"Administrator" - 99\"
2007-05-29 21:19:15    Dodatek Service Pack 2  
ComboFix 07-05.27.V - Running from: "C:\Documents and Settings\Administrator\Pulpit\hijackthis_1
((((((((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
"C:\Program Files\install.log"
(((((((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
(((((((((((((((((((((((((((((((   Files Created from 2007-04-28 to 2007-05-29  ))))))))))))))))))))))))))))))))))
2007-05-29 01:03	<DIR>	d--------	C:\WINDOWS\system32\oodag
2007-05-29 00:49	<DIR>	d--------	C:\Program Files\OO Software
2007-05-28 21:33	<DIR>	d--------	C:\Program Files\acibar
2007-05-26 21:04	<DIR>	d--------	C:\Temp\ACI
2007-05-26 21:04	<DIR>	d--------	C:\Temp
2007-05-24 22:43	<DIR>	d--------	C:\Documents and Settings\Administrator\Shared
2007-05-24 22:43	<DIR>	d--------	C:\Documents and Settings\Administrator\Incomplete
2007-05-24 22:43	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\Shared
2007-05-24 22:43	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\Incomplete
2007-05-24 22:42	6,422,611	--a------	C:\Program Files\frostwire-4.13.1.6.windows.exe
2007-05-24 22:42	<DIR>	d--------	C:\Program Files\FrostWire
2007-05-24 22:42	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\FrostWire
2007-05-21 18:07	336	--a------	C:\WINDOWS\system32\lsprst7.dll
2007-05-21 18:07	1,025	--a------	C:\WINDOWS\system32\sysprs7.dll
2007-05-21 18:06	1,024	--a------	C:\WINDOWS\system32\clauth2.dll
2007-05-21 18:06	1,024	--a------	C:\WINDOWS\system32\clauth1.dll
2007-05-21 18:06	0	--a------	C:\WINDOWS\system32\ssprs.dll
2007-05-21 18:06	0	--a------	C:\WINDOWS\system32\serauth2.dll
2007-05-21 18:06	0	--a------	C:\WINDOWS\system32\serauth1.dll
2007-05-21 18:06	0	--a------	C:\WINDOWS\system32\nsprs.dll
2007-05-20 22:03	<DIR>	d--------	C:\Program Files\NAPI-PROJEKT
2007-05-16 18:24	<DIR>	d--------	C:\Program Files\GSC
2007-05-16 15:59	<DIR>	d--------	C:\Program Files\PBSSCollector2.8.0
2007-05-16 03:04	<DIR>	d--------	C:\Program Files\Bradbury
2007-05-11 02:09	1,050,120	--a------	C:\WINDOWS\system32\oodag.exe
2007-05-11 02:08	2,512,392	--a------	C:\WINDOWS\system32\oodtray.exe
2007-05-11 02:08	194,056	--a------	C:\WINDOWS\system32\oodbs.exe
2007-05-11 02:06	202,248	--a------	C:\WINDOWS\system32\oodtrrs.dll
2007-05-11 02:06	15,880	--a------	C:\WINDOWS\system32\oodagrs.dll
2007-05-11 02:06	15,880	--a------	C:\WINDOWS\system32\oodagmg.dll
2007-05-11 02:06	10,248	--a------	C:\WINDOWS\system32\oodbsrs.dll
2007-05-10 23:52	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\gtk-2.0
2007-05-10 23:49	<DIR>	d--------	C:\Documents and Settings\Administrator\.gimp-2.3
2007-05-10 23:49	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\.gimp-2.3
2007-05-10 23:19	38,160	--a------	C:\WINDOWS\system32\drivers\oobctm.sys
2007-05-10 23:18	15,368	--a------	C:\WINDOWS\system32\ootmapi.dll
2007-05-10 19:19	<DIR>	d--------	C:\Program Files\Microsoft Works
2007-05-09 22:08	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\Gadu-Gadu
2007-05-08 02:44	520,192	---------	C:\WINDOWS\system32\ati2sgag.exe
2007-05-08 02:43	<DIR>	d--------	C:\Program Files\ATI Technologies
2007-05-08 02:35	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\ATI
2007-05-08 02:29	<DIR>	d--------	C:\ATI
2007-05-08 01:36	3,972	--a------	C:\WINDOWS\system32\drivers\PciBus.sys
2007-05-08 01:36	20,400	--a------	C:\WINDOWS\system32\drivers\Entech.sys
2007-05-08 01:36	<DIR>	d--------	C:\WINDOWS\system32\Futuremark
2007-05-04 21:31	56,320	---------	C:\WINDOWS\system32\iyvu9_32.dll
2007-05-04 21:31	136,704	--a------	C:\WINDOWS\system32\iacenc.dll
2007-05-04 21:31	<DIR>	d--------	C:\Program Files\Ligos
2007-05-04 00:55	<DIR>	d--------	C:\Program Files\KC Softwares
2007-05-03 15:51	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\MusicIP
2007-05-03 03:24	765,952	--a------	C:\WINDOWS\system32\xvidcore.dll
2007-05-03 03:24	73,728	--a------	C:\WINDOWS\system32\dpl100.dll
2007-05-03 03:24	639,066	--a------	C:\WINDOWS\system32\divx.dll
2007-05-03 03:24	438,272	--a------	C:\WINDOWS\system32\vp6vfw.dll
2007-05-03 03:24	39,936	--a------	C:\WINDOWS\system32\huffyuv.dll
2007-05-03 03:24	3,596,288	--a------	C:\WINDOWS\system32\qt-dx331.dll
2007-05-03 03:24	217,088	--a------	C:\WINDOWS\system32\yv12vfw.dll
