ComboFix 07-10-17.8@ - Abakus 2007-10-17 0:46:15.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.191 [GMT 2:00] Running from: D:\Documents and Settings\Abakus\Pulpit\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-09-17 to 2007-10-17 ))))))))))))))))))))))))))))))) . 2007-10-17 00:41 51,200 --a------ D:\WINDOWS\NirCmd.exe 2007-10-17 00:38 336,256 --a------ D:\WINDOWS\system32\drivers\srv.sys 2007-10-07 20:02 2007-10-07 15:49 2007-10-07 15:37 153,088 --a------ D:\WINDOWS\system32\irftp.exe 2007-10-07 15:37 87,424 --a------ D:\WINDOWS\system32\drivers\irda.sys 2007-10-07 15:37 27,648 --a------ D:\WINDOWS\system32\irmon.dll 2007-10-07 15:37 26,624 --a------ D:\WINDOWS\system32\drivers\irstusb.sys 2007-10-07 15:37 19,584 --a------ D:\WINDOWS\system32\drivers\rasirda.sys 2007-10-07 15:37 8,192 --a------ D:\WINDOWS\system32\wshirda.dll 2007-10-07 14:33 2007-10-07 08:17 2007-10-07 07:54 2007-10-06 11:50 584,192 -----c— D:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-10-06 10:16 2007-10-06 00:34 2007-10-03 16:22 2007-10-03 13:20 2007-10-03 12:09 2007-10-03 03:34 63,488 --a------ D:\WINDOWS\xobglu16.dll 2007-10-03 03:34 23,552 --a------ D:\WINDOWS\xobglu32.dll 2007-10-03 00:32 2007-10-02 23:23 2007-09-26 16:40 2007-09-26 15:26 2007-09-26 15:26 2007-09-26 12:54 8,482,304 -----c— D:\WINDOWS\system32\dllcache\shell32.dll 2007-09-26 12:54 135,168 -----c— D:\WINDOWS\system32\dllcache\shsvcs.dll 2007-09-26 12:44 450,560 -----c— D:\WINDOWS\system32\dllcache\jscript.dll 2007-09-26 12:44 359,808 -----c— D:\WINDOWS\system32\dllcache\tcpip.sys 2007-09-26 12:44 293,376 -----c— D:\WINDOWS\system32\dllcache\winsrv.dll 2007-09-26 12:44 111,104 -----c— D:\WINDOWS\system32\dllcache\dhcpcsvc.dll 2007-09-26 12:44 95,744 -----c— D:\WINDOWS\system32\dllcache\iphlpapi.dll 2007-09-26 03:16 2007-09-26 03:16 2007-09-26 03:16 40,960 --a------ D:\WINDOWS\system32\drivers\P2k.sys 2007-09-26 03:16 5,632 --a------ D:\WINDOWS\system32\drivers\motswch.sys 2007-09-26 03:15 2007-09-26 02:56 31,616 --a------ D:\WINDOWS\system32\drivers\usbccgp.sys 2007-09-26 02:56 31,616 --a–c— D:\WINDOWS\system32\dllcache\usbccgp.sys 2007-09-26 02:27 25,600 --a------ D:\WINDOWS\system32\drivers\usbser.sys 2007-09-26 02:27 25,600 --a–c— D:\WINDOWS\system32\dllcache\usbser.sys 2007-09-26 02:25 57,552 --a------ D:\WINDOWS\system32\WKDOS.EXE 2007-09-26 02:25 29,696 --a------ D:\WINDOWS\system32\drivers\Wibukey2.sys 2007-09-26 02:24 2007-09-26 02:24 2007-09-26 02:24 2007-09-26 02:24 139,264 --a------ D:\WINDOWS\system32\WkWin32.dll 2007-09-26 02:24 77,895 --a------ D:\WINDOWS\system32\unibus_tcutil.dll 2007-09-26 02:24 67,072 --a------ D:\WINDOWS\system32\drivers\Wibukey.sys 2007-09-26 02:24 52,736 --a------ D:\WINDOWS\system\WkWin.dll 2007-09-25 23:51 145,792 --a------ D:\WINDOWS\system32\drivers\portcls.sys 2007-09-25 23:51 60,288 --a------ D:\WINDOWS\system32\drivers\drmk.sys 2007-09-25 23:51 58,624 --a------ D:\WINDOWS\system32\drivers\redbook.sys 2007-09-25 23:51 42,240 --a------ D:\WINDOWS\system32\drivers\viaagp.sys 2007-09-25 23:51 10,624 --a------ D:\WINDOWS\system32\drivers\gameenum.sys 2007-09-25 23:51 4,096 --a------ D:\WINDOWS\system32\ksuser.dll 2007-09-25 23:51 2,944 --a------ D:\WINDOWS\system32\drivers\msmpu401.sys 2007-09-25 23:50 77,312 --a------ D:\WINDOWS\system32\usbui.dll 2007-09-25 23:49 2007-09-25 23:48 2007-09-25 21:38 453,120 -----c— D:\WINDOWS\system32\dllcache\mrxsmb.sys 2007-09-25 21:38 174,592 -----c— D:\WINDOWS\system32\dllcache\rdbss.sys 2007-09-25 21:34 539,136 -----c— D:\WINDOWS\system32\dllcache\msftedit.dll 2007-09-25 21:34 433,152 -----c— D:\WINDOWS\system32\dllcache\riched20.dll 2007-09-25 21:12 2007-09-25 20:11 1,277 --a------ D:\WINDOWS\mozver.dat 2007-09-25 18:41 2007-09-25 18:41 2007-09-25 18:39 2007-09-25 18:35 2007-09-25 18:31 2007-09-25 18:18 2007-09-25 18:16 2007-09-25 18:16 2007-09-25 18:15 2007-09-25 18:12 2007-09-25 18:10 