"" - 2007-06-27 9:54:46 - ComboFix 07-06-27.7 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\new_drv.sys
C:\WINDOWS\system32\kdffi.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NEW_DRV
((((((((((((((((((((((((( Files Created from 2007-05-27 to 2007-06-27 )))))))))))))))))))))))))))))))
2007-06-27 09:53 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-21 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-06-20 22:46 78,608 --a------ C:\WINDOWS\system32\VB5DB.DLL
2007-06-20 22:46 73,216 --a------ C:\WINDOWS\system32\Odbctl32.dll
2007-06-20 22:46 407,312 --a------ C:\WINDOWS\system32\msrepl35.dll
2007-06-20 22:46 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2007-06-20 22:46 252,176 --a------ C:\WINDOWS\system32\msrd2x35.dll
2007-06-20 22:46 24,848 --a------ C:\WINDOWS\system32\msjter35.dll
2007-06-20 22:46 123,664 --a------ C:\WINDOWS\system32\Msjint35.dll
2007-06-20 22:46 1,045,776 --a------ C:\WINDOWS\system32\msjet35.dll
2007-06-20 22:46 <DIR> d-------- C:\Program Files\Sierra On-Line
2007-06-17 10:21 <DIR> d-------- C:\DOCUME~1\Ronald\APPLIC~1\ACD Systems
2007-06-17 10:14 <DIR> d-------- C:\Program Files\Yahoo!
2007-06-17 10:12 10,368 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2007-06-17 10:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ACD Systems
2007-06-16 22:09 <DIR> d-------- C:\Program Files\Skype
2007-06-16 22:09 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-06-14 15:04 <DIR> d-------- C:\DOCUME~1\Ronald\APPLIC~1\GetRightToGo
2007-06-14 14:12 28,672 --a------ C:\WINDOWS\Photo Express 3.scr
2007-06-07 22:54 <DIR> d-------- C:\DOCUME~1\Ronald\APPLIC~1\Sony
2007-06-07 22:54 <DIR> d-------- C:\DOCUME~1\Ronald\APPLIC~1\Publish Providers
2007-06-07 22:50 <DIR> d-------- C:\Program Files\Vstplugins
2007-06-01 07:44 855,040 --a------ C:\WINDOWS\system32\Ltwvc12n.dll
2007-06-01 07:44 406,016 --a------ C:\WINDOWS\system32\ltkrn12n.dll
2007-06-01 07:44 313,856 --a------ C:\WINDOWS\system32\ltdlg12n.dll
2007-06-01 07:44 313,856 --a------ C:\WINDOWS\system32\LFCMP12n.DLL
2007-06-01 07:44 278,528 --a------ C:\WINDOWS\system32\LTDIS12n.dll
2007-06-01 07:44 227,840 --a------ C:\WINDOWS\system32\ltefx12n.dll
2007-06-01 07:44 166,400 --a------ C:\WINDOWS\system32\ltimg12n.dll
2007-06-01 07:44 146,944 --a------ C:\WINDOWS\system32\ltfil12n.dll
2007-05-31 20:53 78 --ah----- C:\WINDOWS\erty.dat
2007-05-29 18:00 740,442 --a------ C:\WINDOWS\system32\divx.dll
2007-05-29 18:00 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-05-29 18:00 593,920 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-05-29 18:00 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-05-29 18:00 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-05-29 18:00 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-05-29 18:00 1,565,480 --a------ C:\WINDOWS\system32\wmv9vcm.dll
2007-05-29 18:00 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-05-27 23:43 <DIR> d-------- C:\DOCUME~1\Ronald\APPLIC~1\Opera
2007-05-27 23:40 <DIR> d-------- C:\Program Files\Opera
2007-05-27 10:20 <DIR> d-------- C:\DOCUME~1\Ronald\APPLIC~1\Costco Photo Viewer
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-27 13:58:18 -------- d-----w C:\DOCUME~1\Ronald\APPLIC~1\uTorrent
2007-06-27 13:58:06 -------- d-----w C:\Program Files\PeerGuardian2
2007-06-27 12:47:45 -------- d-----w C:\DOCUME~1\Ronald\APPLIC~1\Skype
2007-06-27 12:35:45 -------- d-----w C:\Program Files\eMule
2007-06-27 12:15:45 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-26 19:20:16 -------- d-----w C:\Program Files\Mozilla Thunderbird
2007-06-23 04:40:56 -------- d-----w C:\Program Files\RegCleaner
2007-06-19 16:38:34 -------- d-----w C:\Program Files\Common Files\Ulead Systems
