SDFix: Version 1.126
Run by eMaNeTeWu on 2008-01-14 at 12:37
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\autorun.inf - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-14 12:42:02
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
IPC error: 2 Nie można odnaleźć określonego pliku.
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000000
"hdf12"=hex:ec,00,99,98,bc,8d,fa,27,f5,e0,60,fa,99,d7,a2,fa,1e,76,6b,42,50,..
"p0"="C:\Program Files\DAEMON Tools Pro\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,8a,c2,6a,b7,e9,a3,63,6f,9e,79,01,34,7a,b3,40,0f,ac,..
"hdf12"=hex:02,bc,af,0a,f4,3d,ee,f6,a4,2a,f2,89,c1,a9,0b,5b,33,73,69,78,f3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:68,c8,b9,f1,c3,4a,d0,e0,d9,1a,54,f7,a6,f2,8e,c2,b8,87,f8,53,36,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1]
"hdf12"=hex:81,a4,5a,3f,e3,4b,fa,28,b1,e1,8f,ba,dc,af,60,7f,2d,a2,23,02,37,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002]
"a0"=hex:20,01,00,00,aa,b9,5d,b7,73,7e,29,44,fe,dc,a1,7d,db,74,a8,66,8f,..
"hdf12"=hex:c2,de,b4,7d,28,c6,e9,6e,2c,d2,44,10,9e,36,47,24,ce,dd,1e,af,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0]
"hdf12"=hex:90,67,16,d6,e4,d5,9c,f5,9c,33,fb,71,b3,62,48,36,29,d1,91,df,81,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000000
"hdf12"=hex:ec,00,99,98,bc,8d,fa,27,f5,e0,60,fa,99,d7,a2,fa,1e,76,6b,42,50,..
"p0"="C:\Program Files\DAEMON Tools Pro\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,8a,c2,6a,b7,e9,a3,63,6f,9e,79,01,34,7a,b3,40,0f,ac,..
"hdf12"=hex:02,bc,af,0a,f4,3d,ee,f6,a4,2a,f2,89,c1,a9,0b,5b,33,73,69,78,f3,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:68,c8,b9,f1,c3,4a,d0,e0,d9,1a,54,f7,a6,f2,8e,c2,b8,87,f8,53,36,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1]
"hdf12"=hex:81,a4,5a,3f,e3,4b,fa,28,b1,e1,8f,ba,dc,af,60,7f,2d,a2,23,02,37,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002]
"a0"=hex:20,01,00,00,aa,b9,5d,b7,73,7e,29,44,fe,dc,a1,7d,db,74,a8,66,8f,..
"hdf12"=hex:c2,de,b4,7d,28,c6,e9,6e,2c,d2,44,10,9e,36,47,24,ce,dd,1e,af,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000002\gdq0]
"hdf12"=hex:90,67,16,d6,e4,d5,9c,f5,9c,33,fb,71,b3,62,48,36,29,d1,91,df,81,..
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3A021C0E-1DF5-5426-272F-A124D7BEB6F8}]
"iacafdjdlmnbemhpfd"=hex:6b,61,67,64,6a,62,70,64,6d,65,64,69,6f,6b,6d,61,6c,6f,6f,6f,63,..
"hamalbeefekhgpcp"=hex:6b,61,67,64,6a,62,70,64,6d,65,64,69,6f,6b,6d,61,6c,6f,6f,6f,63,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Mon 6 Aug 2007 16,945 ..SH. --- "C:\PegeFile.pif"
Mon 6 Aug 2007 16,945 ..SH. --- "C:\Program Files\Internet Explorer\PLUGINS\NewTemp.bak"
Mon 14 Jan 2008 10,801 A.SH. --- "C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll"
Finished!
ComboFix 08-01-14.3 - eMaNeTeWu 2008-01-14 12:47:02.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1563 [GMT 1:00]
Running from: C:\Bin\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\iebhoset.ini
C:\WINDOWS\system32\ieset.ini
.
((((((((((((((((((((((((( Files Created from 2007-12-14 to 2008-01-14 )))))))))))))))))))))))))))))))
.
