ComboFix 08-03-17.1 - x 2008-03-19 15:07:18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1401 [GMT 1:00]
Running from: C:\logi wirusa\ComboFix.exe
Command switches used :: C:\logi wirusa\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\amp.bat
C:\WINDOWS\nxstinst.exe
C:\WINDOWS\remover.dll
C:\WINDOWS\wmpdxm.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\amp.bat
C:\Program Files\NavExcel Search Toolbar
C:\Program Files\NavExcel Search Toolbar\settings.dat
C:\Program Files\whInstall
C:\Program Files\whInstall\license.txt
C:\Program Files\whInstall\readme.txt
C:\Program Files\whInstall\Sporder.dll
C:\Program Files\whInstall\whAgent.inf
C:\Program Files\whInstall\whAgent.ini
C:\Program Files\whInstall\whInstaller.ini
C:\WINDOWS\nxstinst.exe
C:\WINDOWS\remover.dll
C:\WINDOWS\wmpdxm.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-19 to 2008-03-19 )))))))))))))))))))))))))))))))
.
2008-03-18 14:18 . 2008-03-19 15:07 <DIR> d-------- C:\logi wirusa
2008-03-16 17:54 . 2008-03-16 17:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-16 17:54 . 2008-03-16 17:54 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-16 17:52 . 2006-09-18 14:58 61,600 -ra------ C:\WINDOWS\system32\drivers\SE27bus.sys
2008-03-16 17:52 . 2006-09-18 14:59 5,872 -ra------ C:\WINDOWS\system32\drivers\SE27whnt.sys
2008-03-16 17:52 . 2006-09-18 14:59 5,872 -ra------ C:\WINDOWS\system32\drivers\SE27wh.sys
2008-03-16 17:01 . 2008-03-16 17:01 <DIR> d-------- C:\Program Files\Alwil Software
2008-03-16 17:01 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-16 17:01 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-16 17:01 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-16 17:01 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-16 17:01 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-16 17:01 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-16 17:01 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-16 17:01 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-16 16:54 . 2008-03-16 16:54 <DIR> d-------- C:\Program Files\ToniArts
2008-03-16 16:35 . 2008-03-16 16:35 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-15 12:11 . 2008-03-15 12:17 1,392 --a------ C:\WINDOWS\mozver.dat
2008-03-09 16:42 . 2008-03-09 16:42 <DIR> dr-hs---- C:\Recycled
2008-03-01 23:28 . 2008-03-01 23:28 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Creative
2008-03-01 10:35 . 2008-03-01 23:28 <DIR> d-------- C:\Documents and Settings\x\Dane aplikacji\Creative
2008-02-29 20:17 . 2006-06-18 18:01 282,624 -ra------ C:\WINDOWS\system32\V0250Cvw.dll
2008-02-29 20:15 . 2000-05-22 09:58 647,872 --------- C:\WINDOWS\system32\Mscomct2.ocx
2008-02-29 20:15 . 1999-10-10 18:00 41,984 --------- C:\WINDOWS\Ctregrun.exe
2008-02-29 20:15 . 2003-06-12 23:25 7,062 --a------ C:\WINDOWS\system32\audiopid.vxd
2008-02-29 20:14 . 2008-02-29 20:14 <DIR> d-------- C:\WINDOWS\CtDrvInstall
2008-02-29 20:06 . 2008-02-29 20:14 <DIR> d-------- C:\Program Files\SightSpeed
2008-02-29 20:06 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-02-29 20:03 . 2008-02-29 20:14 <DIR> d-------- C:\Program Files\Creative
2008-02-29 17:34 . 2006-11-07 09:42 97,056 -ra------ C:\WINDOWS\system32\drivers\w200mdm.sys
2008-02-29 17:34 . 2006-11-07 09:42 88,560 -ra------ C:\WINDOWS\system32\drivers\w200mgmt.sys
2008-02-29 17:34 . 2006-11-07 09:42 86,368 -ra------ C:\WINDOWS\system32\drivers\w200obex.sys
2008-02-29 17:34 . 2006-11-07 09:42 9,328 -ra------ C:\WINDOWS\system32\drivers\w200mdfl.sys
2008-02-29 17:34 . 2006-11-07 09:42 6,208 -ra------ C:\WINDOWS\system32\drivers\w200cmnt.sys
2008-02-29 17:34 . 2006-11-07 09:42 6,208 -ra------ C:\WINDOWS\system32\drivers\w200cm.sys
2008-02-29 17:30 . 2006-11-07 09:42 61,504 -ra------ C:\WINDOWS\system32\drivers\w200bus.sys
2008-02-29 17:30 . 2006-11-07 09:42 5,840 -ra------ C:\WINDOWS\system32\drivers\w200whnt.sys
2008-02-29 17:30 . 2006-11-07 09:42 5,840 -ra------ C:\WINDOWS\system32\drivers\w200wh.sys
2008-02-29 14:29 . 2008-03-19 08:24 <DIR> d-------- C:\Documents and Settings\x\Dane aplikacji\skypePM
2008-02-29 14:29 . 2008-02-29 14:29 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-02-29 13:22 . 2008-03-19 14:50 <DIR> d-------- C:\Documents and Settings\x\Dane aplikacji\Skype
