ComboFix 08-07-31.06 - Właściciel 2008-08-01 15:24:20.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.1201 [GMT 2:00]
Running from: C:\Documents and Settings\Właściciel\Pulpit\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Właściciel\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\AskSBar
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2FFXTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2HIGHIN.EXE
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.JAR
C:\Program Files\AskSBar\bar\1.bin\A2NTSTBR.MANIFEST
C:\Program Files\AskSBar\bar\1.bin\A2PLUGIN.DLL
C:\Program Files\AskSBar\bar\1.bin\NPASKSBR.DLL
C:\Program Files\AskSBar\bar\1.bin\V2RSSMNU.DLL
C:\Program Files\AskSBar\bar\Cache\01EF52AC
C:\Program Files\AskSBar\bar\Cache\01EF6E52
C:\Program Files\AskSBar\bar\Cache\01EF9207.bin
C:\Program Files\AskSBar\bar\Cache\01EF9BCB.bin
C:\Program Files\AskSBar\bar\Cache\01EFA7B2.bin
C:\Program Files\AskSBar\bar\Cache\files.ini
C:\Program Files\AskSBar\bar\History\search2
C:\Program Files\AskSBar\bar\Settings\prevcfg2.htm
.
((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))
.
2008-08-01 15:09 .
2008-08-01 15:09 . 2008-08-01 15:09
2008-08-01 10:36 . 2008-06-24 13:45 1,414,440 --a------ C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-08-01 10:36 . 2008-06-23 17:36 773,120 --a------ C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-08-01 10:35 . 2008-08-01 10:35 0 --a------ C:\WINDOWS\Irremote.ini
2008-07-30 23:20 . 2008-07-30 23:20
2008-07-30 23:19 . 2008-07-30 23:19
2008-07-30 23:19 . 2008-07-30 23:19
2008-07-30 23:19 . 2008-07-30 23:19
2008-07-27 11:55 . 2008-07-27 11:55
2008-07-27 11:55 . 2008-07-27 11:55
2008-07-27 11:52 . 2008-07-27 11:56
2008-07-27 01:17 . 2008-07-27 01:17
2008-07-27 01:17 . 2008-07-27 01:17
2008-07-26 23:03 . 2008-07-27 00:00
2008-07-25 15:56 . 2008-07-25 15:56
2008-07-25 15:56 . 2008-07-25 16:07
2008-07-25 15:36 . 2008-07-30 14:43
2008-07-25 15:35 . 2008-07-25 15:35
2008-07-25 15:35 . 2008-07-25 15:35
2008-07-25 15:35 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-25 15:33 . 2008-07-25 15:35
2008-07-25 15:33 . 2008-07-25 15:33
2008-07-25 15:30 . 2008-07-25 15:32
2008-07-25 02:16 . 2008-07-25 02:16
2008-07-24 23:51 . 2008-07-24 23:51
2008-07-24 23:51 . 2008-07-24 23:51
2008-07-24 01:25 . 2008-07-24 01:25
2008-07-24 01:18 . 2008-07-24 01:18
2008-07-24 01:17 . 2008-07-24 02:19
2008-07-24 01:16 . 2008-07-27 11:43
2008-07-24 01:16 . 2008-08-01 14:53
2008-07-24 01:16 . 2008-07-27 11:43 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-24 01:16 . 2008-07-27 11:43 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-24 01:16 . 2008-07-27 11:43 10,671 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-07-24 01:16 . 2008-07-27 11:43 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-07-24 01:15 . 2008-08-01 15:04
2008-07-24 00:48 . 2008-07-24 02:19
2008-07-23 23:54 . 2008-07-23 23:54
2008-07-23 23:54 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-07-23 22:59 . 2008-07-30 22:53 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-07-23 21:37 . 2008-07-23 21:37
2008-07-23 21:35 . 2008-08-01 10:37
2008-07-23 21:35 . 2008-08-01 10:37
2008-07-22 00:48 . 2008-07-22 00:48
2008-07-22 00:17 . 2008-07-22 00:18
2008-07-22 00:13 . 2008-07-24 01:07
2008-07-19 22:30 . 2008-07-30 02:45
2008-07-04 03:19 . 2008-07-04 03:33
2008-07-04 03:04 . 2008-07-04 03:05
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-01 13:08 --------- d-----w C:\Documents and Settings\Właściciel\Dane aplikacji\Skype
2008-08-01 13:07 --------- d-----w C:\Documents and Settings\Właściciel\Dane aplikacji\skypePM
2008-07-18 13:58 --------- d-----w C:\Program Files\Gadu-Gadu
2008-06-26 20:39 --------- d-----w C:\Program Files\napisy do filmów
2008-06-25 14:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-20 17:42 246,784 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 20:05 --------- d-----w C:\Program Files\Picasa2