2008-01-14 12:36 . 2008-01-14 12:36 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-14 11:07 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 15:47 . 2008-01-13 16:03 <DIR> d-------- C:\Program Files\SkanerOnline
2008-01-13 11:15 . 2008-01-13 20:37 139 --a------ C:\WINDOWS\system32\wcbnurect.fl
2008-01-12 16:25 . 2008-01-12 16:25 <DIR> dr------- C:\Documents and Settings\NetworkService\Ulubione
2008-01-12 14:00 . 2008-01-13 11:12 1 --a------ C:\WINDOWS\ssopk.ids
2008-01-12 11:33 . 2008-01-12 12:52 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-01-12 09:23 . 2007-11-13 15:03 106,496 --a------ C:\WINDOWS\system32\abskey.dll
2008-01-12 09:21 . 2007-03-20 11:26 227 --a------ C:\WINDOWS\sosuo.col
2008-01-12 08:59 . 2008-01-12 08:59 <DIR> d-------- C:\WINDOWS\system32\conime
2008-01-12 08:59 . 2008-01-12 22:15 <DIR> d-------- C:\WINDOWS\ilovegoogle
2008-01-12 08:59 . 2008-01-12 08:59 32,256 --a------ C:\WINDOWS\system32\rxjh_2.exe
2008-01-12 08:59 . 2008-01-14 12:45 1,479 --a------ C:\WINDOWS\system32\feigou.ini
2008-01-12 08:58 . 2008-01-12 08:59 167,522 --a------ C:\WINDOWS\yeSetup.exe
2008-01-12 08:58 . 2008-01-12 11:37 1 --a------ C:\WINDOWS\lasdaybcuwee.tj
2008-01-12 08:29 . 2008-01-12 08:30 <DIR> d-------- C:\Program Files\Skype
2008-01-12 08:29 . 2008-01-12 08:29 584,192 --a------ C:\WINDOWS\system32\oeehquyakghmp.dll
2008-01-12 08:29 . 2008-01-12 08:29 58,496 --a------ C:\WINDOWS\system32\SkypeClient.exe
2008-01-12 08:29 . 2008-01-12 16:28 180 --a------ C:\WINDOWS\system32\resiifers.ini
2008-01-09 17:40 . 2008-01-09 17:40 <DIR> d-------- C:\Program Files\GameSpy
2008-01-09 17:38 . 2008-01-09 17:38 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-01-09 17:37 . 2008-01-09 17:37 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-09 17:37 . 2008-01-09 17:37 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-01-09 17:37 . 2008-01-09 17:37 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-01-09 17:37 . 2008-01-09 17:37 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-01-09 17:37 . 2008-01-09 17:37 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-09 17:37 . 2008-01-09 17:37 22,328 --a------ C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\PnkBstrK.sys
2008-01-09 17:24 . 2008-01-09 17:24 <DIR> d-------- C:\Program Files\Electronic Arts
2008-01-09 16:52 . 2008-01-09 16:52 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\Ahead
2008-01-09 16:32 . 2008-01-09 16:32 <DIR> d-------- C:\Program Files\7-Zip
2008-01-08 16:39 . 2008-01-08 16:39 <DIR> d-------- C:\Program Files\Starbreeze Studios
2008-01-07 14:57 . 2008-01-07 14:57 <DIR> d-------- C:\Program Files\OpenAL
2008-01-07 14:57 . 2008-01-07 14:57 413,696 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-01-07 14:57 . 2008-01-07 14:57 110,592 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-01-07 14:53 . 2008-01-07 14:57 <DIR> d-------- C:\Program Files\Aquadelic GT
2008-01-07 14:53 . 2008-01-07 14:58 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Aquadelic GT
2008-01-01 12:43 . 2008-01-01 12:43 110,592 --a------ C:\t2h8
2007-12-31 23:01 . 2007-12-31 23:01 106,496 --a------ C:\t22s.1
2007-12-28 20:00 . 2007-12-28 20:00 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Trymedia
2007-12-28 08:38 . 2007-12-28 08:38 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\Media Player Classic
2007-12-27 23:14 . 2007-12-27 23:14 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-12-27 23:14 . 2007-11-29 23:30 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-12-27 23:14 . 2006-09-24 16:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm
