
Wrzucam log z ComboFixa.
Prosze o pomoc.
- Kod: Zaznacz wszystko
ComboFix 08-05-15.3 - Michael 2008-05-18 20:41:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.601 [GMT 2:00]
Running from: C:\Documents and Settings\Michael\Pulpit\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\All Users\Menu Start\UUSEE~1.LNK
C:\Documents and Settings\Ewelina.SUPERPIPPO\Menu Start\XP Antivirus 2008
C:\Documents and Settings\Ewelina.SUPERPIPPO\Menu Start\XP Antivirus 2008\Uninstall XP Antivirus 2008.lnk
C:\Documents and Settings\Ewelina.SUPERPIPPO\Menu Start\XP Antivirus 2008\XP Antivirus 2008.lnk
C:\Documents and Settings\Ewelina.SUPERPIPPO\Pulpit\Error Cleaner.url
C:\Documents and Settings\Ewelina.SUPERPIPPO\Pulpit\Privacy Protector.url
C:\Documents and Settings\Ewelina.SUPERPIPPO\Pulpit\Spyware&Malware Protection.url
C:\Documents and Settings\Ewelina.SUPERPIPPO\Ulubione\Error Cleaner.url
C:\Documents and Settings\Ewelina.SUPERPIPPO\Ulubione\Privacy Protector.url
C:\Documents and Settings\Ewelina.SUPERPIPPO\Ulubione\Spyware&Malware Protection.url
C:\Program Files\PlayMP3z
C:\Program Files\PlayMP3z\uninstall.exe
C:\Program Files\uusee
C:\Program Files\uusee\AD\1\[u]0[/u]00\index_new.html
C:\Program Files\uusee\AD\1\[u]0[/u]00\uue_new.jpg
C:\Program Files\uusee\AD\1\[u]0[/u]01\index_new.html
C:\Program Files\uusee\AD\1\[u]0[/u]01\uue_new.jpg
C:\Program Files\uusee\AD\1\cy\cy.html
C:\Program Files\uusee\AD\1\dm\dm.html
C:\Program Files\uusee\AD\1\dy\dy.html
C:\Program Files\uusee\AD\1\gp\gp.html
C:\Program Files\uusee\AD\1\jk\jk.html
C:\Program Files\uusee\AD\1\ty\ty.html
C:\Program Files\uusee\AD\1\uu\uu.html
C:\Program Files\uusee\AD\1\yl\yl.html
C:\Program Files\uusee\AD\1\yx\yx.html
C:\Program Files\uusee\AD\1\zx\zx.html
C:\Program Files\uusee\AD\UUAD.xml.zip
C:\Program Files\uusee\AD\UUAD_Banner.gif
C:\Program Files\uusee\AD\UUAD_Banner.html
C:\Program Files\uusee\AD\UUAD_Banner_1.html
C:\Program Files\uusee\AD\UUAD_Banner_3.html
C:\Program Files\uusee\AD\UUAD_Buffering.html
C:\Program Files\uusee\AD\UUAD_Buffering.jpg
C:\Program Files\uusee\AD\UUAD_TextLink_0.xml
C:\Program Files\uusee\bass-plugins.exe
C:\Program Files\uusee\channelid_chatid.txt
C:\Program Files\uusee\skins\UUPlayer\About.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_Compact_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_Compact_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_Compact_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_FullScreen_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_FullScreen_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_FullScreen_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_pause_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_pause_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_pause_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_pause_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_Recording_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_Recording_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Control_Button_Recording_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_CheckBox_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_CheckBox_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_CheckBox_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_CheckBox_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_CheckBox_C1.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_CheckBox_C2.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_CheckBox_C3.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_CheckBox_C4.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_ComboBox_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_ComboBox_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_ComboBox_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_ComboBox_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_Edit_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_Edit_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_PushButton_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_PushButton_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_PushButton_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_PushButton_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_RadioButton_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_RadioButton_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_RadioButton_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_RadioButton_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_RadioButton_C1.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_RadioButton_C2.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_RadioButton_C3.bmp
C:\Program Files\uusee\skins\UUPlayer\Ctrl_RadioButton_C4.bmp
C:\Program Files\uusee\skins\UUPlayer\Dlg_Back.bmp
C:\Program Files\uusee\skins\UUPlayer\Dlg_Detect.bmp
C:\Program Files\uusee\skins\UUPlayer\Dlg_Frame_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Dlg_Frame_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Dlg_Frame_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Dlg_Record_Task_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Icon_Information.bmp
C:\Program Files\uusee\skins\UUPlayer\Icon_Question.bmp
C:\Program Files\uusee\skins\UUPlayer\Icon_Stop.bmp
C:\Program Files\uusee\skins\UUPlayer\ListHeader_1.bmp
C:\Program Files\uusee\skins\UUPlayer\ListHeader_2.bmp
C:\Program Files\uusee\skins\UUPlayer\ListHeader_3.bmp
C:\Program Files\uusee\skins\UUPlayer\ListHeader_ArrowD.bmp
C:\Program Files\uusee\skins\UUPlayer\ListHeader_ArrowU.bmp
C:\Program Files\uusee\skins\UUPlayer\ListHeader_SP.bmp
C:\Program Files\uusee\skins\UUPlayer\Play_Window_Rec_icon.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_Block_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_Block_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_Block_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_Block_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_BM_0.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_BM_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_BM_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_BM_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_BM_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_BM_5.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_BM_6.bmp
C:\Program Files\uusee\skins\UUPlayer\Progressbar_BM_7.bmp
C:\Program Files\uusee\skins\UUPlayer\Resource.h
