ComboFix 08-02-13.2 - Kornel 2008-02-13 2:30:50.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.631 [GMT 1:00] Running from: E:\Downloads\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . C:\Program Files\SystemDefender C:\WINDOWS\msvb.dll C:\WINDOWS\system32\drivers\npf.sys C:\WINDOWS\system32\packet.dll C:\WINDOWS\system32\wpcap.dll C:\WINDOWS\wsremover.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\NPF ((((((((((((((((((((((((( Files Created from 2008-01-13 to 2008-02-13 ))))))))))))))))))))))))))))))) . 2008-02-11 23:25 . 2008-02-11 23:25 2008-02-11 19:36 . 2008-02-13 02:31 3,537,440 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2008-02-11 19:36 . 2008-02-11 19:52 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat 2008-02-11 19:36 . 2008-02-11 19:52 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat 2008-02-11 19:36 . 2008-02-13 02:26 51,344 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2008-02-11 19:36 . 2008-02-13 02:32 38,944 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2008-02-11 19:36 . 2008-02-13 02:26 5,624 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2008-02-11 19:16 . 2008-02-11 19:16 2008-02-11 18:16 . 2008-02-11 18:16 2008-02-11 18:16 . 2008-02-13 02:27 2008-02-11 14:27 . 2008-02-11 14:27 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe 2008-02-11 02:29 . 2008-02-11 02:29 2008-02-11 02:29 . 2008-01-31 23:13 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx 2008-02-11 02:29 . 2008-01-31 23:13 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts 2008-02-11 02:27 . 2008-02-11 02:27 2008-02-11 02:27 . 2008-02-11 02:27 2008-02-11 01:25 . 2008-02-11 01:25 5,120 --ahs---- C:\WINDOWS\system32\Thumbs.db 2008-02-09 03:05 . 2008-02-09 03:11 2008-02-07 04:04 . 2008-02-07 04:04 2008-02-07 03:59 . 2008-02-07 03:59 2008-02-03 22:56 . 2008-02-03 22:56 2008-02-02 02:53 . 2008-02-02 02:53 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll 2008-02-02 02:13 . 2008-02-11 02:29 2008-02-02 02:11 . 2008-02-11 02:19 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-02-02 02:11 . 2008-02-02 02:11 1,409 --a------ C:\WINDOWS\QTFont.for 2008-01-31 03:02 . 2008-01-31 03:02 54,608 --a------ C:\WINDOWS\system32\xfcodec.dll 2008-01-29 21:37 . 2008-01-29 21:37 2008-01-29 21:36 . 2008-01-29 21:36 2008-01-26 04:49 . 2006-03-23 19:53 442,368 --a------ C:\WINDOWS\system32\CapabilityTable.exe 2008-01-26 04:49 . 2006-03-23 19:51 208,896 --a------ C:\WINDOWS\system32\nvunrm.exe 2008-01-26 04:49 . 2006-03-22 14:23 109,568 --a------ C:\WINDOWS\system32\drivers\nvtcp.sys 2008-01-26 04:49 . 2006-02-20 13:00 3,903 --a------ C:\WINDOWS\system32\nvnrm.nvu 2008-01-26 04:40 . 2008-01-26 04:40 2008-01-26 04:27 . 2008-01-26 04:27 2008-01-26 03:50 . 2008-01-26 03:50 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS 2008-01-26 02:50 . 2008-01-26 02:50 45 --a------ C:\WINDOWS\system32\initdebug.nfo 2008-01-22 10:18 . 2008-01-22 10:18 7,808 --a------ C:\WINDOWS\system32\drivers\psi_mf.sys 2008-01-18 22:02 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2008-01-18 22:01 . 2008-01-18 22:02 2008-01-18 22:01 . 2008-01-18 22:01 2008-01-17 04:01 . 2008-01-17 04:01 2008-01-17 01:19 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll 2008-01-17 01:19 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll 2008-01-17 01:19 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll 2008-01-17 01:19 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll 2008-01-16 00:00 . 2008-01-16 00:00 2008-01-14 00:06 . 2008-01-14 00:07 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-13 01:18 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\Xfire 2008-02-11 18:43 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\FileZilla 2008-02-11 17:19 --------- d—a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP 2008-02-11 01:27 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-02-11 01:23 --------- d-----w C:\Program Files\DivX 2008-02-09 20:52 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\Skype 2008-02-09 19:45 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\skypePM 2008-02-09 00:32 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\Bioshock 2008-02-08 23:20 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-02-07 04:22 737,280 ----a-w C:\WINDOWS\iun6002.exe 2008-02-07 03:05 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2008-02-04 