ComboFix 07-12-21.4 - Prox 2007-12-30 20:21:10.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.284 [GMT 1:00]
Running from: C:\Documents and Settings\Prox.PROX-DD28CKH3TD\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-30 )))))))))))))))))))))))))))))))
.
2007-12-30 20:06 . 2007-12-30 20:13 <DIR> d-------- C:\Documents and Settings\Prox.PROX-DD28CKH3TD\Gadu-Gadu
2007-12-30 19:58 . 2007-12-30 19:58 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-30 19:51 . 2007-12-30 19:51 <DIR> d-------- C:\Program Files\C-Media
2007-12-30 19:50 . 2007-12-30 19:54 26 --a------ C:\WINDOWS\CMCDPLAY.INI
2007-12-30 19:48 . 2007-12-30 19:48 <DIR> d-------- C:\WINDOWS\SiS
2007-12-30 19:48 . 2002-04-25 14:42 316,416 --a------ C:\WINDOWS\IsUninst.exe
2007-12-30 19:48 . 2002-05-22 09:11 27,392 -ra------ C:\WINDOWS\system32\drivers\SISAGP.SYS
2007-12-30 19:48 . 2002-05-22 09:11 27,392 --a--c--- C:\WINDOWS\system32\dllcache\sisagp.sys
2007-12-30 19:47 . 1998-01-23 14:15 304,640 --a------ C:\WINDOWS\IsUn0415.exe
2007-12-30 19:47 . 2002-04-26 10:17 102,400 -ra------ C:\WINDOWS\SiSUSBrg.exe
2007-12-30 19:47 . 2002-01-02 08:40 32,768 -ra------ C:\WINDOWS\SIS_LIB.DLL
2007-12-30 19:47 . 2001-12-07 03:11 3,583 -ra------ C:\WINDOWS\SiSport.sys
2007-12-30 19:46 . 2007-12-30 19:47 397,312 --a------ C:\WINDOWS\system32\symantec.exe
2007-12-30 19:45 . 2007-12-30 19:46 <DIR> d-------- C:\WINDOWS\system32\Tools
2007-12-30 19:39 . 2007-12-30 19:44 28,672 -ra------ C:\WINDOWS\system32\TFTP2164
2007-12-30 19:28 . 2007-12-30 19:28 397,312 -r-hs---- C:\WINDOWS\system\msnrav.exe
2007-12-30 19:28 . 2007-12-30 19:46 73 --a------ C:\WINDOWS\system32\i
2007-12-30 19:17 . 2007-12-30 19:18 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-30 18:44 . 2007-12-30 18:44 <DIR> d-------- C:\Program Files\InCode Solutions
2007-12-30 18:12 . 2007-12-30 18:14 <DIR> d-------- C:\Documents and Settings\Prox.PROX-DD28CKH3TD\.housecall6.6
2007-12-30 18:10 . 2007-12-30 18:10 <DIR> d-------- C:\WINDOWS\Sun
2007-12-30 18:09 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-30 17:51 . 2007-12-30 17:51 250 --a------ C:\WINDOWS\gmer.ini
2007-12-30 17:46 . 2007-12-30 17:46 <DIR> d-------- C:\Documents and Settings\Prox.PROX-DD28CKH3TD\Dane aplikacji\Lavasoft
2007-12-30 17:45 . 2007-12-30 17:45 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-27 16:49 . 2007-12-27 16:49 <DIR> d-------- C:\Documents and Settings\Rodzice\Dane aplikacji\Search Settings
2007-12-26 16:12 . 2007-12-26 17:04 <DIR> d-------- C:\Program Files\VirtualDJ
2007-12-24 13:45 . 2007-12-24 13:45 <DIR> d-------- C:\Program Files\Rozgiwazdkowujacy
2007-12-23 21:52 . 2007-12-23 21:52 <DIR> d-------- C:\Program Files\Search Settings
2007-12-23 21:47 . 2007-12-23 21:50 <DIR> d-------- C:\Program Files\Free Audio Pack
2007-12-23 21:35 . 2007-12-23 21:39 <DIR> d-------- C:\Program Files\GXTranscoder v2
2007-12-23 21:26 . 2007-12-23 21:28 7,500,244 --a------ C:\My Musicnagr14.mp3
2007-12-23 21:24 . 2007-12-23 21:26 8,921,755 --a------ C:\My Musicnagr13.mp3
2007-12-23 18:19 . 2007-12-23 18:39 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-12-23 14:15 . 2007-12-23 20:16 <DIR> d-------- C:\Program Files\The All-Seeing Eye
2007-12-23 11:36 . 2007-12-23 11:36 <DIR> d-------- C:\Program Files\GoldWave
2007-12-20 23:50 . 2007-12-20 23:50 <DIR> d-------- C:\Program Files\LuckaSoft
2007-12-12 20:13 . 2007-12-12 20:13 5,209 --a------ C:\irysa playlista.fpl
