combofix
[/code]ComboFix 07-11-19.4C - wojtek 2007-12-04 23:00:31.4 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.551 [GMT 1:00]
Running from: C:\Documents and Settings\wojtek\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\wojtek\Pulpit\CFScript.txt
* Created a new restore point
FILE
C:\Temp\mrse.exe
C:\WINDOWS\system32\awttttr.dll.vir
C:\WINDOWS\system32\c_g1803.dll
C:\WINDOWS\system32\drivers\vmtwqxza.dat
C:\WINDOWS\system32\efcbxyv.dll
C:\WINDOWS\system32\hjhrfwbv.ini
C:\WINDOWS\system32\iybfttnt.dll
C:\WINDOWS\system32\jtudrpot.dll
C:\WINDOWS\system32\lfqnhgtu.dll
C:\WINDOWS\system32\nwypdjat.dll
C:\WINDOWS\system32\oibxkbcq.ini
C:\WINDOWS\system32\shlsjdeu.dll
C:\WINDOWS\system32\srijmdch.dll.vir
C:\WINDOWS\system32\suyjaoqy.dll
C:\WINDOWS\system32\tajdpywn.ini
C:\WINDOWS\system32\thieqgax.exe
C:\WINDOWS\system32\uxbhjsow.exe
C:\WINDOWS\system32\uxvsidcn.exe
C:\WINDOWS\system32\vbwfrhjh.dll
C:\WINDOWS\system32\xxywust.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\mrse.exe
C:\WINDOWS\system32\awttttr.dll.vir
C:\WINDOWS\system32\efcbxyv.dll
C:\WINDOWS\system32\hjhrfwbv.ini
C:\WINDOWS\system32\iybfttnt.dll
C:\WINDOWS\system32\lfqnhgtu.dll
C:\WINDOWS\system32\nwypdjat.dll
C:\WINDOWS\system32\oibxkbcq.ini
C:\WINDOWS\system32\tajdpywn.ini
C:\WINDOWS\system32\thieqgax.exe
C:\WINDOWS\system32\uxbhjsow.exe
C:\WINDOWS\system32\uxvsidcn.exe
C:\WINDOWS\system32\xxywust.dll
C:\WINDOWS\system32\c_g1803.dll . . . . failed to delete
C:\WINDOWS\system32\drivers\vmtwqxza.dat . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_JXEEFIIS
-------\jxeefiis
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-02 20:44 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-12-02 20:44 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-12-02 20:44 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-12-02 20:43 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-12-02 20:39 <DIR> d-------- C:\Program Files\Activision
2007-12-02 15:03 <DIR> d-------- C:\Downloads
2007-12-02 15:03 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\GetRight
2007-11-29 10:38 <DIR> dr------- C:\Documents and Settings\NetworkService\Ulubione
2007-11-26 12:05 <DIR> d-------- C:\Program Files\Soulseek-Test
2007-11-24 15:19 106,752 --a------ C:\WINDOWS\system32\c_g1803.2
2007-11-24 15:19 89,088 --a------ C:\WINDOWS\system32\c_g1803.dll
2007-11-24 15:19 83,456 --a------ C:\WINDOWS\system32\c_g1803.1
2007-11-24 15:19 19,200 C:\WINDOWS\system32\drivers\vmtwqxza.dat
2007-11-11 10:07 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-11-10 13:13 8,704 --a------ C:\WINDOWS\system32\dllcache\kbdjpn.dll
2007-11-10 13:13 8,192 --a------ C:\WINDOWS\system32\dllcache\kbdkor.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\dllcache\kbd106.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\dllcache\kbd101c.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\dllcache\kbd101b.dll
2007-11-10 13:13 5,632 --a------ C:\WINDOWS\system32\dllcache\kbd103.dll
2007-11-09 13:32 <DIR> d-------- C:\VundoFix Backups
2007-11-09 08:31 <DIR> d-------- C:\!KillBox
2007-11-09 08:12 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-11-09 08:12 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-09 08:12 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-09 08:12 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-09 08:12 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-11-09 08:11 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\PC Tools
2007-11-09 08:11 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-11-09 08:07 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-08 22:58 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\Apple Computer