00:02 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\Nokia Multimedia Player 2008-02-03 21:56 --------- d-----w C:\Program Files\Common Files\Nokia 2008-02-03 21:55 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Installations 2008-02-03 21:15 --------- d-----w C:\Program Files\LIVEUPDATE 2008-01-29 01:19 --------- d-----w C:\Program Files\Microsoft Silverlight 2008-01-25 20:19 413,696 ----a-w C:\WINDOWS\system32\wrap_oal.dll 2008-01-25 20:19 110,592 ----a-w C:\WINDOWS\system32\OpenAL32.dll 2008-01-21 01:31 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-01-20 15:39 --------- d–h--w C:\Program Files\InstallShield Installation Information 2008-01-18 21:34 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys 2008-01-16 10:52 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2008-01-15 22:41 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2008-01-11 21:55 --------- d-----w C:\Program Files\Realtek 2008-01-10 19:07 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\WeGame 2008-01-08 23:15 --------- d-----w C:\Program Files\Common Files\PCSuite 2008-01-08 23:14 --------- d-----w C:\Program Files\PC Connectivity Solution 2008-01-08 23:05 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\Nokia 2008-01-08 22:34 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\Ahead 2008-01-08 22:33 --------- d-----w C:\Program Files\Common Files\Ahead 2008-01-08 22:05 --------- d-----w C:\Program Files\Google 2008-01-05 22:18 --------- d-----w C:\Program Files\Flock 2008-01-02 15:07 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\IEPro 2007-12-27 21:48 81,920 ----a-w C:\Documents and Settings\Kornel\Dane aplikacji\ezpinst.exe 2007-12-27 21:48 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys 2007-12-27 21:48 47,360 ----a-w C:\Documents and Settings\Kornel\Dane aplikacji\pcouffin.sys 2007-12-27 21:48 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\Vso 2007-12-24 15:32 --------- d-----w C:\Documents and Settings\Kornel\Dane aplikacji\DAEMON Tools 2007-12-24 12:49 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2007-12-20 17:00 4,637,696 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys 2007-12-20 15:47 16,860,672 ----a-w C:\WINDOWS\RTHDCPL.exe 2007-12-05 00:41 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll 2007-12-05 00:41 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll 2007-12-05 00:41 8,523,776 ----a-w C:\WINDOWS\system32\nvcpl.dll 2007-12-05 00:41 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe 2007-12-05 00:41 6,901,760 ----a-w C:\WINDOWS\system32\nvoglnt.dll 2007-12-05 00:41 6,549,504 ----a-w C:\WINDOWS\system32\nvdisps.dll 2007-12-05 00:41 5,773,568 ----a-w C:\WINDOWS\system32\nv4_disp.dll 2007-12-05 00:41 5,611,520 ----a-w C:\WINDOWS\system32\nvdispsr.dll 2007-12-05 00:41 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll 2007-12-05 00:41 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll 2007-12-05 00:41 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2007-12-05 00:41 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe 2007-12-05 00:41 425,984 ----a-w C:\WINDOWS\system32\keystone.exe 2007-12-05 00:41 385,024 ----a-w C:\WINDOWS\system32\nvapi.dll 2007-12-05 00:41 35,328 ----a-w C:\WINDOWS\system32\nvcodins.dll 2007-12-05 00:41 35,328 ----a-w C:\WINDOWS\system32\nvcod.dll 2007-12-05 00:41 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll 2007-12-05 00:41 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll 2007-12-05 00:41 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll 2007-12-05 00:41 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll 2007-12-05 00:41 327,680 ----a-w C:\WINDOWS\system32\nvrshe.dll 2007-12-05 00:41 327,680 ----a-w C:\WINDOWS\system32\nvrsar.dll 2007-12-05 00:41 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll 2007-12-05 00:41 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll 2007-12-05 00:41 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll 2007-12-05 00:41 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll 2007-12-05 00:41 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll 2007-12-05 00:41 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll 2007-12-05 00:41 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll 2007-12-05 00:41 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll 2007-12-05 00:41 