2007-12-07 23:25 . 2007-12-07 23:32 <DIR> d-------- C:\Program Files\VstPlugins
2007-12-07 23:25 . 2007-12-07 23:25 <DIR> d-------- C:\Program Files\ASIO4ALL v2
2007-12-07 23:22 . 2007-12-07 23:31 <DIR> d-------- C:\Program Files\Image-Line
2007-12-05 18:14 . 2007-11-28 19:28 210 --ahs---- C:\BOOT.BKK
2007-11-29 13:51 . 2007-11-29 14:03 <DIR> d-------- C:\Program Files\Konnekt
2007-11-28 20:21 . 2007-11-28 20:21 <DIR> d-------- C:\Program Files\Uniblue
2007-11-28 16:10 . 2007-11-28 16:52 <DIR> d-------- C:\Program Files\TweakNow RegCleaner Pro
2007-11-27 22:31 . 2007-11-27 22:31 <DIR> d-------- C:\Documents and Settings\LocalService\Dane aplikacji\iolo
2007-11-27 17:53 . 2007-11-29 13:43 <DIR> d-------- C:\Program Files\Tlen.pl
2007-11-27 14:58 . 2007-11-27 14:58 <DIR> d-------- C:\Program Files\WapSter
2007-11-26 15:03 . 2007-11-26 15:03 <DIR> d-------- C:\Program Files\TGTSoft
2007-11-25 17:17 . 2007-11-25 17:17 <DIR> d-------- C:\Program Files\Audacity
2007-11-25 14:35 . 2007-11-25 20:05 <DIR> d-------- C:\Program Files\PowerStrip
2007-11-24 13:59 . 2007-11-25 14:33 <DIR> d-------- C:\Program Files\ATITool
2007-11-23 16:27 . 2007-12-01 20:43 <DIR> d-------- C:\Documents and Settings\Prox\dwhelper
2007-11-23 14:04 . 2007-11-23 14:37 <DIR> d-------- C:\Program Files\Tibia 7.6
2007-11-23 13:52 . 2007-11-23 13:52 <DIR> d-------- C:\Program Files\Asprate
2007-11-22 12:21 . 2007-11-22 12:21 <DIR> d-------- C:\Program Files\RadioXpi
2007-11-16 19:04 . 2007-11-16 19:04 <DIR> d-------- C:\Program Files\Teamspeak2_RC2
2007-11-16 13:38 . 2007-11-16 13:54 <DIR> d-------- C:\Program Files\SHOUTcast
2007-11-16 13:36 . 2007-11-16 13:50 <DIR> d-------- C:\Program Files\Winamp
2007-11-15 20:27 . 2007-12-25 23:59 <DIR> d-------- C:\Program Files\Bit Che
2007-11-15 20:17 . 2007-11-15 20:17 <DIR> d-------- C:\Program Files\Tibia
2007-11-15 18:48 . 2007-11-15 20:26 <DIR> d-------- C:\Program Files\Runtime Software
2007-11-13 20:11 . 2007-11-13 20:11 <DIR> d-------- C:\Program Files\Ventrilo
2007-11-10 19:37 . 2007-11-10 19:38 <DIR> d-------- C:\Program Files\Dziobas Rar Player 0.0087a
2007-11-04 21:37 . 2007-11-04 21:37 <DIR> d-------- C:\Program Files\MySQL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-30 19:05 --------- d-----w C:\Program Files\foobar2000
2007-12-30 18:55 --------- d-----w C:\Program Files\MozdevMozilla2.0
2007-12-30 18:45 397,312 ----a-w C:\WINDOWS\system32\norman.exe
2007-12-30 17:16 --------- d-----w C:\Program Files\Diablo II
2007-12-30 17:08 --------- d-----w C:\Program Files\Java
2007-12-30 15:59 --------- d-----w C:\Documents and Settings\Prox.PROX-DD28CKH3TD\Dane aplikacji\Smart PC Solutions
2007-12-30 15:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\TEMP
2007-12-30 15:58 512,096 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2007-12-30 15:58 298,104 ----a-w C:\WINDOWS\system32\imon.dll
2007-12-30 15:58 15,424 ----a-w C:\WINDOWS\system32\drivers\nod32drv.sys
2007-12-30 15:46 --------- d-----w C:\Program Files\ToniArts
2007-12-30 15:39 --------- d-----w C:\Documents and Settings\Prox.PROX-DD28CKH3TD\Dane aplikacji\stamina
2007-12-30 15:38 --------- d-----w C:\Documents and Settings\Prox.PROX-DD28CKH3TD\Dane aplikacji\Talkback
2007-12-30 15:38 --------- d-----w C:\Documents and Settings\Prox.PROX-DD28CKH3TD\Dane aplikacji\Search Settings
