"Leszek" - 2007-07-22 13:25:22 - ComboFix 07-07-14.6 - Dodatek Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\cbxywuv.dll
C:\WINDOWS\system32\jtvvvbhw.dll
C:\WINDOWS\system32\qpswfnuy.dll
C:\WINDOWS\system32\xegmiaoh.dll
C:\WINDOWS\system32\bknxtlyj.exe
C:\WINDOWS\system32\dahykwkf.exe
C:\WINDOWS\system32\maeqvlvh.exe
C:\WINDOWS\system32\skmahlkm.exe
C:\WINDOWS\system32\ssjabcyc.exe
C:\WINDOWS\system32\udwvmqbw.exe
C:\WINDOWS\system32\wpvqrtge.exe
C:\WINDOWS\system32\xxpchudc.exe
C:\WINDOWS\system32\adeecxbx.dll
C:\WINDOWS\system32\ahhaknox.dll
C:\WINDOWS\system32\bboatxre.dll
C:\WINDOWS\system32\cphpsudu.dll
C:\WINDOWS\system32\fauofmqq.dll
C:\WINDOWS\system32\fiwrkymy.dll
C:\WINDOWS\system32\fuarruqe.dll
C:\WINDOWS\system32\fwhxmqbk.dll
C:\WINDOWS\system32\gnfkneow.dll
C:\WINDOWS\system32\htpxqwfu.dll
C:\WINDOWS\system32\iarnyqpc.dll
C:\WINDOWS\system32\jjenbahl.dll
C:\WINDOWS\system32\kqvcrvqj.dll
C:\WINDOWS\system32\lafgaqan.dll
C:\WINDOWS\system32\lclvmarf.dll
C:\WINDOWS\system32\lmhswvnb.dll
C:\WINDOWS\system32\mooftmhi.dll
C:\WINDOWS\system32\nikxgxnu.dll
C:\WINDOWS\system32\pdimujmv.dll
C:\WINDOWS\system32\rvigxofd.dll
C:\WINDOWS\system32\smthaugi.dll
C:\WINDOWS\system32\wfvtqbox.dll
C:\WINDOWS\system32\ysctnbas.dll
C:\WINDOWS\system32\cbxywuv.dll
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\yunfwspq.ini
C:\WINDOWS\system32\hoaimgex.ini
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini2
C:\WINDOWS\system32\srqss.tmp
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\qommlji.dll
C:\WINDOWS\system32\qommlji.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\advjahyt.exe
C:\WINDOWS\system32\aeqorepd.exe
C:\WINDOWS\system32\apqalpwj.exe
C:\WINDOWS\system32\dlsdncyh.exe
C:\WINDOWS\system32\fjkpsjxn.exe
C:\WINDOWS\system32\gtsufhqs.exe
C:\WINDOWS\system32\hmqpmfek.exe
C:\WINDOWS\system32\hngtsrbr.exe
C:\WINDOWS\system32\ibtqsygu.exe
C:\WINDOWS\system32\latmmhwu.exe
C:\WINDOWS\system32\llarreld.exe
C:\WINDOWS\system32\luhcdkgp.exe
C:\WINDOWS\system32\msvcrl.dll
C:\WINDOWS\system32\nejfgcwo.exe
C:\WINDOWS\system32\nnmuoeek.exe
C:\WINDOWS\system32\orkyhukq.exe
C:\WINDOWS\system32\ouldnsfg.exe
C:\WINDOWS\system32\qfcseipi.exe
C:\WINDOWS\system32\qsorotbv.exe
C:\WINDOWS\system32\sahhxgoa.exe
C:\WINDOWS\system32\stinabew.exe
C:\WINDOWS\system32\tpvfgciw.exe
C:\WINDOWS\system32\vaddrexq.exe
C:\WINDOWS\system32\waolkmos.exe
C:\WINDOWS\system32\whfgqpuc.exe
C:\WINDOWS\system32\xbccader.exe
C:\WINDOWS\system32\xjkjbbtk.exe
C:\WINDOWS\system32\xlbarbsp.exe
C:\WINDOWS\system32\xudqrhfv.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-06-22 to 2007-07-22 )))))))))))))))))))))))))))))))
2007-07-22 13:24 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-22 13:13 <DIR> d-------- C:\VundoFix Backups
2007-07-22 13:09 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-22 13:09 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Dane aplikacji
2007-07-22 13:09 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Menu Start
2007-07-22 13:09 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Ustawienia lokalne
2007-07-22 13:09 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Szablony
2007-07-22 13:09 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Ulubione
2007-07-22 13:09 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Pulpit
2007-07-22 13:09 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Moje dokumenty
2007-07-20 19:24 <DIR> d-------- C:\Program Files\Lavasoft
2007-07-20 19:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Lavasoft
