ComboFix 08-04-24.1 - Agatka 2008-04-27 12:27:46.2 - NTFSx86
Running from: C:\Documents and Settings\Agatka\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\Agatka\Pulpit\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED
FILE ::
C:\WINDOWS\SYSTEM32\winzzd32.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\avatar.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\bgfadel.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\bgfader.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\common-x.css
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\common.css
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\cornerbl.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\cornerbr.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\ext_def.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\ext_roll.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\include.js
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\index.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\loader.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\loading.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\logo.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\max_def.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\max_roll.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\min_def.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\min_roll.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\noflash.htm
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\res_def.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\res_roll.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\spacer.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\spacer.swf
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\topgrad.gif
C:\Program Files\MyWebSearch\bar\Avatar\COMMON\window.ico
C:\Program Files\MyWebSearch\bar\Cache\000255F6.bin
C:\Program Files\MyWebSearch\bar\Cache\00026D66.bin
C:\Program Files\MyWebSearch\bar\Cache\001756F9
C:\Program Files\MyWebSearch\bar\Cache\001C5DC7.bin
C:\Program Files\MyWebSearch\bar\Cache\001C6A2B.bin
C:\Program Files\MyWebSearch\bar\Cache\001C7101.bin
C:\Program Files\MyWebSearch\bar\Cache\00291507.bin
C:\Program Files\MyWebSearch\bar\Cache\0039141F.bin
C:\Program Files\MyWebSearch\bar\Cache\00392342.bin
C:\Program Files\MyWebSearch\bar\Cache\00392F09.bin
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\SYSTEM32\winzzd32.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.
2008-04-26 21:35 . 2008-04-26 21:35 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-26 21:01 . 2008-04-26 21:01
2008-04-18 19:39 . 2008-04-18 19:39
2008-04-18 19:36 . 2008-04-26 20:54
2008-04-18 19:36 . 2008-04-18 19:36
2008-04-18 19:36 . 2008-04-26 20:54
2008-04-18 19:36 . 2008-04-18 19:37 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-18 19:36 . 2008-04-18 19:37 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-31 20:02 --------- d-----w C:\Program Files\Lx_cats
2008-03-21 11:15 45,056 ----a-w C:\msntlfpm.exe
2008-03-21 11:13 27,136 ----a-w C:\WINDOWS\system32\winmfu32.dll
2008-03-21 11:12 24,576 ----a-w C:\WINDOWS\system32\winosz32.dll
2008-03-21 11:12 24,576 ----a-w C:\WINDOWS\system32\winmyy32.dll
2008-03-13 18:29 --------- d-----w C:\Program Files\ZipGenius 6
2008-03-13 18:29 --------- d-----w C:\Documents and Settings\Agatka\Dane aplikacji\ZipGenius
2008-03-13 18:15 --------- d-----w C:\Documents and Settings\Agatka\Dane aplikacji\Datalayer
2008-03-13 18:14 --------- d-----w C:\Documents and Settings\Agatka\Dane aplikacji\Nokia
2008-03-13 18:12 --------- d-----w C:\Program Files\Nokia
2008-03-13 18:12 --------- d-----w C:\Program Files\DIFX
2008-03-13 18:12 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-03-13 18:12 --------- d-----w C:\Program Files\Common Files\Nokia
2008-03-13 18:12 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\PC Suite
2008-03-13 18:12 --------- d-----w C:\Documents and Settings\Agatka\Dane aplikacji\PC Suite
2008-03-13 18:11 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Downloaded Installations
2008-03-07 14:41 --------- d-----w C:\Documents and Settings\Agatka\Dane aplikacji\AdobeUM
2008-02-29 22:40 --------- d-----w C:\Program Files\PITy
2008-02-29 22:27 --------- d-----w C:\Program Files\Common Files\Adobe
.
------- Sigcheck -------
2002-09-20 19:05 1012736 8ac89a6d9579d7cca05ac655e6f4a8e5 C:\WINDOWS\explorer.exe
2002-09-20 19:05 1012736 6c5b3f17bc2c1e4ce4964e3b1171eb34 C:\WINDOWS\system32\dllcache\explorer.exe
2002-09-20 19:05 20480 91664de0c3158045992c19e3df6c8bae C:\WINDOWS\system32\ctfmon.exe
2002-09-20 19:05 20480 b6fe83dff79b386fc533f9856d2a9423 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\System32\ctfmon.exe” [2002-09-20 19:05 20480]
“Gadu-Gadu”=“C:\Documents and Settings\Agatka\Pulpit\Gadu-Gadu\gg.exe” [2007-11-14 12:54 2131392]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2002-08-20 16:08 1519645]
“PcSync”=“C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe” [2006-06-27 17:21 1458176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Broadcom Wireless Manager UI”=“C:\WINDOWS\System32\WLTRAY.exe” [2005-11-11 14:40 1245184]
“lxccmon.exe”=“C:\Program Files\Lexmark 3300 Series\lxccmon.exe” [2005-07-21 02:17 200704]
“FaxCenterServer”=“C:\Program Files\Lexmark Fax Solutions\fm3032.exe” [2005-07-12 11:36 307200]
“igfxtray”=“C:\WINDOWS\System32\igfxtray.exe” [2006-03-23 06:17 102400]
“igfxhkcmd”=“C:\WINDOWS\System32\hkcmd.exe” [2006-03-23 06:13 86016]
“igfxpers”=“C:\WINDOWS\System32\igfxpers.exe” [2006-03-23 06:17 126976]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2006-03-03 07:07 770138]
“SkyTel”=“SkyTel.EXE” [2006-05-16 12:04 2889728 C:\WINDOWS\SkyTel.exe]
“RTHDCPL”=“RTHDCPL.EXE” [2006-06-28 08:54 16256512 C:\WINDOWS\RTHDCPL.exe]
“AzMixerSel”=“C:\Program Files\Realtek\InstallShield\AzMixerSel.exe” [2005-12-21 09:02 61440]
“LManager”=“C:\PROGRA~1\LAUNCH~1\LManager.exe” [2006-07-20 16:15 602112]
“LXCCCATS”=“C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll” [2005-07-20 15:44 73728]
“PCSuiteTrayApplication”=“C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe” [2006-06-15 13:36 237568]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [2002-09-20 19:05 20480]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 01:00:00 36864]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 21:05:56 73780]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzzd32]
winzzd32.dll
.
Contents of the ‘Scheduled Tasks’ folder
“2008-04-18 17:36:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job”
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 12:31:25
Windows 5.1.2600 Dodatek Service Pack. 1 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCCCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16???
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-27 12:31:57
ComboFix-quarantined-files.txt 2008-04-27 10:31:54
Pre-Run: 4,265,947,136 bajtów wolnych
Post-Run: 4,710,408,192 bajtów wolnych
216