2007-12-27 23:14 . 2007-03-10 12:51 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-12-27 23:14 . 2004-01-25 17:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-12-27 23:14 . 2007-09-04 17:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2007-12-27 23:14 . 2007-09-21 01:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2007-12-27 23:14 . 2007-11-29 23:28 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2007-12-27 23:14 . 2007-12-07 18:28 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-12-27 23:14 . 2007-07-10 17:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2007-12-27 23:14 . 2007-10-03 16:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2007-12-27 22:35 . 2008-01-12 22:35 3,256 --a------ C:\WINDOWS\system32\tmp.reg
2007-12-27 20:48 . 2007-12-27 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2007-12-27 20:20 . 2007-12-27 20:48 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-27 08:59 . 2007-12-27 08:59 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-27 08:44 . 2007-12-27 20:49 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\Lavasoft
2007-12-26 21:05 . 2002-12-17 16:23 33,340 --------- C:\WINDOWS\system32\dbmsqlgc.dll
2007-12-26 21:05 . 2002-10-20 14:05 24,576 --------- C:\WINDOWS\system32\dbmsgnet.dll
2007-12-26 20:53 . 2007-12-26 20:53 <DIR> d-------- C:\Program Files\Vstplugins
2007-12-26 20:53 . 2007-12-26 20:53 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2007-12-26 20:29 . 2007-12-26 20:29 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\Publish Providers
2007-12-26 20:03 . 2007-12-26 20:03 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\Sony
2007-12-26 20:02 . 2007-12-26 20:52 <DIR> d-------- C:\Program Files\Sony
2007-12-26 20:02 . 2007-12-26 20:50 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Sony
2007-12-26 19:42 . 2007-12-26 19:42 <DIR> d-------- C:\Program Files\Sony Setup
2007-12-26 15:51 . 2007-12-26 15:57 <DIR> d-------- C:\Hip-Hop
2007-12-26 15:47 . 2007-12-26 15:50 <DIR> d-------- C:\Program Files\Winamp
2007-12-26 15:47 . 2007-12-26 16:01 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\Winamp
2007-12-26 15:15 . 2008-01-13 15:21 69 --a------ C:\WINDOWS\NeroDigital.ini
2007-12-26 15:11 . 2007-12-29 14:22 <DIR> d-------- C:\Zdjęcia
2007-12-26 15:08 . 2007-08-06 21:30 16,945 ---hs---- C:\PegeFile.pif
2007-12-24 19:25 . 2007-12-24 19:32 <DIR> d-------- C:\Program Files\Skijumping 2007
2007-12-21 21:36 . 2007-12-21 21:36 <DIR> d-------- C:\Program Files\ReaSoft
2007-12-21 21:36 . 2007-12-21 21:36 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\ReaSoft
2007-12-21 14:50 . 2007-12-21 14:50 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\.jpi_cache
2007-12-21 14:49 . 2007-12-21 14:49 <DIR> d-------- C:\Documents and Settings\eMaNeTeWu\.java
2007-12-21 11:22 . 2007-12-21 11:22 <DIR> d-------- C:\Fraps
2007-12-20 10:34 . 2007-12-27 09:18 <DIR> d-------- C:\Program Files\Panzer Elite Action
2007-12-18 14:53 . 2004-06-16 06:03 73,728 --a------ C:\WINDOWS\system32\ISUSPM.cpl
2007-12-18 14:50 . 2007-12-18 14:50 271,360 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2007-12-18 14:50 . 2007-12-18 14:50 18,048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2007-12-18 14:45 . 2007-12-18 14:52 <DIR> d-------- C:\Program Files\Gothic III
2007-12-18 14:42 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-12-18 14:42 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-12-18 14:41 . 2007-12-18 14:41 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-12-18 14:41 . 2007-12-18 14:42 <DIR> d-------- C:\Program Files\Ahead
2007-12-18 14:41 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-12-18 14:41 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-12-18 14:41 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-12-18 14:41 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-12-17 12:51 . 2007-12-17 12:51 <DIR> d-------- C:\WINDOWS\system32\Futuremark
2007-12-17 12:51 . 2004-10-25 20:02 21,664 --a------ C:\WINDOWS\system32\drivers\Entech.sys
2007-12-17 12:51 . 1999-11-02 10:01 6,173 --a------ C:\WINDOWS\system32\drivers\Entech.vxd
2007-12-17 12:51 . 2004-06-22 15:44 5,632 --a------ C:\WINDOWS\system32\drivers\Entech64.sys
2007-12-17 12:51 . 2001-11-19 19:05 3,972 --a------ C:\WINDOWS\system32\drivers\PciBus.sys