2007-11-08 22:54 <DIR> d-------- C:\Program Files\Apple Software Update
2007-11-08 22:54 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple
2007-11-08 22:49 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2007-11-08 17:43 <DIR> d-------- C:\Program Files\BitTorrent_DNA
2007-11-08 17:43 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\BitTorrent DNA
2007-11-08 17:43 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\BitTorrent
2007-11-08 12:48 <DIR> d-------- C:\WINDOWS\system32\Mz02r
2007-11-08 12:48 <DIR> d-------- C:\Temp\mZOr
2007-11-08 12:48 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-31 12:37 --------- d-----w C:\Documents and Settings\jacek\Dane aplikacji\Talkback
2007-10-23 15:20 229,727 ----a-w C:\WINDOWS\Burn4Free_Toolbar_Uninstaller_7375.exe
2007-10-23 15:20 --------- d-----w C:\Program Files\Burn4Free Toolbar
2007-10-23 15:20 --------- d-----w C:\Program Files\Burn4Free
2007-10-21 08:54 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\Media Player Classic
2007-10-15 20:34 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\Talkback
2007-10-03 09:53 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-09-06 11:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 11:00 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-07-27 21:54 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-11-29_10.34.42.87 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-26 19:58:08 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2007-12-02 19:43:52 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2007-07-26 19:58:08 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2007-12-02 19:43:52 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2007-07-26 19:58:08 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2007-12-02 19:43:52 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2007-12-02 19:43:48 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2007-07-25 13:56:22 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2007-07-26 19:58:10 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:52 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:52 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:54 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2007-07-26 19:58:10 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2007-12-02 19:43:54 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2007-07-26 19:58:10 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2007-12-02 19:43:54 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2007-07-26 19:58:10 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2007-12-02 19:43:54 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2007-07-26 19:58:10 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2007-12-02 19:43:54 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2007-07-26 19:58:08 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2007-12-02 19:43:52 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2007-03-13 09:57:12 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2007-12-02 19:43:16 216,358 ----a-r C:\WINDOWS\Installer\{6734CA10-8FB8-4C7F-B8C7-75317C617DC5}\ARPPRODUCTICON.exe
+ 2004-09-29 11:38:58 2,676,224 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2004-12-01 14:53:06 2,846,720 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-05 18:32:54 563,712 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 16:23:14 567,296 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 16:21:34 577,024 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 16:20:50 577,536 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-02-03 06:40:48 578,560 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-03-31 10:27:50 578,560 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