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_1_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_1_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_1_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_2_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_2_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_2_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_3_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_3_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_3_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_4_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_4_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Setting_Group_4_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Button_1_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Button_1_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Button_1_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Group_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Group_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Group_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Group_x1.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Group_x2.bmp
C:\Program Files\uusee\skins\UUPlayer\Sidebar_Group_x3.bmp
C:\Program Files\uusee\skins\UUPlayer\Thumbs.db
C:\Program Files\uusee\skins\UUPlayer\Titlebar_button_Res_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Titlebar_button_Res_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Titlebar_button_Res_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_Compact_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_Compact_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_Compact_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_FullScreen_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_FullScreen_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_FullScreen_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_TopMost_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_TopMost_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Toolbar_Button_TopMost_3.bmp
C:\Program Files\uusee\skins\UUPlayer\TopTab_Browse.bmp
C:\Program Files\uusee\skins\UUPlayer\TopTab_Browse1.bmp
C:\Program Files\uusee\skins\UUPlayer\TopTab_Play.bmp
C:\Program Files\uusee\skins\UUPlayer\TopTab_Play1.bmp
C:\Program Files\uusee\skins\UUPlayer\TopTab_Record.bmp
C:\Program Files\uusee\skins\UUPlayer\TopTab_Record1.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_Arrow.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_Collapse.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_Expand.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_Header.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_ScrollBar_D.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_ScrollBar_H.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_ScrollBar_N.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_ScrollBar_S.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_ScrollBarThumb_D.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_ScrollBarThumb_H.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_ScrollBarThumb_N.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_ScrollBarThumb_S.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_SortIconDown.bmp
C:\Program Files\uusee\skins\UUPlayer\Tree_SortIconUp.bmp
C:\Program Files\uusee\skins\UUPlayer\UUSEE.ui
C:\Program Files\uusee\skins\UUPlayer\Volume_Bar_Block_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Volume_Bar_Block_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Volume_Bar_Block_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Volume_Button_2_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Volume_Button_2_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Volume_Button_2_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Browser_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Browser_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Browser_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_ChannelInfo.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_ChannelInfo_5.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Control_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Control_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Control_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Control_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Info.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Main_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Main_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Main_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Main_5.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Play_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Play_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Play_5.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Record_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Record_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Record_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Record_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Setting_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Setting_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Setting_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Side_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Side_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Side_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Toolbar_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Toolbar_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Toolbar_3.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Toolbar_4.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Top_1.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Top_2.bmp
C:\Program Files\uusee\skins\UUPlayer\Wnd_Top_3.bmp
C:\Program Files\uusee\uninstuusee.exe
C:\Program Files\uusee\UUPlayer.dll
C:\Program Files\uusee\UUPlayer_update.ini
C:\Program Files\uusee\UUSee.url
C:\Program Files\uusee\UUSeePlayer.exe
C:\Program Files\uusee\UUTV_Chat.xml
C:\Program Files\uusee\UUTV_MY.xml
C:\Program Files\uusee\UUTV_UUPlayer.xml
C:\Program Files\XP Antivirus
C:\Program Files\XP Antivirus\xpa.exe
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\acsobelu.ini
C:\WINDOWS\system32\ajdntcqg.ini
C:\WINDOWS\system32\ftsfmemq.ini
C:\WINDOWS\system32\jvswcpry.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\UBLlkUtv.ini
C:\WINDOWS\system32\UBLlkUtv.ini2
C:\WINDOWS\system32\vtUklLBU.dll
----- BITS: Possible infected sites -----
hxxp://77.91.228.188
hxxp://82.103.137.14
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_IPRIP
-------\Service_6to4
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-04-18 to 2008-05-18 )))))))))))))))))))))))))))))))
.