2007-12-30 15:32 23 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2007-12-30 15:17 --------- d-----w C:\Program Files\Usługi online
2007-12-29 19:25 --------- d-----w C:\Program Files\Valve
2007-12-29 13:00 --------- d-----w C:\Program Files\PeerGuardian2
2007-12-25 22:50 --------- d-----w C:\Program Files\VirtualDJJ
2007-12-12 13:53 --------- d-----w C:\Program Files\IrfanView
2007-12-11 18:12 --------- d-----w C:\Program Files\mIRC
2007-12-05 16:55 --------- d-----w C:\Program Files\SpeedFan
2007-11-28 14:27 --------- d-----w C:\Program Files\SmartFTP Client
2007-11-28 14:16 --------- d-----w C:\Program Files\Gadu-Gadu
2007-11-25 21:43 --------- d-----w C:\Program Files\Google
2007-11-24 13:58 --------- d-----w C:\Program Files\ATI Technologies
2007-11-24 13:02 --------- d-----w C:\Program Files\EA SPORTS
2007-11-13 19:11 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-11 19:03 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-10 19:30 --------- d-----w C:\Program Files\FlashGet
2006-12-19 17:07 2,208 ----a-w C:\Program Files\unins000.dat
2006-12-01 14:57 16,173,421 ----a-w C:\Program Files\Vi
2006-07-28 16:35 9 ----a-w C:\Program Files\version.wvd
2006-07-27 20:49 58 ----a-w C:\Program Files\font.ini
2006-07-27 20:49 57 ----a-w C:\Program Files\partition.inf
2006-01-10 08:52 70 ----a-w C:\Program Files\config.ini
2003-06-16 14:23 131,072 ----a-w C:\Program Files\T2DXi.dll
2002-12-17 02:00 82,253 ----a-w C:\Program Files\unins000.exe
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((( snapshot@2007-12-30_19.16.37.64 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-29 06:04:43 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-12-30 18:18:05 667,648 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2007-12-30 18:18:06 143,360 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2007-12-29 06:04:43 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2007-12-30 18:18:02 667,648 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2007-12-30 18:18:02 143,360 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2000-10-20 10:28:00 765,952 ----a-r C:\WINDOWS\system\crlds3d.dll
+ 2001-11-23 04:08:20 712,704 ----a-r C:\WINDOWS\system32\a3d.dll
+ 2001-11-23 04:08:20 712,704 ----a-r C:\WINDOWS\system32\Audio3D.dll
- 2007-12-30 16:37:16 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-30 18:47:35 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-30 16:37:16 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2007-12-30 18:47:35 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2007-12-30 18:47:35 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
+ 2001-11-23 04:08:20 712,704 -c--a-w C:\WINDOWS\system32\dllcache\a3d.dll
+ 2001-08-17 21:01:20 57,344 -c--a-w C:\WINDOWS\system32\dllcache\drmk.sys
+ 2001-08-18 05:24:30 134,144 -c--a-w C:\WINDOWS\system32\dllcache\ks.sys
+ 2001-10-26 16:27:02 4,096 -c--a-w C:\WINDOWS\system32\dllcache\ksuser.dll
+ 2001-08-18 05:24:38 135,040 -c--a-w C:\WINDOWS\system32\dllcache\portcls.sys
+ 2001-08-17 21:01:22 42,752 -c--a-w C:\WINDOWS\system32\dllcache\stream.sys
+ 2002-03-06 06:27:02 389,135 ----a-r C:\WINDOWS\system32\drivers\cmuda.sys
- 2001-10-26 18:03:24 134,144 ----a-w C:\WINDOWS\system32\drivers\ks.sys
+ 2001-08-18 05:24:30 134,144 ----a-w C:\WINDOWS\system32\drivers\ks.sys
- 2001-10-26 18:03:24 42,752 ----a-w C:\WINDOWS\system32\drivers\stream.sys
+ 2001-08-17 21:01:22 42,752 ----a-w C:\WINDOWS\system32\drivers\stream.sys
