ComboFix 08-01-31.1 - Adminow 2008-01-31 0:21:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.733 [GMT 1:00]
Running from: C:\Documents and Settings\Adminow\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Adminow\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
C:\Program Files\ConnectionServices
C:\Program Files\ConnectionServices\Uninstall.exe
C:\WINDOWS\hosts
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.
2008-01-27 12:20 . 2008-01-27 12:20 <DIR> d-------- C:\Program Files\MIKSOFT
2008-01-25 20:22 . 2008-01-25 20:22 <DIR> d-------- C:\Documents and Settings\Adminow\Battleground Europe
2008-01-23 19:58 . 2008-01-23 19:58 217,088 --a------ C:\WINDOWS\system32\UAService7.exe
2008-01-20 17:36 . 2001-05-11 13:18 420,240 --a------ C:\WINDOWS\system32\mpg4c32.dll
2008-01-20 17:36 . 2001-05-16 17:54 309,616 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-01-20 17:36 . 2001-03-26 04:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-01-18 11:25 . 2003-02-18 05:51 545 --a------ C:\WINDOWS\UC.PIF
2008-01-18 11:25 . 2003-02-18 05:51 545 --a------ C:\WINDOWS\RAR.PIF
2008-01-18 11:25 . 2003-02-18 05:51 545 --a------ C:\WINDOWS\PKZIP.PIF
2008-01-18 11:25 . 2003-02-18 05:51 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2008-01-18 11:25 . 2003-02-18 05:51 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2008-01-18 11:25 . 2003-02-18 05:51 545 --a------ C:\WINDOWS\LHA.PIF
2008-01-18 11:25 . 2003-02-18 05:51 545 --a------ C:\WINDOWS\ARJ.PIF
2008-01-18 11:25 . 2008-01-18 11:28 331 --a------ C:\WINDOWS\wincmd.ini
2008-01-16 19:34 . 2008-01-16 19:34 <DIR> d-------- C:\Program Files\Common Files\BOONTY Shared
2008-01-16 19:34 . 2008-01-16 19:34 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\BOONTY
2008-01-10 19:30 . 2008-01-10 19:46 <DIR> d-------- C:\Program Files\RegCleaner
2008-01-10 16:40 . 2008-01-20 16:44 <DIR> d-------- C:\Program Files\eMule
2008-01-09 20:46 . 2008-01-09 20:46 <DIR> d-------- C:\Program Files\TP
2008-01-08 14:31 . 2008-01-08 14:31 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-01-08 14:29 . 2008-01-08 14:30 <DIR> d-------- C:\Program Files\Success Pre-Intermediate
2008-01-07 17:41 . 2005-02-28 20:10 205,824 --a------ C:\WINDOWS\patchw32.dll
2008-01-07 17:19 . 2005-02-28 20:10 205,824 --a------ C:\WINDOWS\pw32a.dll
2007-12-30 19:26 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-30 19:25 . 2007-12-30 19:26 <DIR> d-------- C:\Program Files\Java
2007-12-30 19:21 . 2007-12-30 19:21 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-29 15:05 . 2007-12-29 15:05 <DIR> d-------- C:\Program Files\Steam
2007-12-28 19:20 . 2007-12-28 19:20 <DIR> d-------- C:\Documents and Settings\Adminow\Dane aplikacji\InstallShield
2007-12-27 16:10 . 2007-12-28 09:51 <DIR> d-------- C:\Program Files\Winamp Remote
2007-12-27 16:10 . 2007-12-28 09:51 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\OrbNetworks
2007-12-27 16:02 . 2007-12-27 17:04 <DIR> d-------- C:\Documents and Settings\Adminow\Dane aplikacji\Winamp
2007-12-26 13:09 . 2008-01-05 16:03 23 --a------ C:\WINDOWS\BlendSettings.ini
2007-12-26 12:40 . 2008-01-27 12:04 <DIR> d-------- C:\The Elder Scrolls IV Oblivion
2007-12-22 00:16 . 2007-12-22 00:16 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-21 18:30 . 2008-01-13 13:36 <DIR> d-------- C:\Program Files\MoorHunt
2007-12-21 18:14 . 2004-08-03 23:44 2,804,224 --a------ C:\WINDOWS\system32\msi.dll
2007-12-21 18:14 . 2004-08-03 23:44 2,804,224 --a------ C:\WINDOWS\system32\dllcache\msi.dll
2007-12-21 18:14 . 2004-08-03 23:43 884,736 --a------ C:\WINDOWS\system32\msimsg.dll
2007-12-21 18:14 . 2004-08-03 23:43 884,736 --a------ C:\WINDOWS\system32\dllcache\msimsg.dll
2007-12-21 18:14 . 2004-08-03 23:44 331,264 --a------ C:\WINDOWS\system32\msihnd.dll
2007-12-21 18:14 . 2004-08-03 23:44 331,264 --a------ C:\WINDOWS\system32\dllcache\msihnd.dll
2007-12-21 18:14 . 2004-08-03 23:44 77,312 --a------ C:\WINDOWS\system32\msiexec.exe
2007-12-21 18:14 . 2004-08-03 23:44 77,312 --a------ C:\WINDOWS\system32\dllcache\msiexec.exe
2007-12-21 18:14 . 2004-08-03 23:44 44,032 --a------ C:\WINDOWS\system32\msisip.dll