2007-12-17 12:50 . 2007-12-17 12:50 <DIR> d-------- C:\Program Files\Futuremark
2007-12-16 20:19 . 2007-12-16 20:19 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-16 15:56 . 2008-01-08 20:07 <DIR> d-------- C:\Program Files\Hitman Kontrakty
2007-12-16 13:37 . 2007-12-16 13:37 <DIR> d-------- C:\Program Files\RivaTuner v2.05
2007-12-16 13:21 . 2007-12-16 13:21 <DIR> d-------- C:\nVidia Forceware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-14 11:45 --------- d-----w C:\Program Files\neostrada tp
2008-01-14 10:43 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-01-14 07:15 0 ----a-w C:\WINDOWS\Fonts\cuy.dl
2008-01-13 14:43 --------- d-----w C:\Program Files\HLSW
2008-01-07 17:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-05 13:30 --------- d-----w C:\Program Files\MoorHunt
2007-12-27 19:49 --------- d-----w C:\Program Files\Lavasoft
2007-12-21 09:52 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-13 06:13 892,928 ----a-w C:\WINDOWS\system32\iconv.dll
2007-12-13 06:13 237,568 ----a-w C:\WINDOWS\system32\OggDS.dll
2007-12-13 06:12 921,600 ----a-w C:\WINDOWS\system32\vorbisenc.dll
2007-12-13 06:12 9,216 ----a-w C:\WINDOWS\system32\cpuinf32.dll
2007-12-13 06:12 45,056 ----a-w C:\WINDOWS\system32\ogg.dll
2007-12-13 06:12 245,760 ----a-w C:\WINDOWS\system32\mplvpx.dll
2007-12-13 06:12 188,416 ----a-w C:\WINDOWS\system32\vorbis.dll
2007-12-13 06:12 1,415,680 ----a-w C:\WINDOWS\system32\WMV9VCM.dll
2007-12-12 20:27 --------- d-----w C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\Gadu-Gadu
2007-12-12 20:25 --------- d-----w C:\Program Files\Gadu-Gadu
2007-12-12 18:05 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Adobe Systems
2007-12-12 18:02 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2007-12-12 17:39 --------- d-----w C:\Program Files\Sierra On-Line
2007-12-11 18:04 --------- d-----w C:\Program Files\Common Files\BinarySense
2007-12-11 14:32 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-12-10 17:11 --------- d-----w C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\Thunderbird
2007-12-09 18:01 --------- d-----w C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\THQ
2007-12-09 17:34 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\InstallShield
2007-12-09 17:26 --------- d-----w C:\Program Files\THQ
2007-12-09 17:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-09 17:25 --------- d-----w C:\Program Files\DAEMON Tools Pro
2007-12-09 17:07 --------- d-----w C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\BinarySense
2007-12-09 17:02 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\DAEMON Tools Pro
2007-12-09 17:00 --------- d-----w C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\DAEMON Tools Pro
2007-12-09 16:45 --------- d-----w C:\Documents and Settings\eMaNeTeWu\Dane aplikacji\INTERIAPL
2007-12-09 16:38 --------- d-----w C:\Program Files\Thomson
2007-12-09 16:37 --------- d-----w C:\Program Files\Java
2007-12-09 16:24 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-09 11:13 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\NVIDIA
2007-12-09 10:57 --------- d-----w C:\Program Files\INTERIAPL
2007-12-09 10:56 --------- d-----w C:\Program Files\MarBit
2007-12-09 10:55 --------- d-----w C:\Program Files\PC DUAL SHOCK
2007-12-09 10:55 --------- d-----w C:\Program Files\A4Tech
2007-12-09 10:50 --------- d-----w C:\Program Files\Realtek
2007-12-09 10:36 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-09 10:34 --------- d-----w C:\Program Files\Usługi online
2007-12-08 12:43 175 ----a-w C:\WINDOWS\Fonts\README.txt
2007-12-04 01:33 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2007-11-21 18:23 81,920 ----a-w C:\WINDOWS\system32\frapsvid.dll
2007-11-07 09:29 723,968 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:44 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-20 05:01 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
.