+ 2007-03-12 15:42:30 1,123,696 ----a-w C:\WINDOWS\system32\D3DCompiler_33.dll
+ 2007-03-15 15:57:58 443,752 ----a-w C:\WINDOWS\system32\d3dx10_33.dll
+ 2005-02-05 18:45:26 2,222,800 ----a-w C:\WINDOWS\system32\d3dx9_24.dll
+ 2005-03-18 16:19:58 2,337,488 ----a-w C:\WINDOWS\system32\d3dx9_25.dll
+ 2005-12-05 17:09:18 2,323,664 ----a-w C:\WINDOWS\system32\d3dx9_28.dll
+ 2006-02-03 07:43:16 2,332,368 ----a-w C:\WINDOWS\system32\d3dx9_29.dll
+ 2006-03-31 11:40:58 2,388,176 ----a-w C:\WINDOWS\system32\d3dx9_30.dll
+ 2006-09-28 15:05:20 2,414,360 ----a-w C:\WINDOWS\system32\d3dx9_31.dll
+ 2006-11-29 12:06:18 3,426,072 ----a-w C:\WINDOWS\system32\d3dx9_32.dll
+ 2007-03-12 15:42:30 3,495,784 ----a-w C:\WINDOWS\system32\d3dx9_33.dll
+ 2007-05-16 15:45:16 3,497,832 ----a-w C:\WINDOWS\system32\d3dx9_34.dll
+ 2006-02-03 07:41:26 14,032 ----a-w C:\WINDOWS\system32\x3daudio1_0.dll
+ 2007-03-05 11:42:18 15,128 ----a-w C:\WINDOWS\system32\x3daudio1_1.dll
+ 2006-02-03 07:42:06 230,096 ----a-w C:\WINDOWS\system32\xactengine2_0.dll
+ 2006-03-31 11:39:48 229,584 ----a-w C:\WINDOWS\system32\xactengine2_1.dll
+ 2006-05-31 06:24:16 230,168 ----a-w C:\WINDOWS\system32\xactengine2_2.dll
+ 2006-07-28 08:30:32 236,824 ----a-w C:\WINDOWS\system32\xactengine2_3.dll
+ 2006-09-28 15:05:56 237,848 ----a-w C:\WINDOWS\system32\xactengine2_4.dll
+ 2006-12-08 11:02:00 251,672 ----a-w C:\WINDOWS\system32\xactengine2_5.dll
+ 2007-01-24 14:27:30 255,848 ----a-w C:\WINDOWS\system32\xactengine2_6.dll
+ 2007-04-04 17:55:00 261,480 ----a-w C:\WINDOWS\system32\xactengine2_7.dll
+ 2006-03-31 11:39:24 62,672 ----a-w C:\WINDOWS\system32\xinput1_1.dll
+ 2006-07-28 08:30:14 62,744 ----a-w C:\WINDOWS\system32\xinput1_2.dll
+ 2007-04-04 17:53:42 81,768 ----a-w C:\WINDOWS\system32\xinput1_3.dll
- 2005-09-28 14:35:48 61,136 ----a-w C:\WINDOWS\system32\xinput9_1_0.dll
+ 2005-12-05 17:07:30 61,136 ----a-w C:\WINDOWS\system32\xinput9_1_0.dll
+ 2007-12-04 22:04:06 16,384 ----a-w C:\WINDOWS\TEMP\Perflib_Perfdata_5c8.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{983CFA1B-7559-45CB-B7D2-FA8CF03C9F75}]
2001-10-26 17:27 89088 --a------ C:\WINDOWS\system32\c_g1803.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 22:44]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-07-09 09:39]
"AutoConnect"="C:\Program Files\AutoConnect\AutoConnect.exe" []
"BitTorrent DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" [2007-11-08 17:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16:08 C:\WINDOWS\RTHDCPL.exe]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 13:49]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"SMSERIAL"="sm56hlpr.exe" [2005-09-16 14:01 C:\WINDOWS\sm56hlpr.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickTime Task"="F:\QuickTime\qttask.exe" [2007-10-19 20:16]
"SDTray"="f:\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 22:44]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 21:05:56]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
R0 jxeefiis;jxeefiis;C:\WINDOWS\system32\drivers\vmtwqxza.dat
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys
R2 MSSQL$INSERTGT;SQL Server (INSERTGT);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINSERTGT
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
*Newly Created Service* - JXEEFIIS
.
Contents of the 'Scheduled Tasks' folder
"2007-11-26 11:06:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-04 23:04:39
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-04 23:05:18 - machine was rebooted
C:\ComboFix3.txt ... 2007-11-30 20:05
C:\ComboFix2.txt ... 2007-12-02 11:12
.