2008-02-28 21:18 . 2008-02-28 21:18 <DIR> d-------- C:\Program Files\Skype
2008-02-28 21:18 . 2008-02-28 21:18 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-02-28 21:18 . 2008-02-28 21:18 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-02-27 18:55 . 2008-03-16 16:27 <DIR> d-------- C:\Program Files\Winamp
2008-02-25 21:33 . 2008-02-25 21:33 6,663,744 --a------ C:\WINDOWS\system32\A0047180.EXE.VBTMP
2008-02-25 19:06 . 2008-02-25 19:06 6,663,744 --a------ C:\WINDOWS\system32\msaccess.exe.VBTMP
2008-02-25 19:05 . 2008-03-16 17:02 <DIR> d-------- C:\Program Files\Google
2008-02-25 19:05 . 2008-03-16 16:10 <DIR> d-a------ C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-02-24 18:52 . 2008-02-24 18:52 50 --a------ C:\WINDOWS\Winamp.ini
2008-02-24 18:52 . 2008-02-24 18:52 41 --a------ C:\WINDOWS\winampa.ini
2008-02-24 18:19 . 2008-02-24 18:19 <DIR> d-------- C:\Program Files\Ares
2008-02-23 20:28 . 2008-02-23 20:28 <DIR> d-------- C:\Documents and Settings\x\Dane aplikacji\Gadu-Gadu
2008-02-23 20:24 . 2008-02-23 20:24 <DIR> d-------- C:\Program Files\Gadu-Gadu
2008-02-23 20:24 . 2008-03-10 18:47 <DIR> d-------- C:\Documents and Settings\x\Gadu-Gadu
2008-02-23 13:08 . 2008-02-23 13:08 <DIR> d-------- C:\Program Files\ZyDAS Technology Corporation
2008-02-23 13:08 . 2006-08-24 13:44 477,696 --a------ C:\WINDOWS\system32\drivers\ZD1211BU.sys
2008-02-23 13:08 . 2004-01-14 11:25 81,920 --a------ C:\WINDOWS\system32\ZDPN50.DLL
2008-02-23 13:08 . 2005-03-18 15:35 31,744 --a------ C:\WINDOWS\system32\drivers\ZDPSp50a64.sys
2008-02-23 13:08 . 2005-06-08 18:44 29,184 --a------ C:\WINDOWS\system32\drivers\BRGSp50a64.sys
2008-02-23 13:08 . 2004-03-23 16:38 28,672 --a------ C:\WINDOWS\system32\InsDrvZD.dll
2008-02-23 13:08 . 2003-03-14 12:24 24,576 --a------ C:\WINDOWS\system32\ZyDelReg.exe
2008-02-23 13:08 . 2005-06-08 18:44 20,608 --a------ C:\WINDOWS\system32\drivers\BRGSp50.sys
2008-02-23 13:08 . 2004-10-25 13:40 17,664 --a------ C:\WINDOWS\system32\drivers\ZDPSp50.sys
2008-02-23 13:08 . 2004-01-14 11:30 17,151 --a------ C:\WINDOWS\system32\ZDPNDIS5.SYS
2008-02-23 13:08 . 2005-07-12 14:44 15,872 --a------ C:\WINDOWS\system32\InsDrvZD64.DLL
2008-02-19 17:27 . 2008-02-19 20:22 <DIR> d-------- C:\Program Files\Starcars - Demo Version
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 15:42 --------- d-----w C:\Program Files\TESCOLANDIA - Archipelag Magii
2008-03-16 15:58 --------- d-----w C:\Program Files\Funny Racer
2008-03-16 15:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-09 16:58 356,352 ----a-w C:\WINDOWS\system32\nvusmb.exe
2008-03-09 16:58 356,352 ----a-w C:\WINDOWS\system32\nvunrm.exe
2008-03-09 16:56 778,240 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-25 18:10 972,336 ----a-w C:\WINDOWS\UNRecode.exe
2008-02-25 18:10 972,336 ----a-w C:\WINDOWS\UNNeroVision.exe
2008-02-25 18:10 972,336 ----a-w C:\WINDOWS\UNNeroShowTime.exe
2008-02-25 18:10 972,336 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-25 18:10 972,336 ----a-w C:\WINDOWS\UNNeroBackItUp.exe
2008-02-25 18:10 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-02-25 18:10 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2008-02-25 18:10 189,952 ----a-w C:\WINDOWS\system32\WISPTIS.EXE
2008-02-25 18:10 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2008-02-25 18:09 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2008-02-25 18:09 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-02-25 18:09 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2008-02-25 18:09 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2008-02-25 18:09 233,472 ----a-w C:\WINDOWS\InstIt.exe
2008-02-25 18:09 2,162,688 ------r C:\WINDOWS\MicCal.exe
2008-02-25 18:09 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2008-02-25 18:09 1,191,936 ------r C:\WINDOWS\RtlUpd.exe
2008-02-25 18:07 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-02-22 16:19 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-02-22 12:15 --------- d-----w C:\Program Files\Chicken Invaders 2 Christmas Edition demo
2008-02-19 11:11 --------- d-----w C:\Program Files\Realore
2008-02-19 11:10 --------- d-----w C:\Program Files\Pinokio