2008-05-18 20:48 . 2008-05-18 20:48 294 ---hs---- C:\WINDOWS\system32\ajdntcqg.ini
2008-05-18 19:46 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-18 19:46 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-18 19:46 . 2008-05-15 23:22 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-18 19:46 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-18 19:46 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-18 19:46 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-18 19:46 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-18 19:46 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-17 23:28 . 2008-05-18 19:46 3,480 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-17 16:33 . 2008-05-18 19:49 <DIR> d-------- C:\SmitfraudFix
2008-05-17 16:33 . 2008-05-17 16:33 1,326,512 --a------ C:\SmitfraudFix.zip
2008-05-17 13:52 . 2008-05-17 01:58 172,032 --a------ C:\WINDOWS\emxa.exe
2008-05-17 11:20 . 2008-05-17 11:20 91,264 --a------ C:\WINDOWS\system32\gqctndja.dll
2008-05-16 21:33 . 2008-05-16 21:33 <DIR> d-------- C:\Documents and Settings\Ewelina.SUPERPIPPO\Dane aplikacji\Gadu-Gadu
2008-05-16 21:23 . 2008-05-16 21:23 77,613 --a------ C:\WINDOWS\system32\scui.cpl
2008-05-16 21:16 . 2008-05-16 21:31 <DIR> d-------- C:\Documents and Settings\Ewelina.SUPERPIPPO\Dane aplikacji\TmpRecentIcons
2008-05-16 15:47 . 2008-05-17 18:33 <DIR> d-------- C:\Program Files\BurstWriting
2008-05-16 15:46 . 2008-05-16 15:46 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Adsl Software Limited
2008-05-16 13:52 . 2008-05-16 02:03 159,744 --a------ C:\WINDOWS\exnk.exe
2008-05-15 20:57 . 2008-05-15 20:57 <DIR> d-------- C:\Documents and Settings\Michael\Dane aplikacji\Gadu-Gadu
2008-05-15 20:54 . 2008-05-15 20:54 91,264 --a------ C:\WINDOWS\system32\qmemfstf.dll
2008-05-15 20:46 . 2008-05-15 20:46 <DIR> d-------- C:\Program Files\Common Files\OczyszczaczKomputerza
2008-05-15 19:50 . 2008-05-15 19:50 <DIR> d-------- C:\WINDOWS\system32\AlertModule
2008-05-15 19:50 . 2004-08-23 13:49 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
2008-05-15 19:50 . 2005-10-06 14:55 36,864 --a------ C:\WINDOWS\system32\IfHelper.dll
2008-05-15 18:56 . 2001-10-26 19:29 18,944 --a------ C:\WINDOWS\system32\simptcp.dll
2008-05-15 18:56 . 2001-10-26 19:29 18,944 --a------ C:\WINDOWS\system32\dllcache\simptcp.dll
2008-05-15 13:41 . 2008-05-15 13:41 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-05-15 12:33 . 2008-05-15 12:33 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-05-15 05:08 . 2008-05-15 05:08 <DIR> d-------- C:\Documents and Settings\Michael\Dane aplikacji\TmpRecentIcons
2008-05-14 22:23 . 2008-05-15 19:51 1,426 ---hs---- C:\WINDOWS\system32\mqjlumem.ini
2008-05-14 22:16 . 2008-05-17 01:57 290,816 --a------ C:\WINDOWS\mpfanvqg.dll
2008-05-14 22:16 . 2008-05-17 01:59 94,208 --a------ C:\WINDOWS\oadkxrts.exe
2008-05-14 22:16 . 2008-05-14 19:10 94,208 --a------ C:\WINDOWS\emtd.exe
2008-05-14 22:16 . 2008-05-14 22:16 29,824 --a------ C:\WINDOWS\system32\urqQjhEx.dll
2008-05-13 16:30 . 2008-05-13 16:30 <DIR> d-------- C:\games
2008-05-12 15:10 . 2008-05-12 15:10 0 --a------ C:\10.1.19.109
2008-05-04 23:11 . 2008-05-04 23:11 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Sony Ericsson
2008-05-04 23:10 . 2008-05-04 23:10 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-05-04 23:10 . 2008-05-04 23:10 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-05-04 23:10 . 2008-05-04 23:11 <DIR> d-------- C:\Program Files\Common Files\Sony Ericsson Shared
2008-05-04 23:10 . 2008-05-04 23:11 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Teleca
2008-04-22 21:34 . 2008-04-22 21:34 <DIR> d-------- C:\Documents and Settings\Ewelina.SUPERPIPPO\Dane aplikacji\Teleca
2008-04-22 21:25 . 2008-04-22 21:25 <DIR> d-------- C:\Documents and Settings\Ewelina.SUPERPIPPO\Dane aplikacji\Sony Ericsson
