ComboFix 07-11-08.1 - Ewa 2006-11-21 0:13:56.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.364 [GMT 1:00] Running from: D:\Moje dokumenty\Programy\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-10-08 to 2007-11-08 ))))))))))))))))))))))))))))))) . 2007-11-20 12:10 90,112 --a------ C:\WINDOWS\system32\RegDACL.exe 2007-11-20 12:10 53,248 --a------ C:\WINDOWS\system32\process.exe 2007-11-20 12:10 8,925 --a------ C:\clean.bat 2007-11-20 12:10 4,096 --a------ C:\WINDOWS\system32\reboot.exe 2007-11-20 12:10 347 --a------ C:\run2.reg 2007-11-19 11:01 2007-11-19 00:00 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-22 17:49 2007-10-10 12:29 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-20 18:42 --------- d-----w C:\Program Files\Puzzle 2007-11-20 11:02 --------- d-----w C:\Documents and Settings\Ewa\Dane aplikacji\Tlen.pl 2007-11-19 11:02 --------- d-----w C:\Program Files\Google 2007-11-19 10:37 --------- d-----w C:\Program Files\Gadu-Gadu 2007-10-25 16:57 8,483,328 ------w C:\WINDOWS\system32\dllcache\shell32.dll 2007-10-12 11:58 --------- d-----w C:\Program Files\Tlen.pl 2007-09-24 09:50 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\InsERT 2007-08-22 13:19 96,768 ------w C:\WINDOWS\system32\dllcache\inseng.dll 2007-08-22 13:19 661,504 ------w C:\WINDOWS\system32\dllcache\wininet.dll 2007-08-22 13:19 616,448 ------w C:\WINDOWS\system32\dllcache\urlmon.dll 2007-08-22 13:19 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll 2007-08-22 13:19 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll 2007-08-22 13:19 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll 2007-08-22 13:19 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll 2007-08-22 13:19 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll 2007-08-22 13:19 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll 2007-08-22 13:19 3,079,168 ------w C:\WINDOWS\system32\dllcache\mshtml.dll 2007-08-22 13:19 251,392 ------w C:\WINDOWS\system32\dllcache\iepeers.dll 2007-08-22 13:19 205,312 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll 2007-08-22 13:19 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll 2007-08-22 13:19 151,552 ------w C:\WINDOWS\system32\dllcache\cdfview.dll 2007-08-22 13:19 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll 2007-08-22 13:19 1,494,528 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll 2007-08-22 13:19 1,055,744 ------w C:\WINDOWS\system32\dllcache\danim.dll 2007-08-22 13:19 1,022,976 ------w C:\WINDOWS\system32\dllcache\browseui.dll 2007-08-21 10:30 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-21 06:18 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-04-15 21:24 217 ------w C:\Documents and Settings\Ewa\FIX.REG 2005-06-01 16:54 36,352 ------w C:\Documents and Settings\Ewa\Dane aplikacji\GDIPFONTCACHEV1.DAT 2005-05-26 20:40 226,584 ------w C:\Program Files\jre-1_5_0_02-windows-i586-p-iftw.exe . ((((((((((((((((((((((((((((( snapshot@2007-11-08_19.29.56.98 ))))))))))))))))))))))))))))))))))))))))) . - 2007-10-22 19:43:45 181,760 ----a-w C:\WINDOWS\BDOSCAN8\bdcore.dll + 2007-11-20 07:39:35 181,760 ----a-w C:\WINDOWS\BDOSCAN8\bdcore.dll - 2005-03-01 12:08:48 118,784 ----a-w C:\WINDOWS\BDOSCAN8\bdupd.dll + 2007-10-25 09:26:48 118,784 ----a-w C:\WINDOWS\BDOSCAN8\bdupd.dll - 2005-03-01 12:08:52 53,248 ----a-w C:\WINDOWS\BDOSCAN8\ipsupd.dll + 2007-10-25 09:26:48 53,248 ----a-w C:\WINDOWS\BDOSCAN8\ipsupd.dll - 2007-10-22 19:43:48 142,848 ----a-w C:\WINDOWS\BDOSCAN8\libfn.dll + 2007-11-20 07:39:37 142,848 ----a-w C:\WINDOWS\BDOSCAN8\libfn.dll + 2007-10-25 09:26:48 118,784 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\bdupd.dll + 2007-10-25 09:26:48 53,248 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\ipsupd.dll + 2005-11-08 23:26:46 38,400 ----a-w C:\WINDOWS\system32\moveex.exe - 2006-07-08 13:04:06 75,394 ----a-w C:\WINDOWS\system32\perfc009.dat + 2007-11-20 10:30:51 75,394 ----a-w C:\WINDOWS\system32\perfc009.dat - 2006-07-08 13:04:06 92,136 ----a-w C:\WINDOWS\system32\perfc015.dat + 2007-11-20 10:30:52 92,136 ----a-w C:\WINDOWS\system32\perfc015.dat - 2006-07-08 13:04:06 433,034 ----a-w C:\WINDOWS\system32\perfh009.dat + 2007-11-20 10:30:52 433,034 ----a-w C:\WINDOWS\system32\perfh009.dat - 2006-07-08 13:04:06 489,860 ----a-w C:\WINDOWS\system32\perfh015.dat + 2007-11-20 10:30:52 489,860 ----a-w C:\WINDOWS\system32\perfh015.dat + 2007-11-20 11:23:36 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_50c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [2002-09-11 02:57 C:\WINDOWS\SOUNDMAN.EXE] “StatusClient”=“C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe” [2002-12-16 15:51] “TomcatStartup”=“C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe” [2003-03-31 18:28] “nod32kui”=“C:\Program Files\Eset\nod32kui.exe” [2007-06-06 08:07] “OrderReminder”=“C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe” [2005-12-21 10:00] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe” [2004-12-06 18:40] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-03 23:44] “Odkurzacz-MCD”=“C:\Program Files\Odkurzacz\odk_mcd.exe” [2007-03-02 21:38] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2005-04-25 19:32:58] NkvMon.exe.lnk - C:\Program Files\Nikon\NkView6\NkvMon.exe [2003-11-06 19:23:38] Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 15:23:32] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyTraveler] C:\Documents and Settings\Ewa\Dane aplikacji\MyTraveler\MyTraveler.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys R2 AVMPORT;AVMPORT;C:\WINDOWS\system32\drivers\avmport.sys R2 MSSQL$INSERTGT;MSSQL$INSERTGT;C:\Program Files\Microsoft SQL Server\MSSQL$INSERTGT\Binn\sqlservr.exe -sINSERTGT R3 AVMWAN;Sterownik karty AVM NDIS WAN CAPI;C:\WINDOWS\system32\DRIVERS\avmwan.sys R3 fpcibase;Kontroler AVM ISDN-Controller FRITZ!Card PCI;C:\WINDOWS\system32\DRIVERS\fpcibase.sys R3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys R3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS S3 SQLAgent$INSERTGT;SQLAgent$INSERTGT;C:\Program Files\Microsoft SQL Server\MSSQL$INSERTGT\Binn\sqlagent.EXE -i INSERTGT . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-08 00:19:21 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-08 0:21:50 C:\ComboFix2.txt … 2007-11-08 19:31 . — E O F —