2007-12-21 18:14 . 2004-08-03 23:44 44,032 --a------ C:\WINDOWS\system32\dllcache\msisip.dll
2007-12-19 09:51 . 2007-12-19 09:51 <DIR> d-------- C:\Documents and Settings\Adminow\Dane aplikacji\gslist
2007-12-19 03:34 . 2007-12-19 03:34 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2007-12-19 03:32 . 2007-12-19 03:34 956 --a------ C:\WINDOWS\ARCHPR.INI
2007-12-19 03:31 . 2007-12-19 03:34 <DIR> d-------- C:\Program Files\ARCHPR
2007-12-18 09:43 . 2007-12-18 09:45 <DIR> d-------- C:\Program Files\BitComet
2007-12-16 21:15 . 2007-12-16 21:15 <DIR> d-------- C:\Program Files\D-Tools
2007-12-16 21:15 . 2004-08-22 16:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2007-12-16 21:15 . 2004-08-22 16:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2007-12-12 18:58 . 2007-12-12 19:15 <DIR> d-------- C:\Program Files\EAGLE-4.16r2
2007-12-07 23:10 . 1996-11-06 12:05 302,592 --a------ C:\WINDOWS\unin0407.exe
2007-12-07 16:54 . 2007-12-07 16:54 635 --a------ C:\WINDOWS\Rtcw.INI
2007-12-06 11:36 . 2008-01-24 16:17 <DIR> d-------- C:\Program Files\GameSpy Arcade
2007-12-05 21:03 . 2007-12-05 21:03 3,770 --a------ C:\WINDOWS\Outlook.VUE
2007-12-04 17:29 . 2007-12-04 17:29 31 --a------ C:\WINDOWS\Config.ini
2007-12-01 14:31 . 2007-12-01 14:31 <DIR> d-------- C:\NVIDIA
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-29 19:54 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-29 19:54 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-01-29 19:53 --------- d-----w C:\Documents and Settings\Adminow\Dane aplikacji\teamspeak2
2008-01-27 11:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-25 19:14 --------- d-----w C:\Program Files\FlashGet
2008-01-23 18:58 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-01-22 09:55 --------- d-----w C:\Documents and Settings\Adminow\Dane aplikacji\Skype
2008-01-15 07:35 --------- d-----w C:\Program Files\Gadu-Gadu
2008-01-08 15:05 --------- d-----w C:\Documents and Settings\Adminow\Dane aplikacji\Image Zone Express
2008-01-03 20:05 --------- d-----w C:\Documents and Settings\Adminow\Dane aplikacji\MyPhoneExplorer
2007-12-27 15:11 --------- d-----w C:\Program Files\Winamp
2007-12-26 16:29 --------- d-----w C:\Program Files\Sony Ericsson
2007-12-20 11:52 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-12-06 18:34 --------- d-----w C:\Program Files\Audacity
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-10-30 19:02 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-10-04 17:16 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-10-04 17:16 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-10-04 16:14 8,491,008 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-10-04 16:14 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-10-04 16:14 6,750,208 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-10-04 16:14 6,344,704 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-10-04 16:14 5,783,424 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-10-04 16:14 5,509,120 ----a-w C:\WINDOWS\system32\nvdispsr.dll
2007-10-04 16:14 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-10-04 16:14 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll
2007-10-04 16:14 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-10-04 16:14 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-10-04 16:14 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-10-04 16:14 364,544 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-10-04 16:14 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll
2007-10-04 16:14 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvrshe.dll
2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvrsar.dll
2007-10-04 16:14 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll
2007-10-04 16:14 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll
2007-10-04 16:14 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll
2007-10-04 16:14 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll
2007-10-04 16:14 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll
2007-10-04 16:14 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll
2007-10-04 16:14 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll
2007-10-04 16:14 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll
2007-10-04 16:14 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll
2007-10-04 16:14 3,629,056 ----a-w C:\WINDOWS\system32\nvvitvsr.dll
2007-10-04 16:14 3,551,232 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-10-04 16:14 3,334,144 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-10-04 16:14 3,166,208 ----a-w C:\WINDOWS\system32\nvgamesr.dll
2007-10-04 16:14 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll
2007-10-04 16:14 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll
2007-10-04 16:14 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll
2007-10-04 16:14 290,816 ----a-w C:\WINDOWS\system32\nvwrsth.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll
2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrsfr.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrses.dll
2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrsel.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvrsit.dll
2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvrsde.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrspt.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrsnl.dll
2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrsesm.dll
2007-10-04 16:14 270,336 ----a-w C:\WINDOWS\system32\nvrsru.dll
2007-10-04 16:14 266,240 ----a-w C:\WINDOWS\system32\nvrsptb.dll
2007-10-04 16:14 266,240 ----a-w C:\WINDOWS\system32\nvrsja.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrstr.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrssl.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrssk.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll
2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrshu.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsth.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrssv.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrspl.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsno.dll
2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsda.dll
2007-10-04 16:14 249,856 ----a-w C:\WINDOWS\system32\nvrsfi.dll
2007-10-04 16:14 249,856 ----a-w C:\WINDOWS\system32\nvrscs.dll
2007-10-04 16:14 245,760 ----a-w C:\WINDOWS\system32\nvrseng.dll
2007-10-04 16:14 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-10-04 16:14 225,280 ----a-w C:\WINDOWS\system32\nvrszhc.dll
2007-10-04 16:14 212,992 ----a-w C:\WINDOWS\system32\nvwrsja.dll
2007-10-04 16:14 2,854,912 ----a-w C:\WINDOWS\system32\nvmoblsr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14 8491008]
"nwiz"="nwiz.exe" [2007-10-04 17:14 1626112 C:\WINDOWS\system32\nwiz.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44 15360]
C:\Documents and Settings\Adminow\Menu Start\Programy\Autostart\
GM_DevUpdate.lnk - C:\Program Files\USB all-in-one game controller\GM_DevUpdate.exe [2007-11-15 16:31:49 45056]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
RaConfig2500.lnk - C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe [2007-08-22 15:27:59 532480]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
--a------ 2004-08-11 10:32 7956992 C:\Program Files\VIAudioi\SBADeck\ADeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-11 22:12 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
R0 VirtualK;VirtaulK;C:\WINDOWS\system32\drivers\VirtualK.sys [2003-11-27 19:48]
R1 XPROTECTOR;XPROTECTOR;C:\WINDOWS\system32\drivers\Oreans.sys [2007-10-27 09:57]
R3 GMFilter;GMFilter HID Filter Driver;C:\WINDOWS\system32\DRIVERS\GMFilter.sys [2005-08-23 11:54]
R3 skbusenum;SKBus Enumerator;C:\WINDOWS\system32\DRIVERS\skbusenum.sys [2004-12-16 12:20]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS []
S3 SF-620;Kingsun SF-620 USB Infrared Adapter;C:\WINDOWS\system32\DRIVERS\SF-620.sys [2004-08-12 03:18]
S4 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6aa3931c-95c8-11dc-b404-00508d51fc08}]
\Shell\AutoRun\command - H:\Autorun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-31 00:23:00
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-31 0:23:32
ComboFix-quarantined-files.txt 2008-01-30 23:23:18