- 2007-12-30 16:04:45 39,992 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-30 18:56:12 39,992 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-12-30 16:04:45 49,492 ----a-w C:\WINDOWS\system32\perfc015.dat
+ 2007-12-30 18:56:12 49,492 ----a-w C:\WINDOWS\system32\perfc015.dat
- 2007-12-30 16:04:45 311,604 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-30 18:56:12 311,604 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-12-30 16:04:45 355,486 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2007-12-30 18:56:12 355,486 ----a-w C:\WINDOWS\system32\perfh015.dat
+ 2001-08-17 20:58:02 26,112 ----a-w C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\SISAGP.SYS
+ 2001-03-07 21:19:08 311,296 ---h--r C:\WINDOWS\system32\Tools\AC2K.exe
+ 2001-02-21 02:36:12 310,784 ---h--r C:\WINDOWS\system32\Tools\AC98.exe
+ 2001-02-21 02:37:08 311,296 ---h--r C:\WINDOWS\system32\Tools\ACL98.exe
+ 2001-02-21 02:38:00 311,808 ---h--r C:\WINDOWS\system32\Tools\ACLME.exe
+ 2001-04-27 21:27:06 327,168 ---h--r C:\WINDOWS\system32\Tools\All.exe
+ 2000-11-24 02:33:44 316,416 ---h--r C:\WINDOWS\system32\Tools\AutoClick.exe
+ 2001-10-16 19:06:02 363,008 ---h--r C:\WINDOWS\system32\Tools\Change.exe
+ 2002-04-11 04:07:12 547,840 ---h--r C:\WINDOWS\system32\Tools\CheckPath.exe
+ 2001-08-30 23:16:28 381,440 ---h--r C:\WINDOWS\system32\Tools\Counter.exe
+ 2002-01-21 04:10:30 360,960 ---h--r C:\WINDOWS\system32\Tools\DelDv.exe
+ 2001-03-20 01:50:52 532,480 ---h--r C:\WINDOWS\system32\Tools\DeleteFiles.exe
+ 2002-01-21 04:09:44 360,960 ---h--r C:\WINDOWS\system32\Tools\DelT2.exe
+ 2002-01-21 04:09:58 360,960 ---h--r C:\WINDOWS\system32\Tools\DelT2Dv.exe
+ 2002-03-06 07:55:34 360,960 ---h--r C:\WINDOWS\system32\Tools\DelTools.exe
+ 2002-03-11 07:33:46 361,472 ---h--r C:\WINDOWS\system32\Tools\LostRun.exe
+ 2001-04-03 03:23:54 296,960 ---h--r C:\WINDOWS\system32\Tools\RegClean.exe
+ 2002-03-08 03:44:14 369,152 ---h--r C:\WINDOWS\system32\Tools\Regexe.exe
+ 2002-03-08 03:30:28 382,464 ---h--r C:\WINDOWS\system32\Tools\Restart.exe
+ 2002-03-08 03:48:26 374,784 ---h--r C:\WINDOWS\system32\Tools\RunAP.exe
+ 2002-03-08 03:52:52 360,960 ---h--r C:\WINDOWS\system32\Tools\RunRegexe.exe
+ 2001-11-02 20:19:44 379,392 ---h--r C:\WINDOWS\system32\Tools\SDW98ME.exe
+ 2001-03-09 19:32:00 312,832 ---h--r C:\WINDOWS\system32\Tools\SoundDrv.exe
+ 2001-09-24 04:23:42 28,672 ----a-r C:\WINDOWS\system32\udaprop.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-10-26 18:29]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2006-02-17 14:03]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-12-30 16:58]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-04-26 10:17]
"Cmaudio"="RunDll32 cmicnfg.cpl" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 18:29]
C:\Documents and Settings\Prox.PROX-DD28CKH3TD\Menu Start\Programy\Autostart\
Reboot.exe [2002-03-21 05:40:42]
C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-05-06 19:38:33]
R2 SMSCGISVC;System Managment Controler;"C:\WINDOWS\system\smscg.exe" [2007-12-30 16:49]
R4 MSN RAV;MSN RAV;"C:\WINDOWS\system\msnrav.exe" [2007-12-30 19:28]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-30 20:24:20
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.0000]
-> C:\Program Files\Eset\pr_imon.dll
.
Completion time: 2007-12-30 20:25:17
C:\ComboFix2.txt ... 2007-12-30 19:17