ComboFix 08-03-17.1 - x 2008-03-19 15:07:18.2 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.1401 [GMT 1:00]
Running from: C:\logi wirusa\ComboFix.exe
Command switches used :: C:\logi wirusa\CFScript.txt
 * Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\amp.bat
C:\WINDOWS\nxstinst.exe
C:\WINDOWS\remover.dll
C:\WINDOWS\wmpdxm.dll
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\amp.bat
C:\Program Files\NavExcel Search Toolbar
C:\Program Files\NavExcel Search Toolbar\settings.dat
C:\Program Files\whInstall
C:\Program Files\whInstall\license.txt
C:\Program Files\whInstall\readme.txt
C:\Program Files\whInstall\Sporder.dll
C:\Program Files\whInstall\whAgent.inf
C:\Program Files\whInstall\whAgent.ini
C:\Program Files\whInstall\whInstaller.ini
C:\WINDOWS\nxstinst.exe
C:\WINDOWS\remover.dll
C:\WINDOWS\wmpdxm.dll
.
(((((((((((((((((((((((((   Files Created from 2008-02-19 to 2008-03-19  )))))))))))))))))))))))))))))))
.
2008-03-18 14:18 . 2008-03-19 15:07	<DIR>	d--------	C:\logi wirusa
2008-03-16 17:54 . 2008-03-16 17:54	54,156	--ah-----	C:\WINDOWS\QTFont.qfn
2008-03-16 17:54 . 2008-03-16 17:54	1,409	--a------	C:\WINDOWS\QTFont.for
2008-03-16 17:52 . 2006-09-18 14:58	61,600	-ra------	C:\WINDOWS\system32\drivers\SE27bus.sys
2008-03-16 17:52 . 2006-09-18 14:59	5,872	-ra------	C:\WINDOWS\system32\drivers\SE27whnt.sys
2008-03-16 17:52 . 2006-09-18 14:59	5,872	-ra------	C:\WINDOWS\system32\drivers\SE27wh.sys
2008-03-16 17:01 . 2008-03-16 17:01	<DIR>	d--------	C:\Program Files\Alwil Software
2008-03-16 17:01 . 2007-12-04 14:04	837,496	--a------	C:\WINDOWS\system32\aswBoot.exe
2008-03-16 17:01 . 2004-01-09 10:13	380,928	--a------	C:\WINDOWS\system32\actskin4.ocx
2008-03-16 17:01 . 2007-12-04 13:54	95,608	--a------	C:\WINDOWS\system32\AvastSS.scr
2008-03-16 17:01 . 2007-12-04 15:55	94,544	--a------	C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-16 17:01 . 2007-12-04 15:56	93,264	--a------	C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-16 17:01 . 2007-12-04 15:51	42,912	--a------	C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-16 17:01 . 2007-12-04 15:49	26,624	--a------	C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-16 17:01 . 2007-12-04 15:53	23,152	--a------	C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-16 16:54 . 2008-03-16 16:54	<DIR>	d--------	C:\Program Files\ToniArts
2008-03-16 16:35 . 2008-03-16 16:35	0	--a------	C:\WINDOWS\nsreg.dat
2008-03-15 12:11 . 2008-03-15 12:17	1,392	--a------	C:\WINDOWS\mozver.dat
2008-03-09 16:42 . 2008-03-09 16:42	<DIR>	dr-hs----	C:\Recycled
2008-03-01 23:28 . 2008-03-01 23:28	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\Creative
2008-03-01 10:35 . 2008-03-01 23:28	<DIR>	d--------	C:\Documents and Settings\x\Dane aplikacji\Creative
2008-02-29 20:17 . 2006-06-18 18:01	282,624	-ra------	C:\WINDOWS\system32\V0250Cvw.dll
2008-02-29 20:15 . 2000-05-22 09:58	647,872	---------	C:\WINDOWS\system32\Mscomct2.ocx
2008-02-29 20:15 . 1999-10-10 18:00	41,984	---------	C:\WINDOWS\Ctregrun.exe
2008-02-29 20:15 . 2003-06-12 23:25	7,062	--a------	C:\WINDOWS\system32\audiopid.vxd
2008-02-29 20:14 . 2008-02-29 20:14	<DIR>	d--------	C:\WINDOWS\CtDrvInstall
2008-02-29 20:06 . 2008-02-29 20:14	<DIR>	d--------	C:\Program Files\SightSpeed
2008-02-29 20:06 . 1998-10-29 16:45	306,688	--a------	C:\WINDOWS\IsUninst.exe