2007-06-18 15:42:41 -------- d-----w C:\Program Files\FM Modifier 2.1
2007-06-17 02:33:11 28,648 ----a-w C:\WINDOWS\mozver.dat
2007-06-17 02:29:18 118,784 ----a-w C:\WINDOWS\SeaMonkeyUninstall.exe
2007-06-14 02:37:15 -------- d-----w C:\Program Files\EA GAMES
2007-06-01 11:45:40 -------- d-----w C:\Program Files\Beston
2007-06-01 04:56:08 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-05-31 09:59:57 -------- d-----w C:\Program Files\iTunes
2007-05-30 12:05:07 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-05-29 22:08:22 2,065 --sha-w C:\WINDOWS\system32\mmf.sys
2007-05-29 21:53:28 -------- d-----w C:\Program Files\ffdshow
2007-05-28 04:30:09 -------- d-----w C:\Program Files\mozilla.org
2007-05-24 17:24:12 -------- d-----w C:\DOCUME~1\Ronald\APPLIC~1\Thunderbird
2007-05-24 14:09:48 -------- d-----w C:\DOCUME~1\Ronald\APPLIC~1\GlarySoft
2007-05-24 13:59:35 -------- d-----w C:\Program Files\Absolute Uninstaller
2007-05-24 11:48:45 -------- d-----w C:\Program Files\Google
2007-05-24 02:34:05 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-05-24 01:43:22 -------- d-----w C:\Program Files\Globe Software
2007-05-23 23:20:29 -------- d-----w C:\Program Files\Gadu-Gadu
2007-05-23 23:15:45 -------- d-----w C:\Program Files\uTorrent
2007-05-23 21:19:05 -------- d-----w C:\Program Files\RocketDock
2007-05-17 15:06:52 -------- d-----w C:\Program Files\QuickTime
2007-05-17 14:52:36 -------- d-----w C:\Program Files\Odkurzacz
2007-05-09 02:47:25 50,688 ----a-w C:\WINDOWS\system32\wbhelp2.dll
2007-05-08 19:17:13 -------- d-----w C:\Program Files\WMV9_VCM
2007-05-06 16:57:20 -------- d-----w C:\Program Files\Common Files\DirectX
2007-05-06 13:52:19 -------- d-----w C:\DOCUME~1\Ronald\APPLIC~1\ESTSoft
2007-05-06 13:52:04 -------- d-----w C:\Program Files\ESTsoft
2007-05-06 03:12:33 -------- d-----w C:\DOCUME~1\Ronald\APPLIC~1\Movie Label
2007-05-05 20:20:20 -------- d-----w C:\Program Files\Audacity
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-04-13 02:06:25 48,640 ----a-w C:\WINDOWS\mmfs.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-06-06 09:28]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-03-09 15:29 C:\WINDOWS\system32\nwiz.exe]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2002-10-11 21:26]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 11:42]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 16:09]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 17:00]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 15:29]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 15:56]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-19 00:05]
"StatBar"="C:\Program Files\Globe Software\StatBar\StatBar.exe" [2003-07-25 02:40]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40]
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-27 09:59:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-27 10:01:12 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-27 10:00
--- E O F ---
[ Dodano: Dzisiaj o 15:48 ] Logfile of HijackThis v1.99.1
Scan saved at 10:22:52, on 2007-06-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\mozilla.org\SeaMonkey\seamonkey.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Globe Software\StatBar\StatBar.exe
d:\Documents and Settings\Ronald\My Documents\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [StatBar] C:\Program Files\Globe Software\StatBar\StatBar.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
[ Dodano: Dzisiaj o 16:23 ] Stwierdzam, że nadal mam ten sam problem z "zamrażaniem". Głównie gierki mi się zatrzymują ale nawet jak pisze na forum to litery wyskakują ze sporym opóźnieniem....
[ Dodano: Dzisiaj o 17:37 ] Hm, przeinstalowalem directX i wtłączyłem torrenta... jak ręką odjął.
Przynajmniej na razie...