ComboFix 07-10-23.2 - Kasia 2007-10-23 18:29:33.1 - FAT32x86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.231 [GMT 2:00] Running from: C:\Documents and Settings\Kasia\Pulpit\Clean\combofix\ComboFix.exe Command switches used :: C:\Documents and Settings\Kasia\Pulpit\Clean\combofix\CFScript.txt * Created a new restore point FILE:: C:\Documents and Settings\Kasia\Dane aplikacji\m\flec006.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Kasia\Dane aplikacji\ezpinst.log C:\Documents and Settings\Kasia\Dane aplikacji\inst.exe C:\Documents and Settings\Kasia\Dane aplikacji\m\flec006.exe . ((((((((((((((((((((((((( Files Created from 2007-09-23 to 2007-10-23 ))))))))))))))))))))))))))))))) . 2007-10-23 15:34 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-10-23 14:56 2007-10-23 14:37 2007-10-23 03:54 2007-10-22 21:27 2007-10-20 19:41 2007-10-19 23:45 2007-10-13 19:45 44,032 --------- C:\WINDOWS\system32\CTSVCCDA.EXE 2007-10-13 19:45 25,088 --------- C:\WINDOWS\system32\CTSVCCTL.EXE 2007-10-13 19:08 2007-10-13 18:49 53,248 --------- C:\WINDOWS\Ctregrun.exe 2007-10-13 18:48 2007-10-13 18:45 2007-10-13 18:45 2007-10-13 18:43 2007-10-09 20:52 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-10-06 00:00 2007-10-05 20:22 2007-10-05 20:22 2007-09-29 01:39 2007-09-29 01:39 735,568 -ra------ C:\WINDOWS\system32\drivers\alcaudsl.sys 2007-09-29 01:39 54,256 --a------ C:\WINDOWS\system32\drivers\alcan5wn.sys 2007-09-29 01:39 5,605 -ra------ C:\WINDOWS\system32\stci.dll 2007-09-29 01:39 5,440 -ra------ C:\WINDOWS\system32\drivers\alcawh.sys 2007-09-29 01:39 4,000 -ra------ C:\WINDOWS\system32\drivers\alcacr.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-09-21 21:42 --------- d-----w C:\Program Files\Corel 2007-09-21 21:39 --------- d-----w C:\Documents and Settings\Kasia\Dane aplikacji\Corel 2007-09-19 23:48 --------- d-----w C:\Program Files\Home Audiometer 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-21 06:18 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-08-20 10:01 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll 2007-08-20 10:01 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll 2007-08-20 10:01 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll 2007-08-20 10:01 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll 2007-08-20 10:01 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2007-08-20 10:01 477,696 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll 2007-08-20 10:01 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll 2007-08-20 10:01 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll 2007-08-20 10:01 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll 2007-08-20 10:01 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll 2007-08-20 10:01 3,584,512 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2007-08-20 10:01 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll 2007-08-20 10:01 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll 2007-08-20 10:01 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll 2007-08-20 10:01 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll 2007-08-20 10:01 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll 2007-08-20 10:01 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll 2007-08-20 10:01 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll 2007-08-20 10:01 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll 2007-08-20 10:01 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll 2007-08-20 10:01 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll 2007-08-20 10:01 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll 2007-08-20 10:01 1,152,000 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll 2007-08-17 10:24 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2007-08-17 10:24 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2007-08-17 10:24 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe 2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\dllcache\wups.dll 2007-07-07 17:55 47,360 ----a-w C:\Documents and Settings\Kasia\Dane aplikacji\pcouffin.sys 2007-05-15 22:54 26,504 ----a-w C:\Documents and Settings\Kasia\Dane aplikacji\GDIPFONTCACHEV1.DAT 2005-10-12 23:21 386,784 ------w C:\WINDOWS\Media$NtUninstallKB930178$\spuninst\updspapi.dll 2005-10-12 23:21 216,288 ------w C:\WINDOWS\Media$NtUninstallKB930178$\spuninst\spuninst.exe 2005-09-01 03:28 292,352 ------w C:\WINDOWS\Media$NtUninstallKB930178$\winsrv.dll 2006-05-14 19:37:36 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys 2006-05-14 19:37:36 56 --sh–r C:\WINDOWS\system32\51E23938B5.