--- E O F ---
- Kod: Zaznacz wszystko
[size=75][ [i][b][color=#B50158]Dodano:[/b] Dzisiaj o 23:08[/i] ][/size] [/color]
hijack
[code]ComboFix 07-11-19.4C - wojtek 2007-12-04 23:00:31.4 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.551 [GMT 1:00]
Running from: C:\Documents and Settings\wojtek\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\wojtek\Pulpit\CFScript.txt
* Created a new restore point
FILE
C:\Temp\mrse.exe
C:\WINDOWS\system32\awttttr.dll.vir
C:\WINDOWS\system32\c_g1803.dll
C:\WINDOWS\system32\drivers\vmtwqxza.dat
C:\WINDOWS\system32\efcbxyv.dll
C:\WINDOWS\system32\hjhrfwbv.ini
C:\WINDOWS\system32\iybfttnt.dll
C:\WINDOWS\system32\jtudrpot.dll
C:\WINDOWS\system32\lfqnhgtu.dll
C:\WINDOWS\system32\nwypdjat.dll
C:\WINDOWS\system32\oibxkbcq.ini
C:\WINDOWS\system32\shlsjdeu.dll
C:\WINDOWS\system32\srijmdch.dll.vir
C:\WINDOWS\system32\suyjaoqy.dll
C:\WINDOWS\system32\tajdpywn.ini
C:\WINDOWS\system32\thieqgax.exe
C:\WINDOWS\system32\uxbhjsow.exe
C:\WINDOWS\system32\uxvsidcn.exe
C:\WINDOWS\system32\vbwfrhjh.dll
C:\WINDOWS\system32\xxywust.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\mrse.exe
C:\WINDOWS\system32\awttttr.dll.vir
C:\WINDOWS\system32\efcbxyv.dll
C:\WINDOWS\system32\hjhrfwbv.ini
C:\WINDOWS\system32\iybfttnt.dll
C:\WINDOWS\system32\lfqnhgtu.dll
C:\WINDOWS\system32\nwypdjat.dll
C:\WINDOWS\system32\oibxkbcq.ini
C:\WINDOWS\system32\tajdpywn.ini
C:\WINDOWS\system32\thieqgax.exe
C:\WINDOWS\system32\uxbhjsow.exe
C:\WINDOWS\system32\uxvsidcn.exe
C:\WINDOWS\system32\xxywust.dll
C:\WINDOWS\system32\c_g1803.dll . . . . failed to delete
C:\WINDOWS\system32\drivers\vmtwqxza.dat . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_JXEEFIIS
-------\jxeefiis
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-02 20:44 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-12-02 20:44 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-12-02 20:44 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-12-02 20:43 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-12-02 20:39 <DIR> d-------- C:\Program Files\Activision
2007-12-02 15:03 <DIR> d-------- C:\Downloads
2007-12-02 15:03 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\GetRight
2007-11-29 10:38 <DIR> dr------- C:\Documents and Settings\NetworkService\Ulubione
2007-11-26 12:05 <DIR> d-------- C:\Program Files\Soulseek-Test
2007-11-24 15:19 106,752 --a------ C:\WINDOWS\system32\c_g1803.2
2007-11-24 15:19 89,088 --a------ C:\WINDOWS\system32\c_g1803.dll
2007-11-24 15:19 83,456 --a------ C:\WINDOWS\system32\c_g1803.1
2007-11-24 15:19 19,200 C:\WINDOWS\system32\drivers\vmtwqxza.dat
2007-11-11 10:07 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-11-10 13:13 8,704 --a------ C:\WINDOWS\system32\dllcache\kbdjpn.dll
2007-11-10 13:13 8,192 --a------ C:\WINDOWS\system32\dllcache\kbdkor.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\dllcache\kbd106.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\dllcache\kbd101c.dll
2007-11-10 13:13 6,144 --a------ C:\WINDOWS\system32\dllcache\kbd101b.dll
2007-11-10 13:13 5,632 --a------ C:\WINDOWS\system32\dllcache\kbd103.dll
2007-11-09 13:32 <DIR> d-------- C:\VundoFix Backups
2007-11-09 08:31 <DIR> d-------- C:\!KillBox
2007-11-09 08:12 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-11-09 08:12 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-09 08:12 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-09 08:12 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-09 08:12 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-11-09 08:11 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\PC Tools
2007-11-09 08:11 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-11-09 08:07 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-08 22:58 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\Apple Computer
