers\SCDEmu.sys
R2 EIO;EIO;\??\C:\WINDOWS\system32\drivers\EIO.sys
R2 PHPGeekUtil;PHPGeekUtil;"c:\apache\APACHE.EXE" --ntservice
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service;C:\WINDOWS\system32\drivers\ADIHdAud.sys
R3 MTsensor;ATK0110 ACPI UTILITY;C:\WINDOWS\system32\DRIVERS\ASACPI.sys
R3 Pcouffin;VSO Software pcouffin;C:\WINDOWS\system32\Drivers\Pcouffin.sys
R3 SenFiltService;SenFilt Service;C:\WINDOWS\system32\drivers\Senfilt.sys
R3 vaxscsi;vaxscsi;C:\WINDOWS\system32\Drivers\vaxscsi.sys
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service;"C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe"
S3 odserv;Microsoft Office Diagnostics Service;"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-26 15:13:34
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-26 15:14:35 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-26 15:14
C:\ComboFix2.txt ... 2007-07-26 14:30
--- E O F ---
co z tym zrobić