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “RTHDCPL”=“RTHDCPL.EXE” [2005-09-06 08:39 C:\WINDOWS\RTHDCPL.EXE] “SynTPLpr”=“C:\Program Files\Synaptics\SynTP\SynTPLpr.exe” [2004-12-22 01:23] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2004-12-22 01:23] “ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2007-01-09 17:32] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-08-30 21:05] “NWEReboot”="" [] “Symantec NetDriver Monitor”=“C:\PROGRA~1\SYMNET~1\SNDMon.exe” [2007-05-08 12:04] “REGSHAVE”=“C:\Program Files\REGSHAVE\REGSHAVE.exe” [2002-02-04 22:32] “!AVG Anti-Spyware”=“D:\Programy\Utilities\Security\Spyware\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 11:25] “IntelZeroConfig”=“C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe” [2005-05-31 22:46] “IntelWireless”=“C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” [2005-06-03 01:31] “EOUApp”=“C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe” [2005-05-31 22:50] “googletalk”=“C:\Program Files\Google\Google Talk\googletalk.exe” [2007-01-01 23:22] “SpeedTouch USB Diagnostics”=“C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe” [2002-05-03 10:40] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2006-05-28 23:42] “BluetoothAuthenticationAgent”=“bthprops.cpl” [2004-08-04 13:00 C:\WINDOWS\system32\bthprops.cpl] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 13:00] “CTSyncU.exe”=“C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe” [2007-07-17 11:03] “eMuleAutoStart”=“D:\Programy\eMule\emule.exe” [2007-05-13 16:57] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless] C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2005-05-31 22:46 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll SafeBoot registry key needs repairs. This machine cannot enter Safe Mode. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] @=“Driver Group” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys] @=“Driver” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E967-E325-11CE-BFC1-08002BE10318}] @=“DiskDrive” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96A-E325-11CE-BFC1-08002BE10318}] @=“Hdc” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96B-E325-11CE-BFC1-08002BE10318}] @=“Keyboard” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96F-E325-11CE-BFC1-08002BE10318}] @=“Mouse” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E97D-E325-11CE-BFC1-08002BE10318}] @=“System” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @=“Volume” R0 R592;R592;C:\WINDOWS\system32\DRIVERS\R592.sys R0 risdpntk;risdpntk;C:\WINDOWS\system32\DRIVERS\risdpntk.sys R1 ts_lb;ts_lb;C:\WINDOWS\system32\drivers\ts_lb.sys R2 ghaio;ghaio;??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;??\C:\WINDOWS\system32\DNINDIS5.SYS R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\WINDOWS\system32\DRIVERS\WPN111.sys S1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys S3 A5AGU;D-Link USB Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\A5AGU.sys S3 ATHFMWDL;D-Link predator Bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys S3 CV2K1;CommView Network Monitor;C:\WINDOWS\system32\DRIVERS\cv2k1.sys S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;??\C:\WINDOWS\system32\NSNDIS5.SYS S3 USB28xxBGA;Cinergy Hybrid T USB XS;C:\WINDOWS\system32\DRIVERS\emBDA.sys S3 USB28xxOEM;Cinergy T USB XS Custom Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys S3 usbstor;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS S3 WLAN(WLAN);802.11g USB 2.0 WLAN Dongle(WLAN);C:\WINDOWS\system32\DRIVERS\zd1211u.sys S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;??\C:\WINDOWS\system32\ZDBRGSYS.SYS S3 ZDCndis5;ZDCndis5 Protocol Driver;??\C:\WINDOWS\system32\ZDCndis5.SYS *Newly Created Service* - MCSHIELD *Newly Created Service* - MCTASKMANAGER *Newly Created Service* - NAIAVFILTER1 . Contents of the ‘Scheduled Tasks’ folder “2007-10-19 18:00:36 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Kasia.job” “2007-10-23 15:47:30 C:\WINDOWS\Tasks\User_Feed_Synchronization-{C7B914E9-9E19-4507-BAA0-819E6B8CC586}.job” . ************************************************************************** catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-23 18:31:20 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-23 18:31:45 C:\ComboFix-quarantined-files.txt … 2007-10-23 15:37 C:\ComboFix3.txt … 2007-07-12 17:41 C:\ComboFix2.txt … 2007-10-23 15:37 . — E O F —