2008-02-18 16:24 --------- d-----w C:\Program Files\JPEGCrops
2008-01-31 20:34 --------- d-----w C:\Program Files\Trickshot
2008-01-30 22:42 --------- d-----w C:\Program Files\Absolute Mastermind
2008-01-26 20:12 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-26 20:06 --------- d-----w C:\Program Files\Codec Pack - All In 1
2008-01-26 19:55 --------- d-----w C:\Program Files\DivX
2008-01-25 19:45 --------- d-----w C:\Documents and Settings\x\Dane aplikacji\Leadertech
2008-01-25 19:43 --------- d-----w C:\Documents and Settings\x\Dane aplikacji\AdobeUM
2008-01-20 21:18 --------- d-----w C:\Program Files\Sony Ericsson
2008-01-20 21:18 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-01-20 21:18 --------- d-----w C:\Program Files\Common Files\Sony Ericsson Shared
2008-01-20 21:18 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Teleca
2008-01-20 21:18 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Sony Ericsson
2007-12-25 21:03 24 ----a-w C:\Documents and Settings\x\Config.dat
2007-12-23 21:44 15,600 ----a-w C:\WINDOWS\gdrv.sys
.
((((((((((((((((((((((((((((( snapshot@2008-03-18_15.15.47.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-19 13:28:22 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5d4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:44 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 10:21 153136]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 00:55 1667584]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 11:54 2131392]
"ares"="C:\Program Files\Ares\Ares.exe" [2008-02-20 15:33 963072]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-06 18:37 21898024]
"Creative Live! Cam Manager"="C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2006-05-31 16:00 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ioCentre"="C:\Genius\ioCentre\gTaskBar.exe" [2006-12-08 21:09 241664]
"CHotkey"="mHotkey.exe" [2006-12-08 17:01 547840 C:\WINDOWS\mHotkey.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 17:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 17:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 17:43 81920]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-02-25 19:16 153136]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 07:49 16377344 C:\WINDOWS\RTHDCPL.exe]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 21:09 157592]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-15 22:57 155648]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 01:06 487424]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-15 19:04 35328]
"AVFX Engine"="C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-06-09 01:11 24576]
"V0250Mon.exe"="C:\WINDOWS\V0250Mon.exe" [2006-06-07 18:00 32768]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-02-23 13:08:53 487424]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\SightSpeed\\SightSpeed.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 gMouPS2;PS2 Scroll Mouse Device;C:\WINDOWS\system32\DRIVERS\gMouPS2.sys [2006-07-12 04:48]
R3 V0250Dev;Live! Cam Notebook Pro;C:\WINDOWS\system32\DRIVERS\V0250Dev.sys [2006-06-27 04:25]
R3 V0250Vfx;V0250Vfx;C:\WINDOWS\system32\DRIVERS\V0250Vfx.sys [2006-03-24 09:24]
R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2006-08-24 13:44]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-12-23 22:44]
S3 SunkFilt6;Alcor Micro Corp - 6360;C:\WINDOWS\System32\Drivers\sunkfilt6.sys []
S3 SunkFilt62;Alcor Micro Corp - 6362;C:\WINDOWS\System32\Drivers\sunkfilt62.sys []
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 09:42]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 09:42]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 09:42]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 09:42]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 09:42]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a38deb2-cc48-11dc-ba58-001a4df4dff3}]
\Shell\AutoRun\command - J:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2632728-f27f-11dc-bb04-001aff015ae0}]
\Shell\AutoRun\command - J:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-19 15:08:27
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-19 15:08:40
ComboFix-quarantined-files.txt 2008-03-19 14:08:38
ComboFix2.txt 2008-03-18 14:15:56