2008-02-29 20:03 . 2008-02-29 20:14	<DIR>	d--------	C:\Program Files\Creative
2008-02-29 17:34 . 2006-11-07 09:42	97,056	-ra------	C:\WINDOWS\system32\drivers\w200mdm.sys
2008-02-29 17:34 . 2006-11-07 09:42	88,560	-ra------	C:\WINDOWS\system32\drivers\w200mgmt.sys
2008-02-29 17:34 . 2006-11-07 09:42	86,368	-ra------	C:\WINDOWS\system32\drivers\w200obex.sys
2008-02-29 17:34 . 2006-11-07 09:42	9,328	-ra------	C:\WINDOWS\system32\drivers\w200mdfl.sys
2008-02-29 17:34 . 2006-11-07 09:42	6,208	-ra------	C:\WINDOWS\system32\drivers\w200cmnt.sys
2008-02-29 17:34 . 2006-11-07 09:42	6,208	-ra------	C:\WINDOWS\system32\drivers\w200cm.sys
2008-02-29 17:30 . 2006-11-07 09:42	61,504	-ra------	C:\WINDOWS\system32\drivers\w200bus.sys
2008-02-29 17:30 . 2006-11-07 09:42	5,840	-ra------	C:\WINDOWS\system32\drivers\w200whnt.sys
2008-02-29 17:30 . 2006-11-07 09:42	5,840	-ra------	C:\WINDOWS\system32\drivers\w200wh.sys
2008-02-29 14:29 . 2008-03-19 08:24	<DIR>	d--------	C:\Documents and Settings\x\Dane aplikacji\skypePM
2008-02-29 14:29 . 2008-02-29 14:29	32	--a------	C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-02-29 13:22 . 2008-03-19 14:50	<DIR>	d--------	C:\Documents and Settings\x\Dane aplikacji\Skype
2008-02-28 21:18 . 2008-02-28 21:18	<DIR>	d--------	C:\Program Files\Skype
2008-02-28 21:18 . 2008-02-28 21:18	<DIR>	d--------	C:\Program Files\Common Files\Skype
2008-02-28 21:18 . 2008-02-28 21:18	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-02-27 18:55 . 2008-03-16 16:27	<DIR>	d--------	C:\Program Files\Winamp
2008-02-25 21:33 . 2008-02-25 21:33	6,663,744	--a------	C:\WINDOWS\system32\A0047180.EXE.VBTMP
2008-02-25 19:06 . 2008-02-25 19:06	6,663,744	--a------	C:\WINDOWS\system32\msaccess.exe.VBTMP
2008-02-25 19:05 . 2008-03-16 17:02	<DIR>	d--------	C:\Program Files\Google
2008-02-25 19:05 . 2008-03-16 16:10	<DIR>	d-a------	C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-02-24 18:52 . 2008-02-24 18:52	50	--a------	C:\WINDOWS\Winamp.ini
2008-02-24 18:52 . 2008-02-24 18:52	41	--a------	C:\WINDOWS\winampa.ini
2008-02-24 18:19 . 2008-02-24 18:19	<DIR>	d--------	C:\Program Files\Ares
2008-02-23 20:28 . 2008-02-23 20:28	<DIR>	d--------	C:\Documents and Settings\x\Dane aplikacji\Gadu-Gadu
2008-02-23 20:24 . 2008-02-23 20:24	<DIR>	d--------	C:\Program Files\Gadu-Gadu
2008-02-23 20:24 . 2008-03-10 18:47	<DIR>	d--------	C:\Documents and Settings\x\Gadu-Gadu
2008-02-23 13:08 . 2008-02-23 13:08	<DIR>	d--------	C:\Program Files\ZyDAS Technology Corporation
2008-02-23 13:08 . 2006-08-24 13:44	477,696	--a------	C:\WINDOWS\system32\drivers\ZD1211BU.sys
2008-02-23 13:08 . 2004-01-14 11:25	81,920	--a------	C:\WINDOWS\system32\ZDPN50.DLL
2008-02-23 13:08 . 2005-03-18 15:35	31,744	--a------	C:\WINDOWS\system32\drivers\ZDPSp50a64.sys
2008-02-23 13:08 . 2005-06-08 18:44	29,184	--a------	C:\WINDOWS\system32\drivers\BRGSp50a64.sys
2008-02-23 13:08 . 2004-03-23 16:38	28,672	--a------	C:\WINDOWS\system32\InsDrvZD.dll
2008-02-23 13:08 . 2003-03-14 12:24	24,576	--a------	C:\WINDOWS\system32\ZyDelReg.exe
2008-02-23 13:08 . 2005-06-08 18:44	20,608	--a------	C:\WINDOWS\system32\drivers\BRGSp50.sys
2008-02-23 13:08 . 2004-10-25 13:40	17,664	--a------	C:\WINDOWS\system32\drivers\ZDPSp50.sys
2008-02-23 13:08 . 2004-01-14 11:30	17,151	--a------	C:\WINDOWS\system32\ZDPNDIS5.SYS