2007-05-03 03:24	217,088	--a------	C:\WINDOWS\system32\i420vfw.dll
2007-05-03 03:24	200,704	--a------	C:\WINDOWS\system32\ssldivx.dll
2007-05-03 03:24	196,608	--a------	C:\WINDOWS\system32\dtu100.dll
2007-05-03 03:24	180,224	--a------	C:\WINDOWS\system32\xvidvfw.dll
2007-05-03 03:24	1,044,480	--a------	C:\WINDOWS\system32\libdivx.dll
2007-05-03 03:21	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\Media Player Classic
2007-05-03 03:19	10,752	--a------	C:\WINDOWS\system32\ff_vfw.dll
2007-05-02 16:03	<DIR>	d--------	C:\Program Files\Real Alternative
2007-05-02 16:03	<DIR>	d--------	C:\Program Files\Media Player Classic
2007-05-02 16:03	<DIR>	d--------	C:\DOCUME~1\ALLUSE~1\DANEAP~1\Real
2007-05-02 16:03	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\Real
2007-05-02 15:58	<DIR>	d--------	C:\Program Files\K-Lite Codec Pack
2007-05-02 14:07	464	--a------	C:\WINDOWS\system32\vorbisenc.dll
2007-05-02 14:07	464	--a------	C:\WINDOWS\system32\vorbis.dll
2007-05-02 14:07	464	--a------	C:\WINDOWS\system32\OggDS.dll
2007-05-02 14:07	464	--a------	C:\WINDOWS\system32\ogg.dll
2007-05-02 14:07	464	--a------	C:\WINDOWS\system32\mplvpx.dll
2007-05-02 14:07	464	--a------	C:\WINDOWS\system32\cpuinf32.dll
2007-05-02 13:35	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\GetRightToGo
2007-05-02 00:32	<DIR>	d--------	C:\DOCUME~1\ADMINI~1\DANEAP~1\GSC
((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-29 15:57:12	63,040	----a-w	C:\WINDOWS\system32\PnkBstrA.exe
2007-05-28 19:06:00	--------	d-----w	C:\DOCUME~1\ADMINI~1\DANEAP~1\teamspeak2
2007-05-26 23:38:39	--------	d-----w	C:\DOCUME~1\ADMINI~1\DANEAP~1\Xfire
2007-05-26 23:38:23	--------	d-s---w	C:\Program Files\Xfire
2007-05-24 20:39:29	--------	d--h--w	C:\Program Files\InstallShield Installation Information
2007-05-17 16:51:55	43,520	----a-w	C:\WINDOWS\system32\CmdLineExt03.dll
2007-05-15 18:08:29	--------	d-----w	C:\Program Files\AV VCS 3.0
2007-05-15 18:04:01	--------	d-----w	C:\Program Files\Yahoo!
2007-05-15 18:03:17	--------	d-----w	C:\Program Files\Winamp
2007-05-08 00:34:53	--------	d-----w	C:\Program Files\Gadu-Gadu
2007-05-02 11:59:20	--------	d-----w	C:\Program Files\QuickTime
2007-05-02 10:16:58	--------	d-----w	C:\Program Files\Jasc Software Inc
2007-04-24 17:22:35	--------	d-----w	C:\DOCUME~1\ADMINI~1\DANEAP~1\MegauploadToolbar
2007-04-24 17:19:13	--------	d-----w	C:\Program Files\Common Files\Crystal Decisions
2007-04-24 17:19:12	--------	d-----w	C:\Program Files\aLeX^rS
2007-04-22 17:23:06	--------	d-----w	C:\Program Files\Microsoft Access Runtime
2007-04-17 11:36:12	--------	d-----w	C:\Program Files\Anim-FX
2007-04-15 23:17:43	99,904	----a-w	C:\WINDOWS\system32\PnkBstrB.exe
2007-04-14 21:28:19	22,584	----a-w	C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-04-12 21:51:03	19,422	----a-w	C:\WINDOWS\War3Unin.dat
2007-04-12 21:50:59	2,829	----a-w	C:\WINDOWS\War3Unin.pif
2007-04-12 21:50:59	126,976	----a-w	C:\WINDOWS\War3Unin.exe
2007-04-11 21:05:30	--------	d-----w	C:\Program Files\BitComet
2007-04-10 23:02:19	--------	d-----w	C:\DOCUME~1\ADMINI~1\DANEAP~1\Skype
2007-04-02 11:34:17	--------	d-----w	C:\Program Files\SkanerOnline
2007-04-01 09:57:16	80,444	----a-w	C:\WINDOWS\system32\perfc015.dat
2007-04-01 09:57:16	461,026	----a-w	C:\WINDOWS\system32\perfh015.dat
2007-03-28 10:11:23	--------	d-----w	C:\Program Files\Kustom Appz Software
2007-03-15 01:58:38	315,392	----a-w	C:\WINDOWS\system32\ATIDEMGX.dll
2007-03-15 01:57:34	267,776	----a-w	C:\WINDOWS\system32\ati2dvag.dll
2007-03-15 01:55:38	307,200	----a-w	C:\WINDOWS\system32\atiiiexx.dll
2007-03-15 01:50:39	122,880	----a-w	C:\WINDOWS\system32\atipdlxx.dll
2007-03-15 01:50:27	114,688	----a-w	C:\WINDOWS\system32\Oemdspif.dll
2007-03-15 01:50:19	26,112	----a-w	C:\WINDOWS\system32\Ati2mdxx.exe
2007-03-15 01:50:12	42,496	----a-w	C:\WINDOWS\system32\ati2edxx.dll
2007-03-15 01:49:59	114,688	----a-w	C:\WINDOWS\system32\ati2evxx.dll
2007-03-15 01:48:39	450,560	----a-w	C:\WINDOWS\system32\ati2evxx.exe
2007-03-15 01:47:52	53,248	----a-w	C:\WINDOWS\system32\ATIDDC.DLL
2007-03-15 01:40:10	2,820,544	----a-w	C:\WINDOWS\system32\ati3duag.dll
2007-03-15 01:29:47	1,315,712	----a-w	C:\WINDOWS\system32\ativvaxx.dll
2007-03-15 01:29:32	3,107,788	----a-w	C:\WINDOWS\system32\ativvaxx.dat