((((((((((((((((((((((((((((( snapshot_2008-01-14_11.14.52.65 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-12 08:21:54 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-14 11:36:37 4,317,184 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-01-14 11:36:37 12,288 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-01-12 08:21:54 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-14 11:36:29 4,317,184 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-01-14 11:36:29 12,288 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-01-14 09:50:08 155,648 ----a-w C:\WINDOWS\ilovegoogle\google.dll
+ 2008-01-14 10:17:05 155,648 ----a-w C:\WINDOWS\ilovegoogle\google.dll
- 2008-01-14 09:52:34 69,970 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-14 11:45:24 69,970 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-14 09:52:34 87,070 ----a-w C:\WINDOWS\system32\perfc015.dat
+ 2008-01-14 11:45:24 87,070 ----a-w C:\WINDOWS\system32\perfc015.dat
- 2008-01-14 09:52:34 418,454 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-14 11:45:24 418,454 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-01-14 09:52:34 475,060 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2008-01-14 11:45:24 475,060 ----a-w C:\WINDOWS\system32\perfh015.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CE7C3CF0-4B15-11D1-ABED-709549C10531}]
2008-01-14 11:17 155648 --a------ C:\WINDOWS\ILOVEG~1\google.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Stefan"="C:\Program Files\INTERIAPL\Stefan\Stefan.exe" [2007-08-29 14:30 685056]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 14:08 136136]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-06-02 16:03 1957888]
"Comrade.exe"="C:\Program Files\GameSpy\Comrade\Comrade.exe" [2007-06-29 15:03 36864]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 08:34 16143872 C:\WINDOWS\RTHDCPL.exe]
"WheelMouse"="C:\Program Files\A4Tech\Mouse\Amoumain.exe" [2006-12-26 08:08 196608]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-05 15:25 8491008]
"nwiz"="nwiz.exe" [2007-10-05 15:25 1626112 C:\WINDOWS\system32\nwiz.exe]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 14:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\GestMaj.exe" [2004-10-14 16:55 32768]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.05\RivaTuner.exe" [2007-09-27 18:20 2633728]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-05 15:25 81920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 06:03 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 10:58 86960]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-12-20 16:16 37376]
"Vmlist"="regsvr32 /s apphelps.dll" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{0EA66AD2-CF26-2E23-532B-B292E22F3266}"= C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll [2008-01-14 12:41 10801]
[HKLM\~\startupfolder\C:^Documents and Settings^eMaNeTeWu^Menu Start^Programy^Autostart^HDDlife.lnk]
path=C:\Documents and Settings\eMaNeTeWu\Menu Start\Programy\Autostart\HDDlife.lnk
backup=C:\WINDOWS\pss\HDDlife.lnkStartup
R0 xxqt;xxq;C:\WINDOWS\system32\DRIVERS\xxqt.sys [2004-08-03 23:44]
R2 conime;conime;C:\WINDOWS\System32\svchost.exe [2004-08-03 23:44]
R2 qvcog;qvcog;C:\WINDOWS\system32\drivers\qvcog.sys [2004-08-03 23:44]
S3 cpuz128;cpuz128;C:\DOCUME~1\EMANET~1\USTAWI~1\Temp\cpuz_x32.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
conime
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\Auto\command - C:\PegeFile.pif
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL PegeFile.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ba842172-b3bb-11dc-8296-000e50f342eb}]
\Shell\Auto\command - G:\PegeFile.pif
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL PegeFile.pif
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-14 12:48:02
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-14 12:48:37
ComboFix-quarantined-files.txt 2008-01-14 11:48:22
ComboFix2.txt 2008-01-14 10:15:22
ComboFix3.txt 2007-12-27 21:49:48
.
2008-01-11 19:25:34 --- E O F ---