2008-06-14 18:01 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 12:45 579,464 ----a-w C:\WINDOWS\system32\SymNeti.dll
2008-06-13 12:45 207,240 ----a-w C:\WINDOWS\system32\SymRedir.dll
2008-06-13 12:14 31,280 ----a-w C:\WINDOWS\system32\drivers\SymIM.sys
2008-06-13 12:14 13,093 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2008-06-13 12:14 1,611 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2008-06-13 12:13 96,432 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2008-06-13 12:13 41,008 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2008-06-13 12:13 38,576 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2008-06-13 12:13 37,424 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2008-06-13 12:13 22,320 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2008-06-13 12:13 184,240 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2008-06-13 12:13 13,616 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2008-06-07 23:39 --------- d-----w C:\Documents and Settings\Właściciel\Dane aplikacji\Azureus
2008-06-07 23:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Azureus
2008-06-04 01:52 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Admin Inter 1 Mags
2008-05-07 05:16 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-05 10:38 315,392 ----a-w C:\WINDOWS\HideWin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 14:00 15360]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2008-05-08 17:01 68856]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2008-03-20 12:04 2127296]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2008-04-30 17:17 22058792]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 18:24 1694208]
“Picasa Media Detector”=“C:\Program Files\Picasa2\PicasaMediaDetector.exe” [2008-02-26 03:23 443968]
“Veoh”=“C:\Program Files\Veoh Networks\Veoh\VeohClient.exe” [2008-06-19 15:15 3664944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2007-05-10 19:22 864256]
“TouchPadHotKey”=“C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe” [2007-08-13 13:47 364544]
“SMSERIAL”=“C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe” [2006-11-22 17:31 630784]
“WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2008-07-09 23:33 36352]
“ISUSPM”=“C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe” [2006-05-16 11:58 213936]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 22:16 39792]
“ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2008-02-14 11:01 51048]
“osCheck”=“C:\Program Files\Norton Internet Security\osCheck.exe” [2007-08-24 22:53 714608]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe” [2008-06-10 04:27 144784]
“SiSPower”=“SiSPower.dll” [2007-08-03 16:07 53248 C:\WINDOWS\system32\SiSPower.dll]
“RTHDCPL”=“RTHDCPL.EXE” [2007-08-10 15:21 16384000 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2006-03-02 14:00 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-05-05 11:31:02 262144]
WirelessSelector.lnk - C:\Program Files\FSC\Wireless Utility\WirelessSelector.exe [2008-05-05 11:31:52 650752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.ffds”= ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“C:\Program Files\Gadu-Gadu\gg.exe”=
“C:\Program Files\Messenger\msmsgs.exe”=
“C:\Program Files\LimeWire\LimeWire.exe”=
“C:\Program Files\Skype\Phone\Skype.exe”=
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-14 11:02]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
*Newly Created Service* - COMHOST
.
Contents of the ‘Scheduled Tasks’ folder
2008-07-23 C:\WINDOWS\Tasks\Norton Internet Security - Uruchom pełne skanowanie systemu - Właściciel.job
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 19:19]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-01 15:25:30
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-01 15:26:14
ComboFix-quarantined-files.txt 2008-08-01 13:26:07
ComboFix2.txt 2008-08-01 13:09:04
Pre-Run: 35,067,904,000 bajtów wolnych
Post-Run: 35,060,416,512 bajtów wolnych
184 — E O F — 2008-07-25 00:16:32