2008-04-22 20:21 . 2008-04-22 20:21 <DIR> d-------- C:\Documents and Settings\Michael\Dane aplikacji\Teleca
2008-04-22 20:20 . 2008-04-22 20:20 <DIR> d-------- C:\Documents and Settings\Michael\Dane aplikacji\Sony Ericsson
2008-04-22 20:18 . 2008-05-04 23:13 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-04-22 20:17 . 2008-05-05 09:29 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2008-04-22 20:08 . 2008-04-22 20:09 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-04-22 20:04 . 2006-09-13 18:18 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-22 20:04 . 2006-09-13 18:18 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-18 21:27 . 2008-04-18 21:27 <DIR> d-------- C:\Program Files\Canada Poker
2008-04-18 10:14 . 2008-04-18 10:14 4 --a------ C:\WINDOWS\system32\proc1795523372.bin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-18 18:48 --------- d-----w C:\Program Files\neostrada tp
2008-05-18 18:48 --------- d-----w C:\Documents and Settings\Michael\Dane aplikacji\OpenOffice.org2
2008-05-18 06:58 --------- d-----w C:\Program Files\BrowsingSoftware
2008-05-16 19:41 --------- d-----w C:\Documents and Settings\Ewelina.SUPERPIPPO\Dane aplikacji\OpenOffice.org2
2008-05-15 18:56 --------- d-----w C:\Program Files\Gadu-Gadu
2008-05-15 11:43 --------- d-----w C:\Program Files\Alwil Software
2008-05-14 20:30 --------- d-----w C:\Documents and Settings\Michael\Dane aplikacji\GanymedeNet
2008-05-09 14:43 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spadester
2008-05-04 16:53 --------- d-----w C:\Program Files\SunPoker.com
2008-05-04 16:23 --------- d-----w C:\Program Files\PokerStars
2008-05-03 15:58 --------- d-----w C:\Documents and Settings\Michael\Dane aplikacji\Microgaming
2008-04-30 20:23 --------- d-----w C:\Program Files\CarbonPoker
2008-04-18 18:58 --------- d-----w C:\Program Files\Everest Poker
2008-04-18 18:56 --------- d-----w C:\Program Files\WalkerPoker
2008-04-18 07:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-17 22:33 --------- d-----w C:\Program Files\TP
2008-04-17 11:06 --------- d-----w C:\Program Files\Axxo Poker
2008-04-17 11:02 --------- d-----w C:\Program Files\Poker Royale
2008-04-15 13:40 --------- d-----w C:\Program Files\Ace Venue
2008-04-09 17:14 --------- d-----w C:\Program Files\PokerRoom.com
2008-04-07 08:22 --------- d-----w C:\Program Files\MGS FF Helper
2008-04-06 16:08 --------- d-----w C:\Program Files\G2GPoker
2008-04-05 16:27 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\microgaming
2008-04-03 12:28 --------- d-----w C:\Program Files\SubEdit-Player
2008-04-01 11:43 --------- d-----w C:\Documents and Settings\Michael\Dane aplikacji\Ankh
2008-03-31 08:08 --------- d-----w C:\Program Files\FMA 2
2008-03-29 14:51 --------- d-----w C:\Program Files\Palace of Chance
2008-03-28 14:25 --------- d-----w C:\Program Files\Betway
2008-03-26 09:31 --------- d-----w C:\Program Files\Audacity
2008-03-25 17:09 --------- d-----w C:\Program Files\VIP Lounge
2008-03-25 17:07 --------- d-----w C:\Program Files\Absolute Poker
2008-03-24 18:48 --------- d-----w C:\Documents and Settings\Ewelina.SUPERPIPPO\Dane aplikacji\FMA
2008-03-24 16:21 --------- d-----w C:\Documents and Settings\Michael\Dane aplikacji\FMA
2008-03-20 16:48 --------- d-----w C:\Program Files\VIA
2008-03-20 16:48 --------- d-----w C:\Program Files\Common Files\InstallShield
2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06DF596B-3170-4F07-BE10-86E31456BC56}]
2008-05-14 22:16 29824 --a------ C:\WINDOWS\system32\urqQjhEx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18CB1A7B-94CD-4582-8022-ADA16851E44B}]
2008-03-27 14:57 247296 --a------ C:\Program Files\BurstWriting\BurstWriting.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B886C1F4-D1D3-45F5-F45E-75EB024320AC}]
2007-12-30 22:48 1019904 --a------ C:\Program Files\BrowsingSoftware\BrowsingSoftware-1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:44 15360]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 13:24 167368]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 12:04 2127296]