2007-09-25 18:10 2007-09-25 18:07 2007-09-25 18:05 2007-09-25 18:05 2007-09-25 18:05 2007-09-25 17:58 2007-09-25 17:58 2007-09-25 17:58 2007-09-25 17:52 0 --a------ D:\WINDOWS\nsreg.dat 2007-09-25 17:51 42,880 -ra------ D:\WINDOWS\system32\drivers\viaudio.sys 2007-09-25 17:49 2007-09-25 17:47 2007-09-25 17:45 2007-09-25 17:44 2007-09-25 17:35 2007-09-25 17:35 2007-09-25 17:34 2007-09-25 17:25 2007-09-25 17:25 2007-09-25 17:25 208,896 --a------ D:\WINDOWS\system32\NVUNINST.EXE 2007-09-25 17:25 208,896 --a------ D:\WINDOWS\system32\nvudisp.exe 2007-09-25 17:21 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-07 13:38 --------- d–h--w D:\Program Files\InstallShield Installation Information 2007-09-26 12:34 --------- d-----w D:\Program Files\Common Files\InstallShield 2007-09-25 22:49 --------- d-----w D:\Program Files\Eurobarre 2007-09-25 22:45 15,872 ------w D:\WINDOWS\system32\winskfr.dll 2007-09-25 22:45 119,568 ------w D:\WINDOWS\system32\vb6fr.dll 2007-09-25 14:35 --------- d-----w D:\Program Files\Thomson 2007-09-25 14:27 --------- d-----w D:\Program Files\microsoft frontpage 2007-09-25 14:25 --------- d-----w D:\Program Files\Usługi online 2007-09-06 10:09 801,144 ----a-w D:\WINDOWS\system32\aswBoot.exe 2007-09-06 10:05 94,416 ----a-w D:\WINDOWS\system32\drivers\aswmon2.sys 2007-09-06 10:05 92,848 ----a-w D:\WINDOWS\system32\drivers\aswmon.sys 2007-09-06 10:03 23,152 ----a-w D:\WINDOWS\system32\drivers\aswRdr.sys 2007-09-06 10:02 42,912 ----a-w D:\WINDOWS\system32\drivers\aswTdi.sys 2007-09-06 10:00 95,608 ----a-w D:\WINDOWS\system32\AVASTSS.scr 2007-09-06 10:00 26,624 ----a-w D:\WINDOWS\system32\drivers\aavmker4.sys 2007-08-21 06:18 683,520 ----a-w D:\WINDOWS\system32\inetcomm.dll 2007-07-30 17:19 92,504 ----a-w D:\WINDOWS\system32\cdm.dll 2007-07-30 17:19 549,720 ----a-w D:\WINDOWS\system32\wuapi.dll 2007-07-30 17:19 53,080 ----a-w D:\WINDOWS\system32\wuauclt.exe 2007-07-30 17:19 43,352 ----a-w D:\WINDOWS\system32\wups2.dll 2007-07-30 17:19 325,976 ----a-w D:\WINDOWS\system32\wucltui.dll 2007-07-30 17:19 203,096 ----a-w D:\WINDOWS\system32\wuweb.dll 2007-07-30 17:19 1,712,984 ----a-w D:\WINDOWS\system32\wuaueng.dll 2007-07-30 17:18 33,624 ----a-w D:\WINDOWS\system32\wups.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NvCplDaemon”=“D:\WINDOWS\system32\NvCpl.dll” [2006-10-22 12:22] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “PeerGuardian”=“D:\Program Files\PeerGuardian2\pg2.exe” [2005-09-18 18:40] “H/PC Connection Agent”=“D:\Program Files\Microsoft ActiveSync\wcescomm.exe” [2006-11-13 15:57] “P2kAutostart”="" [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^Abakus^Menu Start^Programy^Autostart^Eurobarre.lnk] path=d:\Documents and Settings\Abakus\Menu Start\Programy\Eurobarre\eurobarre.lnk backup=D:\WINDOWS\pss\Eurobarre.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!] D:\PROGRA~1\AVAST4~1\ashDisp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent] “D:\Program Files\Microsoft ActiveSync\Wcescomm.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /install [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Odkurzacz-MCD] D:\Program Files\Odkurzacz\odk_mcd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2kAutostart] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] “D:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized R3 pgfilter;pgfilter;??\D:\Program Files\PeerGuardian2\pgfilter.sys *Newly Created Service* - PGFILTER . Contents of the ‘Scheduled Tasks’ folder “2007-09-26 13:26:47 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job” . ************************************************************************** catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-17 00:47:56 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … HKCU\Software\Microsoft\Windows\CurrentVersion\Run P2kAutostart = ??? scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-17 0:48:37 . — E O F —