2007-07-17 14:16 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-07-17 14:16 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-07-17 14:16 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-07-17 14:16 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2007-07-17 14:16 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-07-17 14:15 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-07-17 14:15 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-07-17 14:15 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2007-07-17 14:15 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-07-17 14:15 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2007-07-17 14:15 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-07-17 13:31 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-07-17 13:31 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-07-17 13:31 22 --a------ C:\WINDOWS\system32\register.bat
2007-07-17 13:31 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2007-07-16 22:28 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-07-16 22:27 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2007-07-16 22:27 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-16 22:27 <DIR> d-------- C:\Program Files\AGEIA Technologies
2007-07-16 18:03 <DIR> d-------- C:\DOCUME~1\Leszek\DANEAP~1\Shareaza
2007-07-14 17:16 1,916,928 --------- C:\WINDOWS\UNNVEContent.exe
2007-07-13 15:26 <DIR> d-------- C:\DOCUME~1\Leszek\DANEAP~1\BearShare
2007-07-12 17:47 <DIR> d-------- C:\DOCUME~1\Ewelina\DANEAP~1\uTorrent
2007-07-11 19:07 <DIR> d-------- C:\DOCUME~1\Ewelina\DANEAP~1\Gadu-Gadu
2007-07-10 22:31 <DIR> d-------- C:\Program Files\Soulseek-Test
2007-07-01 16:24 77,895 --a------ C:\WINDOWS\system32\unibus_tcutil.dll
2007-07-01 16:24 67,072 --a------ C:\WINDOWS\system32\drivers\Wibukey.sys
2007-07-01 16:24 57,552 --a------ C:\WINDOWS\system32\WKDOS.EXE
2007-07-01 16:24 52,736 --a------ C:\WINDOWS\system\WkWin.dll
2007-07-01 16:24 38,656 --a------ C:\WINDOWS\system32\drivers\P2k.sys
2007-07-01 16:24 29,696 --a------ C:\WINDOWS\system32\drivers\Wibukey2.sys
2007-07-01 16:24 139,264 --a------ C:\WINDOWS\system32\WkWin32.dll
2007-07-01 16:24 <DIR> d-------- C:\Program Files\WIBUKEY
2007-07-01 16:24 <DIR> d-------- C:\Program Files\WIBU-SYSTEMS
2007-06-23 12:05 86,016 --a------ C:\WINDOWS\unvise32.exe
2007-06-23 12:03 217,088 --a------ C:\WINDOWS\system32\libmySQL.dll
2007-06-23 12:03 102,400 --a------ C:\WINDOWS\system32\TrackerNET.dll
2007-06-23 12:00 <DIR> d-------- C:\WINDOWS\solcache
2007-06-23 11:58 231,936 --a------ C:\WINDOWS\system32\SNWValid.dll
2007-06-23 11:58 1,022,976 --a------ C:\WINDOWS\system32\SierraNW.dll
2007-06-23 11:58 <DIR> d-------- C:\Program Files\Sierra On-Line
2007-06-23 11:58 <DIR> d-------- C:\DOCUME~1\Leszek\WINDOWS
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-22 11:13:31 -------- d-----w C:\DOCUME~1\Leszek\DANEAP~1\uTorrent
2007-07-14 15:14:25 -------- d-----w C:\DOCUME~1\Leszek\DANEAP~1\Ahead
2007-07-14 15:12:49 -------- d-----w C:\DOCUME~1\Leszek\DANEAP~1\foobar2000
2007-07-01 14:24:31 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-23 10:13:34 -------- d-----w C:\Program Files\HLSW
2007-06-20 12:40:10 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-06-20 09:44:38 -------- d-----w C:\DOCUME~1\Leszek\DANEAP~1\teamspeak2
2007-06-20 09:42:03 -------- d-----w C:\Program Files\Teamspeak2_RC2
2007-06-07 11:16:37 740 ----a-w C:\WINDOWS\eReg.dat
2007-06-04 13:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 13:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 13:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-31 17:45:18 -------- d-----w C:\Program Files\File Rescue Plus
2007-05-31 17:43:06 -------- d-----w C:\Program Files\GetData
2007-05-27 20:21:03 -------- d-----w C:\Program Files\TC PowerPack
2007-05-27 19:19:55 -------- d-----w C:\Program Files\ScannerU
2007-05-07 15:44:33 4 ----a-w C:\WINDOWS\vx86036.dat
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2002-12-18 17:55:08 57,344 ----a-w C:\Program Files\Scanutl.exe
2002-12-18 16:58:52 327,680 ----a-w C:\Program Files\Scanutl.rsc
2002-10-04 09:28:02 200,704 ----a-w C:\Program Files\copy.exe
2002-10-02 10:03:08 36,864 ----a-w C:\Program Files\Copyres.dll
2002-08-13 10:59:08 184,320 ----a-w C:\Program Files\Album.exe
2002-08-13 10:54:40 126,976 ----a-w C:\Program Files\Positive.exe
2002-08-13 10:53:16 131,072 ----a-w C:\Program Files\Negative.exe