"WinSpywareProtect (ver. 5.1)"="C:\Documents and Settings\All Users\Dane aplikacji\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe" [2008-05-16 15:47 1338880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="C:\WINDOWS\htpatch.exe" [2002-10-30 11:40 28672]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 12:15 106496]
"Cmaudio"="cmicnfg.cpl" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-05-25 23:02 6746112]
"nwiz"="nwiz.exe" [2005-05-25 23:02 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-05-25 23:02 86016]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"BootSkin Startup Jobs"="C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 17:21 270336]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 13:06 40048]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [ ]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 01:06 487424]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 13:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\GestMaj.exe" [2004-10-14 15:55 32768]
"8c56754f"="C:\WINDOWS\system32\gqctndja.dll" [2008-05-17 11:20 91264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 02:44 15360]
C:\Documents and Settings\Ewelina.FORZAMILAN\Menu Start\Programy\Autostart\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 23:57:56 393216]
C:\Documents and Settings\Ewelina.SUPERPIPPO\Menu Start\Programy\Autostart\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 23:57:56 393216]
C:\Documents and Settings\Michael\Menu Start\Programy\Autostart\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 23:57:56 393216]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{06DF596B-3170-4F07-BE10-86E31456BC56}"= C:\WINDOWS\system32\urqQjhEx.dll [2008-05-14 22:16 29824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"mpfanvqg"= {95778FA4-94CA-4F44-8E13-7301F247DA29} - C:\WINDOWS\mpfanvqg.dll [2008-05-17 01:57 290816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqQjhEx]
urqQjhEx.dll 2008-05-14 22:16 29824 C:\WINDOWS\system32\urqQjhEx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\PPMate\\ppmate.exe"=
"C:\\Program Files\\Internet\\PCast\\PCast.exe"=
"C:\\Program Files\\PPMate\\ppmnet.exe"=
"C:\\Program Files\\IBP 9\\IBP.exe"=
"C:\\Program Files\\Windows Media Components\\Encoder\\wmenc.exe"=
"C:\\Program Files\\Windows Media Components\\Encoder\\wmstreamedt.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\Polish\\setup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Grupowanie sieci równorzędnej Windows
"3540:UDP"= 3540:UDP:Protokół rozpoznawania nazw równorzędnych (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-09-19 12:03]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-09-15 12:07]
S3 p2pgasvc;Uwierzytelnianie grup sieci równorzędnej;C:\WINDOWS\system32\svchost.exe [2004-08-04 02:44]
S3 p2pimsvc;Menedżer tożsamości sieci równorzędnej;C:\WINDOWS\system32\svchost.exe [2004-08-04 02:44]
S3 p2psvc;Sieć równorzędna;C:\WINDOWS\system32\svchost.exe [2004-08-04 02:44]
S3 PNRPSvc;Protokół PNRP (Peer Name Resolution Protocol);C:\WINDOWS\system32\svchost.exe [2004-08-04 02:44]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-09-13 19:19]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-18 20:48:46
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\urqQjhEx.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\gqctndja.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\NEOSTR~1\TaskBarIcon.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\File Manager\SendToDevice.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Completion time: 2008-05-18 20:57:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-18 18:56:51
ComboFix2.txt 2007-12-26 19:54:55
Pre-Run: 751,513,600 bajtów wolnych
Post-Run: 714,825,728 bajt˘w wolnych
448