2008-02-23 13:08 . 2005-07-12 14:44	15,872	--a------	C:\WINDOWS\system32\InsDrvZD64.DLL
2008-02-19 17:27 . 2008-02-19 20:22	<DIR>	d--------	C:\Program Files\Starcars - Demo Version
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 15:42	---------	d-----w	C:\Program Files\TESCOLANDIA - Archipelag Magii
2008-03-16 15:58	---------	d-----w	C:\Program Files\Funny Racer
2008-03-16 15:54	---------	d--h--w	C:\Program Files\InstallShield Installation Information
2008-03-09 16:58	356,352	----a-w	C:\WINDOWS\system32\nvusmb.exe
2008-03-09 16:58	356,352	----a-w	C:\WINDOWS\system32\nvunrm.exe
2008-03-09 16:56	778,240	----a-w	C:\WINDOWS\system32\DivXsm.exe
2008-02-25 18:10	972,336	----a-w	C:\WINDOWS\UNRecode.exe
2008-02-25 18:10	972,336	----a-w	C:\WINDOWS\UNNeroVision.exe
2008-02-25 18:10	972,336	----a-w	C:\WINDOWS\UNNeroShowTime.exe
2008-02-25 18:10	972,336	----a-w	C:\WINDOWS\UNNeroMediaHome.exe
2008-02-25 18:10	972,336	----a-w	C:\WINDOWS\UNNeroBackItUp.exe
2008-02-25 18:10	356,352	----a-w	C:\WINDOWS\system32\NVUNINST.EXE
2008-02-25 18:10	356,352	----a-w	C:\WINDOWS\system32\nvudisp.exe
2008-02-25 18:10	189,952	----a-w	C:\WINDOWS\system32\WISPTIS.EXE
2008-02-25 18:10	1,339,392	----a-w	C:\WINDOWS\system32\nvdspsch.exe
2008-02-25 18:09	753,664	----a-w	C:\WINDOWS\system32\nvcplui.exe
2008-02-25 18:09	720,896	----a-w	C:\WINDOWS\iun6002.exe
2008-02-25 18:09	442,368	----a-w	C:\WINDOWS\system32\nvappbar.exe
2008-02-25 18:09	425,984	----a-w	C:\WINDOWS\system32\keystone.exe
2008-02-25 18:09	233,472	----a-w	C:\WINDOWS\InstIt.exe
2008-02-25 18:09	2,162,688	------r	C:\WINDOWS\MicCal.exe
2008-02-25 18:09	147,456	----a-w	C:\WINDOWS\system32\nvcolor.exe
2008-02-25 18:09	1,191,936	------r	C:\WINDOWS\RtlUpd.exe
2008-02-25 18:07	315,392	----a-w	C:\WINDOWS\HideWin.exe
2008-02-22 16:19	108,144	----a-w	C:\WINDOWS\system32\CmdLineExt.dll
2008-02-22 12:15	---------	d-----w	C:\Program Files\Chicken Invaders 2 Christmas Edition demo
2008-02-19 11:11	---------	d-----w	C:\Program Files\Realore
2008-02-19 11:10	---------	d-----w	C:\Program Files\Pinokio
2008-02-18 16:24	---------	d-----w	C:\Program Files\JPEGCrops
2008-01-31 20:34	---------	d-----w	C:\Program Files\Trickshot
2008-01-30 22:42	---------	d-----w	C:\Program Files\Absolute Mastermind
2008-01-26 20:12	---------	d-----w	C:\Program Files\Common Files\Adobe
2008-01-26 20:06	---------	d-----w	C:\Program Files\Codec Pack - All In 1
2008-01-26 19:55	---------	d-----w	C:\Program Files\DivX
2008-01-25 19:45	---------	d-----w	C:\Documents and Settings\x\Dane aplikacji\Leadertech
2008-01-25 19:43	---------	d-----w	C:\Documents and Settings\x\Dane aplikacji\AdobeUM
2008-01-20 21:18	---------	d-----w	C:\Program Files\Sony Ericsson
2008-01-20 21:18	---------	d-----w	C:\Program Files\Common Files\Teleca Shared
2008-01-20 21:18	---------	d-----w	C:\Program Files\Common Files\Sony Ericsson Shared
2008-01-20 21:18	---------	d-----w	C:\Documents and Settings\All Users\Dane aplikacji\Teleca
2008-01-20 21:18	---------	d-----w	C:\Documents and Settings\All Users\Dane aplikacji\Sony Ericsson
2007-12-25 21:03	24	----a-w	C:\Documents and Settings\x\Config.dat
2007-12-23 21:44	15,600	----a-w	C:\WINDOWS\gdrv.sys
.