2007-11-08 22:54 <DIR> d-------- C:\Program Files\Apple Software Update
2007-11-08 22:54 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple
2007-11-08 22:49 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2007-11-08 17:43 <DIR> d-------- C:\Program Files\BitTorrent_DNA
2007-11-08 17:43 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\BitTorrent DNA
2007-11-08 17:43 <DIR> d-------- C:\Documents and Settings\wojtek\Dane aplikacji\BitTorrent
2007-11-08 12:48 <DIR> d-------- C:\WINDOWS\system32\Mz02r
2007-11-08 12:48 <DIR> d-------- C:\Temp\mZOr
2007-11-08 12:48 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-31 12:37 --------- d-----w C:\Documents and Settings\jacek\Dane aplikacji\Talkback
2007-10-23 15:20 229,727 ----a-w C:\WINDOWS\Burn4Free_Toolbar_Uninstaller_7375.exe
2007-10-23 15:20 --------- d-----w C:\Program Files\Burn4Free Toolbar
2007-10-23 15:20 --------- d-----w C:\Program Files\Burn4Free
2007-10-21 08:54 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\Media Player Classic
2007-10-15 20:34 --------- d-----w C:\Documents and Settings\wojtek\Dane aplikacji\Talkback
2007-10-03 09:53 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-09-06 11:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 11:00 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-07-27 21:54 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2007-11-29_10.34.42.87 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-26 19:58:08 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2007-12-02 19:43:52 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2007-07-26 19:58:08 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2007-12-02 19:43:52 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2007-07-26 19:58:08 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2007-12-02 19:43:52 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2007-12-02 19:43:48 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2007-07-25 13:56:22 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2007-07-26 19:58:10 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:50 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:52 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:52 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2007-12-02 19:43:54 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2007-07-26 19:58:10 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2007-12-02 19:43:54 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2007-07-26 19:58:10 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2007-12-02 19:43:54 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2007-07-26 19:58:10 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2007-12-02 19:43:54 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2007-07-26 19:58:10 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2007-12-02 19:43:54 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2007-07-26 19:58:08 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2007-12-02 19:43:52 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2007-03-13 09:57:12 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2007-12-02 19:43:16 216,358 ----a-r C:\WINDOWS\Installer\{6734CA10-8FB8-4C7F-B8C7-75317C617DC5}\ARPPRODUCTICON.exe
+ 2004-09-29 11:38:58 2,676,224 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2004-12-01 14:53:06 2,846,720 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-05 18:32:54 563,712 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 16:23:14 567,296 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 16:21:34 577,024 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 16:20:50 577,536 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-02-03 06:40:48 578,560 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-03-31 10:27:50 578,560 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
