Log z ComboFix
"Admin" - 2007-05-13 22:25:07 Dodatek Service Pack 2
ComboFix 07-05.13.V - Running from: "C:\DOCUME~1\Admin\USTAWI~1\Temp\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\keyboard1.dat
C:\Program Files\outlook\p.zip
C:\Program Files\winupdates\a.zip
C:\Program Files\install.log
C:\WINDOWS\system\smss.exe
C:\Program Files\outlook
C:\Program Files\winupdates
C:\Program Files\video access activex object
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CMDSERVICE
-------\LEGACY_WINDOWS_LOG
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-13 ))))))))))))))))))))))))))))))))))
2007-05-09 12:52 <DIR> d-------- C:\DOCUME~1\Admin\Braciszek
2007-05-07 20:36 <DIR> d-------- C:\Program Files\FlusiFix-2006
2007-04-27 22:08 <DIR> d-------- C:\DOCUME~1\Admin\DANEAP~1\DivX
2007-04-24 12:35 <DIR> d-------- C:\Program Files\DAEMON Tools
2007-04-24 12:05 755,200 --a------ C:\WINDOWS\system32\ir50_32.dll
2007-04-24 12:03 639,066 --a------ C:\WINDOWS\system32\DivX.dll
2007-04-23 15:32 <DIR> dr-h----- C:\DOCUME~1\Admin\DANEAP~1\SecuROM
2007-04-23 10:30 <DIR> d-------- C:\Tlen_pliki
2007-04-14 17:47 56,320 --------- C:\WINDOWS\system32\iyvu9_32.dll
2007-04-14 17:47 136,704 --a------ C:\WINDOWS\system32\iacenc.dll
2007-04-14 17:47 <DIR> d-------- C:\Program Files\Ligos
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2060-08-18 18:02:22 1,496,064 ------w C:\WINDOWS\system32\CC3250MT.DLL
2060-08-18 17:40:44 909,824 ------w C:\WINDOWS\system32\cp3245mt.dll
2060-08-18 17:40:44 24,064 ------w C:\WINDOWS\system32\borlndmm.dll
2007-05-13 20:21:38 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\The Bat!
2007-05-13 20:21:36 -------- d-----w C:\Program Files\eMule
2007-05-12 11:11:05 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\Tlen.pl
2007-05-10 08:01:29 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\Skype
2007-05-01 19:00:09 -------- d-----w C:\Program Files\GetRight
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-04-24 06:59:23 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-04-23 14:19:14 682,232 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-04-05 07:31:48 -------- d-----w C:\Program Files\Kalendarz XP
2007-03-27 19:19:55 -------- d-----w C:\Program Files\Multi_Media
2007-03-27 07:45:02 -------- d-----w C:\Program Files\FrostWire
2007-03-26 18:32:41 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\FrostWire
2007-03-25 20:10:08 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\FSAutoStart
2007-03-25 20:09:21 -------- d-----w C:\Program Files\ASRC
2007-03-25 09:33:38 74,230 ----a-w C:\WINDOWS\system32\perfc015.dat
2007-03-25 09:33:38 448,004 ----a-w C:\WINDOWS\system32\perfh015.dat
2007-03-24 20:36:08 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-03-19 18:13:10 6,422,611 ----a-w C:\Program Files\frostwire-4.13.1.6.windows.exe
2007-03-19 18:08:42 359,040 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2007-03-17 21:45:55 -------- d-----w C:\Program Files\Boeing737FPL
2007-03-13 09:28:13 -------- d-----w C:\Program Files\Jezyk Angielski dla kazdego
2007-03-13 09:28:13 -------- d-----w C:\Program Files\Common Files\YDP
2007-03-13 09:27:14 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll
2007-03-13 09:27:14 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
2007-03-11 12:53:50 -------- d-----w C:\Program Files\VRC
2007-03-11 12:02:45 -------- d-----w C:\Program Files\FSFDT
2007-02-13 15:19:19 1,328 ----a-w C:\FSUIPC_reg.bin
2007-02-05 15:41:18 56 --sh--r C:\WINDOWS\system32\3A8EDB2F66.sys
2007-02-05 15:41:18 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 21:38]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}=C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [2006-10-31 08:55]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"HP Software Update"="C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb08.exe"
"DeviceDiscovery"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpotdd01.exe"
"FineReader7NewsReaderPro"="C:\\Program Files\\ABBYY FineReader 7.0 Professional Edition\\AbbyyNewsReader.exe"
"WheelMouse"="C:\\Program Files\\A4Tech\\Mouse\\Amoumain.exe"
"WatchDog"="C:\\Program Files\\mobile PhoneTools\\WatchDog.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2002-12-17 11:40]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-11 12:08]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2002-12-02 20:56]
"FineReader7NewsReaderPro"="C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe" [2003-08-05 16:16]
"WheelMouse"="C:\Program Files\A4Tech\Mouse\Amoumain.exe" [2006-04-12 20:44]
"WatchDog"="C:\Program Files\mobile PhoneTools\WatchDog.exe" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-07-15 12:42]
"nwiz"="nwiz.exe" [2004-07-15 12:42 C:\WINDOWS\system32\nwiz.exe])
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-07-15 12:42]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-11-24 15:38]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2006-10-10 17:51]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-04 00:29]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-04-23 15:12]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\lib\\NMBgMonitor.exe\""
"Gadu-Gadu"="\"C:\\Program Files\\Gadu-Gadu\\gg.exe\" /tray"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_8 -reboot 1"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"eMuleAutoStart"="C:\\Program Files\\eMule\\emule.exe -AutoStart"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter HTTPFilter\0\0
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
DcomLaunch DcomLaunch\0TermService\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20061214-220811-660
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
backup-20061023-113622-795
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
backup-20060909-193420-257
O4 - HKCU\..\Run: [mwzk] C:\PROGRA~1\COMMON~1\mwzk\mwzkm.exe
backup-20060909-193420-990
R3 - Default URLSearchHook is missing
backup-20060909-193420-168
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
backup-20060909-193420-822
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
backup-20060909-193420-427
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
backup-20060909-193420-647
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
backup-20060909-193420-448
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-13 22:27:47
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-13 22:28:05 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-13 22:28