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll 2007-12-05 00:41 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll 2007-12-05 00:41 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll 2007-12-05 00:41 3,715,072 ----a-w C:\WINDOWS\system32\nvvitvsr.dll 2007-12-05 00:41 3,710,976 ----a-w C:\WINDOWS\system32\nvvitvs.dll 2007-12-05 00:41 3,420,160 ----a-w C:\WINDOWS\system32\nvgames.dll 2007-12-05 00:41 3,334,144 ----a-w C:\WINDOWS\system32\nvgamesr.dll 2007-12-05 00:41 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll 2007-12-05 00:41 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll 2007-12-05 00:41 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll 2007-12-05 00:41 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll 2007-12-05 00:41 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll 2007-12-05 00:41 290,816 ----a-w C:\WINDOWS\system32\nvwrsth.dll 2007-12-05 00:41 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll 2007-12-05 00:41 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll 2007-12-05 00:41 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll 2007-12-05 00:41 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll 2007-12-05 00:41 282,624 ----a-w C:\WINDOWS\system32\nvrsfr.dll 2007-12-05 00:41 282,624 ----a-w C:\WINDOWS\system32\nvrses.dll 2007-12-05 00:41 282,624 ----a-w C:\WINDOWS\system32\nvrsel.dll 2007-12-05 00:41 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll 2007-12-05 00:41 278,528 ----a-w C:\WINDOWS\system32\nvrsit.dll 2007-12-05 00:41 278,528 ----a-w C:\WINDOWS\system32\nvrsde.dll 2007-12-05 00:41 274,432 ----a-w C:\WINDOWS\system32\nvrspt.dll 2007-12-05 00:41 274,432 ----a-w C:\WINDOWS\system32\nvrsnl.dll 2007-12-05 00:41 274,432 ----a-w C:\WINDOWS\system32\nvrsesm.dll 2007-12-05 00:41 270,336 ----a-w C:\WINDOWS\system32\nvrsru.dll 2007-12-05 00:41 266,240 ----a-w C:\WINDOWS\system32\nvrsptb.dll 2007-12-05 00:41 266,240 ----a-w C:\WINDOWS\system32\nvrsja.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44 15360] “DAEMON Tools Lite”=“E:\Programy\DAEMON Tools\daemon.exe” [2008-01-17 17:51 486856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2007-12-05 01:41 8523776] “HPDJ Taskbar Utility”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe” [2003-11-10 20:21 176128] “Logitech Hardware Abstraction Layer”=“KHALMNPR.EXE” [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe] “amd_dc_opt”=“C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe” [2007-07-23 11:06 77824] “NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2007-12-05 01:41 81920] “RTHDCPL”=“RTHDCPL.EXE” [2007-12-20 16:47 16860672 C:\WINDOWS\RTHDCPL.exe] “AVP”=“E:\Programy\Kav7\avp.exe” [2007-06-28 12:51 218376] “UnlockerAssistant”=“E:\Programy\Unlocker\UnlockerAssistant.exe” [2006-09-07 18:19 15872] “Adobe Reader Speed Launcher”=“E:\Programy\Adobe Reader 8\Reader\Reader_sl.exe” [2007-05-11 13:06 40048] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44 15360] “Nokia.PCSync”=“E:\Programy\Nokia PC Suite\Nokia PC Suite 6\PcSync2.exe” [2007-11-07 17:35 1294336] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-10-16 21:23:50 692224] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv] E:\Programy\WindowBlinds\wbsrv.dll 2007-09-23 09:10 229376 E:\Programy\WindowBlinds\WbSrv.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “AppInit_DLLs”=wbsys.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock] E:\Programy\RocketDock\RocketDock.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] --a------ 2007-11-20 18:15 1826816 C:\WINDOWS\SkyTel.exe R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys [2006-07-05 13:46] R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58] S3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2008-01-22 10:18] S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08] . Contents of the ‘Scheduled Tasks’ folder “2008-02-12 19:14:19 C:\WINDOWS\Tasks\User_Feed_Synchronization-{C42B96CA-51FA-459A-8879-B5B15F0630D7}.job” - C:\WINDOWS\system32\msfeedssync.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-13 02:32:27 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156] - E:\Programy\Unlocker\UnlockerHook.dll . Completion time: 2008-02-13 2:33:16 ComboFix-quarantined-files.txt 2008-02-13 01:33:13 . 2008-01-09 15:50:45 — E O F — Może Ty mi wytłumaczysz, skąd się wzięło takie cholerstwo, jeśli staram się dbać o komputer?