+ 2007-03-12 15:42:30 1,123,696 ----a-w C:\WINDOWS\system32\D3DCompiler_33.dll
+ 2007-03-15 15:57:58 443,752 ----a-w C:\WINDOWS\system32\d3dx10_33.dll
+ 2005-02-05 18:45:26 2,222,800 ----a-w C:\WINDOWS\system32\d3dx9_24.dll
+ 2005-03-18 16:19:58 2,337,488 ----a-w C:\WINDOWS\system32\d3dx9_25.dll
+ 2005-12-05 17:09:18 2,323,664 ----a-w C:\WINDOWS\system32\d3dx9_28.dll
+ 2006-02-03 07:43:16 2,332,368 ----a-w C:\WINDOWS\system32\d3dx9_29.dll
+ 2006-03-31 11:40:58 2,388,176 ----a-w C:\WINDOWS\system32\d3dx9_30.dll
+ 2006-09-28 15:05:20 2,414,360 ----a-w C:\WINDOWS\system32\d3dx9_31.dll
+ 2006-11-29 12:06:18 3,426,072 ----a-w C:\WINDOWS\system32\d3dx9_32.dll
+ 2007-03-12 15:42:30 3,495,784 ----a-w C:\WINDOWS\system32\d3dx9_33.dll
+ 2007-05-16 15:45:16 3,497,832 ----a-w C:\WINDOWS\system32\d3dx9_34.dll
+ 2006-02-03 07:41:26 14,032 ----a-w C:\WINDOWS\system32\x3daudio1_0.dll
+ 2007-03-05 11:42:18 15,128 ----a-w C:\WINDOWS\system32\x3daudio1_1.dll
+ 2006-02-03 07:42:06 230,096 ----a-w C:\WINDOWS\system32\xactengine2_0.dll
+ 2006-03-31 11:39:48 229,584 ----a-w C:\WINDOWS\system32\xactengine2_1.dll
+ 2006-05-31 06:24:16 230,168 ----a-w C:\WINDOWS\system32\xactengine2_2.dll
+ 2006-07-28 08:30:32 236,824 ----a-w C:\WINDOWS\system32\xactengine2_3.dll
+ 2006-09-28 15:05:56 237,848 ----a-w C:\WINDOWS\system32\xactengine2_4.dll
+ 2006-12-08 11:02:00 251,672 ----a-w C:\WINDOWS\system32\xactengine2_5.dll
+ 2007-01-24 14:27:30 255,848 ----a-w C:\WINDOWS\system32\xactengine2_6.dll
+ 2007-04-04 17:55:00 261,480 ----a-w C:\WINDOWS\system32\xactengine2_7.dll
+ 2006-03-31 11:39:24 62,672 ----a-w C:\WINDOWS\system32\xinput1_1.dll
+ 2006-07-28 08:30:14 62,744 ----a-w C:\WINDOWS\system32\xinput1_2.dll
+ 2007-04-04 17:53:42 81,768 ----a-w C:\WINDOWS\system32\xinput1_3.dll
- 2005-09-28 14:35:48 61,136 ----a-w C:\WINDOWS\system32\xinput9_1_0.dll
+ 2005-12-05 17:07:30 61,136 ----a-w C:\WINDOWS\system32\xinput9_1_0.dll
+ 2007-12-04 22:04:06 16,384 ----a-w C:\WINDOWS\TEMP\Perflib_Perfdata_5c8.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{983CFA1B-7559-45CB-B7D2-FA8CF03C9F75}]
2001-10-26 17:27 89088 --a------ C:\WINDOWS\system32\c_g1803.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 22:44]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-07-09 09:39]
"AutoConnect"="C:\Program Files\AutoConnect\AutoConnect.exe" []
"BitTorrent DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" [2007-11-08 17:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16:08 C:\WINDOWS\RTHDCPL.exe]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 13:49]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"SMSERIAL"="sm56hlpr.exe" [2005-09-16 14:01 C:\WINDOWS\sm56hlpr.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickTime Task"="F:\QuickTime\qttask.exe" [2007-10-19 20:16]
"SDTray"="f:\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 22:44]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 21:05:56]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
R0 jxeefiis;jxeefiis;C:\WINDOWS\system32\drivers\vmtwqxza.dat
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys
R2 MSSQL$INSERTGT;SQL Server (INSERTGT);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sINSERTGT
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
*Newly Created Service* - JXEEFIIS
.
Contents of the 'Scheduled Tasks' folder
"2007-11-26 11:06:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-04 23:04:39
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-04 23:05:18 - machine was rebooted
C:\ComboFix3.txt ... 2007-11-30 20:05
C:\ComboFix2.txt ... 2007-12-02 11:12
.
--- E O F ---
[ Dodano: Dzisiaj o 23:11 ] spyware doctor wykrywa:
spyware.known_bad_Sites
adware.advertising
trojan-PWS.tanspy
trojan.generic