2002-07-09 02:55:12 32,768 ----a-w C:\Program Files\prndrv32.dll
2002-04-24 10:29:08 77,824 ----a-w C:\Program Files\Custom_Config.exe
2002-04-18 04:22:50 57,344 ----a-w C:\Program Files\AM32.exe
2002-02-26 14:56:44 122,880 ----a-w C:\Program Files\OCR.exe
2002-01-21 15:39:34 36,864 ----a-w C:\Program Files\WebRes.dll
2002-01-21 15:38:06 36,864 ----a-w C:\Program Files\MailRes.dll
2002-01-21 15:32:02 36,864 ----a-w C:\Program Files\FaxRes.dll
2002-01-21 15:27:24 36,864 ----a-w C:\Program Files\AlbumRes.dll
2002-01-09 23:02:20 208,896 ----a-w C:\Program Files\mail.exe
2002-01-09 23:02:20 196,608 ----a-w C:\Program Files\Web.exe
2002-01-04 00:38:50 32,768 ----a-w C:\Program Files\Plkdata.dll
2002-01-03 17:11:56 32,768 ----a-w C:\Program Files\PosNegRes.dll
2002-01-03 17:10:42 32,768 ----a-w C:\Program Files\OcrRes.dll
2002-01-03 17:08:00 36,864 ----a-w C:\Program Files\Am32Res.dll
2001-12-28 01:09:06 28,672 ----a-w C:\Program Files\ImageFolio.exe
2001-12-06 20:41:00 28,672 ----a-w C:\Program Files\PowerSve.exe
2001-11-22 13:15:38 32,768 ----a-w C:\Program Files\CustomRes.dll
2001-11-16 16:26:02 24,576 ----a-w C:\Program Files\Custom_Launcher.exe
2001-07-03 09:50:44 49,152 ----a-w C:\Program Files\db4plk.dll
2001-06-11 14:39:32 155,648 ----a-w C:\Program Files\fax.exe
2001-02-13 14:46:50 98,304 ----a-w C:\Program Files\plkcom32.dll
2001-01-16 11:30:38 57,344 ----a-w C:\Program Files\IM31xpcx.del
2001-01-12 16:52:00 278,528 ----a-w C:\Program Files\ImgLib32.dll
2000-07-05 08:59:18 45,568 ----a-w C:\Program Files\EmailModule.dll
2000-06-28 16:31:54 53,248 ----a-w C:\Program Files\IM31XJPG.DEL
2000-04-24 09:08:16 2,081 ----a-w C:\Program Files\EmailDB.ini
1999-10-18 19:11:20 212,480 ----a-w C:\Program Files\Pcdlib32.dll
1999-08-03 17:58:06 65,536 ----a-w C:\Program Files\Guided.dll
1998-11-24 12:59:14 142,848 ----a-w C:\Program Files\IM31BMP.DIL
1998-02-19 12:58:38 67,584 ----a-w C:\Program Files\IM31XTIF.DEL
1998-02-19 11:11:02 32,768 ----a-w C:\Program Files\IM31XBMP.DEL
1998-02-19 11:10:28 82,432 ----a-w C:\Program Files\IM31TIF.DIL
1998-02-19 11:10:16 35,328 ----a-w C:\Program Files\IM31TGA.DIL
1998-02-19 11:10:04 54,784 ----a-w C:\Program Files\IM31PNG.DIL
1998-02-19 11:09:22 60,928 ----a-w C:\Program Files\IM31PCX.DIL
1998-02-19 11:09:10 33,280 ----a-w C:\Program Files\IM31PCD.DIL
1998-02-19 11:06:54 34,304 ----a-w C:\Program Files\IM31IMG.DIL
1998-02-19 11:06:40 36,864 ----a-w C:\Program Files\im31Gif.dil
1998-02-19 11:06:28 77,824 ----a-w C:\Program Files\IM31FAX.DIL
1998-02-18 20:19:06 86,528 ----a-w C:\Program Files\IM31XPNG.DEL
1998-02-03 14:06:14 67,072 ----a-w C:\Program Files\IM31JPG.DIL
1997-01-22 19:26:26 565,760 ----a-w C:\Program Files\MSVCP50.DLL
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-11-04 01:17 54248 --a------ C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
"PWRISOVM.EXE"="D:\Program Files\PowerISO\PWRISOVM.EXE" [2006-11-06 10:27]
"InCD"="D:\Program Files\Ahead\InCD\InCD.exe" [2005-07-25 12:01]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 12:24]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 19:37]
"Cmaudio"="cmicnfg.cpl" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" []
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44]
"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit" []
"NVIEW"="nview.dll,nViewLoadHook" []
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-03-11 17:04]
"µTorrent"="C:\Program Files\uTorrent\utorrent.exe" [2007-07-14 13:28]
"Komunikator"="C:\Program Files\Tlen.pl\tlen.exe" []
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-04-17 13:12]
"uTorrent"="C:\Program Files\uTorrent\utorrent.exe" [2007-07-14 13:28]
"Shareaza"="D:\Program Files\Shareaza\Shareaza.exe" [2007-02-05 04:05]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-07-22 13:31:44
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
Completion time: 2007-07-22 13:33:30 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-22 13:32
--- E O F ---