ComboFix 07-05.27.BV - Running from: “D:\Documents and Settings\Kasia\Pulpit\waľne narz©dzia” Error: dll_whitelist.cf Error: whitedir.cf Error: miscfile.cf Error: attr.cf ((((((((((((((((((((((((((((((( Files Created from 2007-04-28 to 2007-05-30 )))))))))))))))))))))))))))))))))) 2007-05-31 00:33 64 --a------ D:\ComboFix.txt.bat 2007-05-31 00:30 2007-05-31 00:10 2007-05-29 21:24 87,040 --a------ D:\WINDOWS\catchme.exe 2007-05-29 21:24 49,152 --a------ D:\WINDOWS\system32\vfind.exe 2007-05-29 21:24 49,152 --a------ D:\WINDOWS\nircmd.exe 2007-05-29 21:24 428,032 --a------ D:\WINDOWS\system32\swreg.exe 2007-05-29 21:24 38,400 --a------ D:\WINDOWS\system32\moveex.exe 2007-05-29 21:24 370,688 --a------ D:\WINDOWS\system32\swsc.exe 2007-05-29 21:24 212,480 --a------ D:\WINDOWS\system32\swxcacls.exe 2007-05-29 21:18 2007-05-26 09:56 2007-05-11 21:46 2007-05-11 12:11 2007-05-10 21:11 2007-05-10 20:08 2007-05-10 19:35 2007-05-10 10:52 2007-05-06 19:05 73,728 --a------ D:\WINDOWS\system32\pv.exe 2007-05-06 19:05 39,184 --a------ D:\WINDOWS\system32\Ntrights.exe 2007-05-06 19:05 175,616 --a------ D:\WINDOWS\system32\strings.exe 2007-05-06 19:05 16,384 --a------ D:\WINDOWS\system32\restart.exe 2007-05-06 19:05 126,976 --a------ D:\WINDOWS\system32\zip.exe 2007-05-06 19:05 11,254 --a------ D:\WINDOWS\system32\locate.com 2007-05-05 19:39 76,560 --a------ D:\WINDOWS\system32\drivers\tmcomm.sys 2007-05-05 19:39 2007-05-05 09:53 25,992 --a------ D:\WINDOWS\system32\pgdfgsvc.exe 2007-05-04 22:02 2007-05-04 16:41 2007-05-02 16:11 46,892 --a------ D:\WINDOWS\system32\adadix16.dll 2007-05-02 16:11 46,167 --a------ D:\WINDOWS\system32\drivers\adildr.sys 2007-05-02 16:11 4,981 --a------ D:\WINDOWS\system32\adadix2k.dll 2007-05-02 16:11 22,395 --a------ D:\WINDOWS\system32\drivers\fpga.bin 2007-05-02 16:11 155,648 --a------ D:\WINDOWS\system32\adadix32.dll 2007-05-02 16:11 143,360 --a------ D:\WINDOWS\autoclk.exe 2007-05-02 16:11 135,168 --a------ D:\WINDOWS\system32\unaddrv.exe 2007-05-02 16:11 127,497 --a------ D:\WINDOWS\system32\drivers\adiusbaw.sys 2007-05-02 16:11 127,456 --a------ D:\WINDOWS\system32\ipdetect.exe 2007-05-02 16:11 126,976 --a------ D:\WINDOWS\system32\coclassfast.dll 2007-05-02 16:11 2007-05-02 15:35 2007-05-02 15:35 2007-05-02 13:23 2007-05-02 12:59 3,145,728 --a------ D:\Documents and Settings\Kasia\ntuser.dat 2007-05-01 17:45 2007-05-01 12:07 80 --a------ D:\WINDOWS\gmer_uninstall.cmd 2007-05-01 12:07 69,905 --a------ D:\WINDOWS\system32\drivers\gmer.sys 2007-05-01 12:07 577,536 -ra------ D:\WINDOWS\gmer.exe 2007-05-01 12:07 573,503 --a------ D:\WINDOWS\gmer.dll 2007-05-01 11:52 2007-05-01 11:45 2007-04-27 22:39 26,622 --a------ D:\WINDOWS\system32\lr86.exe 2007-04-23 13:20 2007-04-16 16:58 0 --a------ D:\WINDOWS\system32\CMMGR32.EXE 2007-04-15 12:41 128,232 --a------ D:\WINDOWS\system32\mucltui.dll 2007-04-14 19:02 726,920 --a------ D:\Program Files\WindowsXP-KB935448-x86-PLK.exe 2007-04-14 18:57 4,709,688 --a------ D:\Program Files\WindowsXP-KB922760-x86-PLK.exe 2007-04-14 17:37 2007-04-14 16:49 125,208 --a------ D:\WINDOWS\system32\wuauclt.exe 2007-04-14 16:49 1,343,768 --a------ D:\WINDOWS\system32\wuaueng.dll 2007-04-14 16:44 24,661 --a------ D:\WINDOWS\system32\spxcoins.dll 2007-04-14 16:44 13,312 --a------ D:\WINDOWS\system32\irclass.dll 2007-04-14 16:38 402,653,184 D:\pagefile.sys 2007-04-14 16:38 2007-04-14 16:30 37,860,928 --a------ D:\Program Files\iTunesSetup.exe 2007-04-14 09:12 2007-04-10 21:05 2007-04-10 20:32 2007-04-10 20:28 68,888 --a------ D:\WINDOWS\system32\xinput1_3.dll 2007-04-10 20:28 62,744 --a------ D:\WINDOWS\system32\xinput1_2.dll 2007-04-10 20:28 62,672 --a------ D:\WINDOWS\system32\xinput1_1.dll 2007-04-10 20:28 61,136 --a------ D:\WINDOWS\system32\xinput9_1_0.dll 2007-04-10 20:28 237,848 --a------ D:\WINDOWS\system32\xactengine2_4.dll 2007-04-10 20:28 236,824 --a------ D:\WINDOWS\system32\xactengine2_3.dll 2007-04-10 20:28 230,168 --a------ D:\WINDOWS\system32\xactengine2_2.dll 2007-04-10 20:28 230,096 --a------ D:\WINDOWS\system32\xactengine2_0.dll 2007-04-10 20:28 229,584 --a------ D:\WINDOWS\system32\xactengine2_1.dll 2007-04-10 20:28 2,414,360 --a------ D:\WINDOWS\system32\d3dx9_31.dll 2007-04-10 20:28 2,388,176 --a------ D:\WINDOWS\system32\d3dx9_30.dll 2007-04-10 20:28 2,337,488 --a------ D:\WINDOWS\system32\d3dx9_25.dll 2007-04-10 20:28 2,332,368 --a------ D:\WINDOWS\system32\d3dx9_29.dll 2007-04-10 20:28 2,323,664 --a------ D:\WINDOWS\system32\d3dx9_28.dll 2007-04-10 20:28 2,319,568 --a------ D:\WINDOWS\system32\d3dx9_27.dll 2007-04-10 20:28 2,297,552 --a------ D:\WINDOWS\system32\d3dx9_26.dll 2007-04-10 20:28 2,222,800 --a------ D:\WINDOWS\system32\d3dx9_24.dll 2007-04-10 20:28 15,128 --a------ D:\WINDOWS\system32\x3daudio1_1.dll 2007-04-10 20:28 14,032 --a------ D:\WINDOWS\system32\x3daudio1_0.dll 2007-04-10 20:28 2007-04-10 20:26 98,816 --a------ D:\WINDOWS\system32\dmstyle.dll 2007-04-10 20:26 974,848 --a------ D:\WINDOWS\system32\dxdiag.exe 2007-04-10 20:26 83,968 --a------ D:\WINDOWS\system32\drivers\nabtsfec.sys 2007-04-10 20:26 80,896 --a------ D:\WINDOWS\system32\dpvsetup.exe 2007-04-10 20:26 8,192 --a------ D:\WINDOWS\system32\d3d8thk.dll 2007-04-10 20:26 797,184 --a------ D:\WINDOWS\system32\d3dim700.dll 2007-04-10 20:26 79,360 --a------ D:\WINDOWS\system32\dpwsockx.dll 2007-04-10 20:26 77,824 --a------ D:\WINDOWS\system32\dpmodemx.dll 2007-04-10 20:26 76,800 --a------ D:\WINDOWS\system32\dmscript.dll 2007-04-10 20:26 733,184 --a------ D:\WINDOWS\system32\qedwipes.dll 2007-04-10 20:26 723,968 --a------ D:\WINDOWS\system32\dpnet.dll 2007-04-10 20:26 7,424 --a------ D:\WINDOWS\system32\drivers\mskssrv.sys 2007-04-10 20:26 68,096 --a------ D:\WINDOWS\system32\dpnhupnp.dll 2007-04-10 20:26 667,648 --a------ D:\WINDOWS\system32\dinput8.dll 2007-04-10 20:26 648,704 --a------ D:\WINDOWS\system32\dinput.dll 2007-04-10 20:26 64,512 --a------ D:\WINDOWS\system32\amstream.dll 2007-04-10 20:26 602,624 --a------ D:\WINDOWS\system32\dx7vb.dll 2007-04-10 20:26 590,336 --a------ D:\WINDOWS\system32\d3dramp.dll 2007-04-10 20:26 58,368 --a------ D:\WINDOWS\system32\dmcompos.dll 2007-04-10 20:26 52,096 --a------ D:\WINDOWS\system32\drivers\msdv.sys 2007-04-10 20:26 5,504 --a------ D:\WINDOWS\system32\drivers\mstee.sys 2007-04-10 20:26 5,248 --a------ D:\WINDOWS\system32\drivers\mspclock.sys 2007-04-10 20:26 491,520 --a------ D:\WINDOWS\system32\dsdmoprp.dll 2007-04-10 20:26 48,512 --a------ D:\WINDOWS\system32\drivers\stream.sys 2007-04-10 20:26 470,528 --a------ D:\WINDOWS\system32\qdvd.dll 2007-04-10 20:26 47,616 --a------ D:\WINDOWS\system32\d3dxof.dll 2007-04-10 20:26 47,104 --a------ D:\WINDOWS\system32\wstdecod.dll 2007-04-10 20:26 467,968 --a------ D:\WINDOWS\system32\diactfrm.dll 2007-04-10 20:26 44,032 --a------ D:\WINDOWS\system32\dimap.dll 2007-04-10 20:26 436,224 --a------ D:\WINDOWS\system32\d3dim.dll 2007-04-10 20:26 4,608 --a------ D:\WINDOWS\system32\drivers\mspqm.sys 2007-04-10 20:26 4,096 --a------ D:\WINDOWS\system32\ksuser.dll 2007-04-10 20:26 4,096 --a------ D:\WINDOWS\system32\drivers\swenum.sys 2007-04-10 20:26 381,952 --a------ D:\WINDOWS\system32\dsound.dll 2007-04-10 20:26 381,952 --a------ D:\WINDOWS\system32\dpvoice.dll 2007-04-10 20:26 354,816 --a------ D:\WINDOWS\system32\psisdecd.dll 2007-04-10 20:26 350,208 --a------ D:\WINDOWS\system32\d3drm.dll 2007-04-10 20:26 34,816 --a------ D:\WINDOWS\system32\d3dpmesh.dll 2007-04-10 20:26 34,304 --a------ D:\WINDOWS\system32\mciqtz32.dll 2007-04-10 20:26 33,280 --a------ D:\WINDOWS\system32\dmloader.dll 2007-04-10 20:26 324,096 --a------ D:\WINDOWS\system32\mswebdvd.dll 2007-04-10 20:26 32,768 --a------ D:\WINDOWS\system32\dpnhpast.dll 2007-04-10 20:26 316,928 --a------ D:\WINDOWS\system32\qdv.dll 2007-04-10 20:26 31,744 --a------ D:\WINDOWS\system32\pid.dll 2007-04-10 20:26 3,072 --a------ D:\WINDOWS\system32\dpnlobby.dll 2007-04-10 20:26 3,072 --a------ D:\WINDOWS\system32\dpnaddr.dll 2007-04-10 20:26 292,864 --a------ D:\WINDOWS\system32\ddraw.dll 2007-04-10 20:26 28,160 --a------ D:\WINDOWS\system32\dplaysvr.exe 2007-04-10 20:26 27,136 --a------ D:\WINDOWS\system32\dmband.dll 2007-04-10 20:26 257,024 --a------ D:\WINDOWS\system32\qcap.dll 2007-04-10 20:26 24,064 --a------ D:\WINDOWS\system32\ddrawex.dll 2007-04-10 20:26 230,400 --a------ D:\WINDOWS\system32\dplayx.dll 2007-04-10 20:26 223,232 --a------ D:\WINDOWS\system32\gcdef.dll 2007-04-10 20:26 19,968 --a------ D:\WINDOWS\system32\dpvacm.dll 2007-04-10 20:26 186,880 --a------ D:\WINDOWS\system32\dsdmo.dll 2007-04-10 20:26 181,248 --a------ D:\WINDOWS\system32\dmime.dll 2007-04-10 20:26 18,944 --a------ D:\WINDOWS\system32\encapi.dll 2007-04-10 20:26 18,688 --a------ D:\WINDOWS\system32\drivers\wstcodec.sys 2007-04-10 20:26 18,432 --a------ D:\WINDOWS\system32\dswave.dll 2007-04-10 20:26 173,056 --a------ D:\WINDOWS\system32\qasf.dll 2007-04-10 20:26 16,896 --a------ D:\WINDOWS\system32\msyuv.dll 2007-04-10 20:26 16,896 --a------ D:\WINDOWS\system32\dpnsvr.exe 2007-04-10 20:26 16,384 --a------ D:\WINDOWS\system32\drivers\ccdecode.sys 2007-04-10 20:26 15,104 --a------ D:\WINDOWS\system32\drivers\mpe.sys 2007-04-10 20:26 14,976 --a------ D:\WINDOWS\system32\drivers\streamip.sys 2007-04-10 20:26 132,608 --a------ D:\WINDOWS\system32\devenum.dll 2007-04-10 20:26 130,304 --a------ D:\WINDOWS\system32\drivers\ks.sys 2007-04-10 20:26 13,312 --a------ D:\WINDOWS\system32\msdmo.dll 2007-04-10 20:26 122,880 --a------ D:\WINDOWS\system32\dmusic.dll 2007-04-10 20:26 112,128 --a------ D:\WINDOWS\system32\dpvvox.dll 2007-04-10 20:26 11,392 --a------ D:\WINDOWS\system32\drivers\bdasup.sys 2007-04-10 20:26 100,864 --a------ D:\WINDOWS\system32\dmsynth.dll 2007-04-10 20:26 10,880 --a------ D:\WINDOWS\system32\drivers\slip.sys 2007-04-10 20:26 10,496 --a------ D:\WINDOWS\system32\drivers\dxapi.sys 2007-04-10 20:26 10,112 --a------ D:\WINDOWS\system32\drivers\ndisip.sys 2007-04-10 20:26 1,962,496 --a------ D:\WINDOWS\system32\quartz.dll 2007-04-10 20:26 1,798,144 --a------ D:\WINDOWS\system32\qedit.dll 2007-04-10 20:26 1,769,472 --a------ D:\WINDOWS\system32\dxdiagn.dll 2007-04-10 20:26 1,703,936 --a------ D:\WINDOWS\system32\d3d9.dll 2007-04-10 20:26 1,294,336 --a------ D:\WINDOWS\system32\dsound3d.dll 2007-04-10 20:26 1,230,336 --a------ D:\WINDOWS\system32\msvidctl.dll 2007-04-10 20:26 1,201,152 --a------ D:\WINDOWS\system32\d3d8.dll 2007-04-10 20:26 1,189,888 --a------ D:\WINDOWS\system32\dx8vb.dll 2007-04-10 19:58 2007-04-06 11:53 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-05-30 22:29:54 2,048 --s-a-w D:\WINDOWS\bootstat.dat 2007-05-30 22:29:48 402,653,184 --sha-w D:\pagefile.sys 2007-05-26 07:58:36 12,400 ----a-w D:\WINDOWS\system32\drivers\secdrv.sys 2007-05-01 09:43:54 -------- d-----w D:\Documents and Settings\Kasia\Dane aplikacji\SiteAdvisor 2007-04-14 15:43:24 49,492 ----a-w D:\WINDOWS\system32\perfc015.dat 2007-04-14 15:43:24 39,992 ----a-w D:\WINDOWS\system32\perfc009.dat 2007-04-14 15:43:24 355,486 ----a-w D:\WINDOWS\system32\perfh015.dat 2007-04-14 15:43:24 311,604 ----a-w D:\WINDOWS\system32\perfh009.dat 2007-04-14 14:59:42 250,288 ----a-w D:\WINDOWS\system32\FNTCACHE.DAT 2007-04-14 14:50:36 23,016 ----a-w D:\WINDOWS\system32\emptyregdb.dat 2007-04-10 18:54:30 -------- d-----w D:\Documents and Settings\Kasia\Dane aplikacji\FunkyFarm 2007-03-30 15:00:22 -------- d-----w D:\Program Files\Microsoft.NET 2007-03-30 14:58:54 -------- d-----w D:\Program Files\Common Files\DESIGNER 2007-03-30 14:58:44 -------- d-----w D:\Program Files\Microsoft Works 2007-03-30 14:41:58 -------- d-----w D:\Program Files\Windows Messaging 2007-03-14 00:04:46 139,264 ----a-w D:\WINDOWS\system32\javaws.exe 2007-03-13 22:31:28 135,168 ----a-w D:\WINDOWS\system32\javaw.exe 2007-03-13 22:31:24 135,168 ----a-w D:\WINDOWS\system32\java.exe 2007-03-07 10:36:34 12,619,736 ----a-w D:\WINDOWS\system32\MRT.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {089FD14D-132B-48FC-8861-0048AE113215}=D:\Program Files\SiteAdvisor\6066\SiteAdv.dll [2007-03-30 17:41] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SiteAdvisor”=“D:\Program Files\SiteAdvisor\6066\SiteAdv.exe” [2007-03-30 17:42] “WOOWATCH”=“D:\PROGRA~1\WANADOO\Watch.exe” [2002-12-09 18:24] “WOOTASKBARICON”=“D:\PROGRA~1\WANADOO\TaskbarIcon.exe” [2002-12-09 18:24] “win msdt service”=“mswindtc.exe” [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Odkurzacz-MCD”=“D:\Program Files\Odkurzacz\odk_mcd.exe” [2007-05-03 10:02] “Spyware Doctor”=“D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe” [2007-03-26 21:09] “win msdt service”=“mswindtc.exe” [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices] “win msdt service”=mswindtc.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices] “win msdt service”=mswindtc.exe [HKEY_USERS.default\software\microsoft\windows\currentversion\runservices] “win msdt service”=mswindtc.exe [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Spyware Doctor”=“D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe” /Q “win msdt service”=mswindtc.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk] path=c:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk backup=D:\WINDOWS\pss\DSLMON.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^VIA RAID TOOL.lnk] backup=D:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^Kasia^Menu Start^Programy^Autostart^Trend Micro Anti-Spyware.lnk] backup=D:\WINDOWS\pss\Trend Micro Anti-Spyware.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “D:\Program Files\Messenger\msmsgs.exe” /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor] “D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe” /Q HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs* ******************************************************************** catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-31 00:35:18 Windows 5.1.2600 FAT NTAPI scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 2007-05-31 0:35:37 D:\ComboFix3.txt … 2007-05-29 21:25 D:\ComboFix-quarantined-files.txt … 2007-05-31 00:35 D:\ComboFix2.txt … 2007-05-31 00:10 — E O F —