2007-03-15 01:19:32	5,402,624	----a-w	C:\WINDOWS\system32\atioglxx.dll
2007-03-15 01:16:14	258,048	----a-w	C:\WINDOWS\system32\atikvmag.dll
2007-03-15 01:14:43	17,408	----a-w	C:\WINDOWS\system32\atitvo32.dll
2007-03-15 01:10:28	356,352	----a-w	C:\WINDOWS\system32\ati2cqag.dll
2007-03-07 23:51:00	129,784	------w	C:\WINDOWS\system32\pxafs.dll
2007-03-06 22:04:53	143,676	----a-w	C:\WINDOWS\system32\atiicdxx.dat
((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
 
 
*Note* empty entries & legit default entries are not shown 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0 CE\Reader\ActiveX\AcroIEHelper.ocx [2001-04-16 18:39]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}=C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL [2006-10-31 08:55]
{ea443796-0ffa-44aa-9dcb-58ff72bb6db7}=C:\Program Files\acibar\tbacib.dll [2007-05-27 13:17]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0\bin\jusched.exe" [2006-08-06 21:35]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-23 21:31]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-04-25 17:44]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Komunikator"="C:\Program Files\Tlen.pl\tlen.exe" []
"Twoje TVN24"="" []
"@"="" []
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-05-10 16:36]
	
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070529-192012-303 
R3 - URLSearchHook: acibar toolbar - {ea443796-0ffa-44aa-9dcb-58ff72bb6db7} - C:\Program Files\acibar\tbacib.dll
backup-20070529-192003-927 
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
backup-20070529-002209-739 
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
????????????????????????????????????????????4??????????????????????
backup-20070529-002208-929 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
????????????????????????????????????????????
backup-20070529-002208-967 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
backup-20070529-002208-768 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
backup-20070529-002208-636 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
backup-20070529-002208-629 
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
backup-20070529-002208-121 
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
backup-20070529-002208-384 
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
backup-20070529-002208-236 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
backup-20070529-002208-870 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
backup-20070529-002208-860 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
backup-20070529-002208-650 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
backup-20070529-002208-682 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
backup-20070209-131702-103 
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????:?????????????????????'????????
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
????????????????????????????????????????????4?????????????????????????????????????????????????????????????????????????????????????????????????????4???????????????????????????????????????????????????????????????
backup-20070110-000407-412 
O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
backup-20061207-013410-506 
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL (file missing)
backup-20061203-221222-862 
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
backup-20061203-220254-844 
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
?Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc]
"DllName"="C:\\WINDOWS\\system32\\rpcc.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001
"Startup"="Startup"
backup-20061203-220254-461 
O16 - DPF: {82FFA573-38AA-482A-99AD-91F697B91631} (Installer.InstallControl) - http://www.file2you.net/applet.cab
?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????6??????'?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
backup-20061118-185556-637 
O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\iexplore.exe
********************************************************************
catchme 0.3.681 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-29 21:22:19
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-29 21:23:36 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-29 21:23
	--- E O F ---