(((((((((((((((((((((((((((((   snapshot@2008-03-18_15.15.47.07   )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-19 13:28:22	16,384	----atw	C:\WINDOWS\Temp\Perflib_Perfdata_5d4.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:44 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 10:21 153136]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 00:55 1667584]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-11-14 11:54 2131392]
"ares"="C:\Program Files\Ares\Ares.exe" [2008-02-20 15:33 963072]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-06 18:37 21898024]
"Creative Live! Cam Manager"="C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2006-05-31 16:00 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ioCentre"="C:\Genius\ioCentre\gTaskBar.exe" [2006-12-08 21:09 241664]
"CHotkey"="mHotkey.exe" [2006-12-08 17:01 547840 C:\WINDOWS\mHotkey.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 17:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 17:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 17:43 81920]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-02-25 19:16 153136]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 07:49 16377344 C:\WINDOWS\RTHDCPL.exe]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 21:09 157592]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-15 22:57 155648]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 01:06 487424]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-15 19:04 35328]
"AVFX Engine"="C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-06-09 01:11 24576]
"V0250Mon.exe"="C:\WINDOWS\V0250Mon.exe" [2006-06-07 18:00 32768]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-02-23 13:08:53 487424]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\SightSpeed\\SightSpeed.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 gMouPS2;PS2 Scroll Mouse Device;C:\WINDOWS\system32\DRIVERS\gMouPS2.sys [2006-07-12 04:48]
R3 V0250Dev;Live! Cam Notebook Pro;C:\WINDOWS\system32\DRIVERS\V0250Dev.sys [2006-06-27 04:25]
R3 V0250Vfx;V0250Vfx;C:\WINDOWS\system32\DRIVERS\V0250Vfx.sys [2006-03-24 09:24]
R3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2006-08-24 13:44]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-12-23 22:44]
S3 SunkFilt6;Alcor Micro Corp - 6360;C:\WINDOWS\System32\Drivers\sunkfilt6.sys []
S3 SunkFilt62;Alcor Micro Corp - 6362;C:\WINDOWS\System32\Drivers\sunkfilt62.sys []
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 09:42]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 09:42]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 09:42]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 09:42]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 09:42]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12	REG_MULTI_SZ   	Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt	REG_MULTI_SZ   	hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a38deb2-cc48-11dc-ba58-001a4df4dff3}]
\Shell\AutoRun\command - J:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2632728-f27f-11dc-bb04-001aff015ae0}]
\Shell\AutoRun\command - J:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-19 15:08:27
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ... 
scanning hidden autostart entries ...
scanning hidden files ... 
scan completed successfully 
hidden files: 0 
**************************************************************************
.
Completion time: 2008-03-19 15:08:40
ComboFix-quarantined-files.txt  2008-03-19 14:08:38
ComboFix2.txt  2008-03-18 14:15:56