“Admin” - 2007-11-20 23:09:06 Dodatek Service Pack 2 ComboFix 07-05.27.BV - Running from: “C:\Documents and Settings\Admin\Moje dokumenty\PorzĄdki” ((((((((((((((((((((((((((((((( Files Created from 2007-10-20 to 2007-11-20 )))))))))))))))))))))))))))))))))) 2007-11-18 17:13 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe 2007-11-18 17:13 2007-11-18 17:12 2007-11-18 17:11 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2007-11-18 13:11 32 --a------ C:\DOCUME~1\ALLUSE~1\DANEAP~1\ezsid.dat 2007-11-18 13:11 2007-11-18 13:07 2007-11-18 13:04 2007-11-18 13:04 2007-11-18 13:04 2007-11-17 21:38 669,184 --a------ C:\WINDOWS\system32\pbsvc.exe 2007-11-17 21:38 22,328 --a------ C:\DOCUME~1\Admin\DANEAP~1\PnkBstrK.sys 2007-11-16 13:25 34,576 --a------ C:\WINDOWS\system32\drivers\LHidFilt.Sys 2007-11-16 13:25 33,296 --a------ C:\WINDOWS\system32\drivers\LMouFilt.Sys 2007-11-16 13:25 28,176 --a------ C:\WINDOWS\system32\drivers\LUsbFilt.sys 2007-11-16 13:25 1,419,024 --a------ C:\WINDOWS\system32\WdfCoInstaller01005.dll 2007-11-16 13:25 2007-11-07 22:16 2007-11-07 22:15 2007-11-07 22:15 2007-10-30 18:31 2007-10-28 11:23 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll 2007-10-28 11:23 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll 2007-10-28 11:23 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll 2007-10-27 13:05 2007-10-27 13:05 2007-10-26 11:05 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll 2007-10-26 11:05 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll 2007-10-26 11:05 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-10-26 11:05 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll 2007-10-26 11:05 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll 2007-10-26 11:05 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll 2007-10-26 11:05 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll 2007-10-26 11:05 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll 2007-10-26 11:05 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-10-26 11:05 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll 2007-10-26 11:05 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-10-26 11:05 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll 2007-10-26 11:05 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-11-19 21:59:54 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\Free Download Manager 2007-11-17 20:38:31 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2007-11-17 20:38:21 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2007-11-16 22:28:57 -------- d-----w C:\Program Files\e-Kiosk Reader 2007-11-16 22:28:17 -------- d-----w C:\Program Files\ASUS 2007-11-16 12:25:45 -------- d-----w C:\Program Files\Common Files\Logitech 2007-11-07 21:21:57 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\Sports Interactive 2007-11-07 19:15:35 -------- d-----w C:\Program Files\Gadu-Gadu 2007-11-01 11:26:42 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-10-28 08:16:58 74,786 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-10-28 08:16:58 449,026 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-10-17 20:15:36 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\InstallShield 2007-10-17 20:10:35 -------- d-----w C:\Program Files\jv16 PowerTools 2007-10-04 20:18:13 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2007-10-04 16:14:00 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll 2007-10-04 16:14:00 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll 2007-10-04 16:14:00 8,491,008 ----a-w C:\WINDOWS\system32\nvcpl.dll 2007-10-04 16:14:00 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe 2007-10-04 16:14:00 6,854,464 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys 2007-10-04 16:14:00 6,750,208 ----a-w C:\WINDOWS\system32\nvoglnt.dll 2007-10-04 16:14:00 6,344,704 ----a-w C:\WINDOWS\system32\nvdisps.dll 2007-10-04 16:14:00 5,783,424 ----a-w C:\WINDOWS\system32\nv4_disp.dll 2007-10-04 16:14:00 5,509,120 ----a-w C:\WINDOWS\system32\nvdispsr.dll 2007-10-04 16:14:00 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll 2007-10-04 16:14:00 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll 2007-10-04 16:14:00 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2007-10-04 16:14:00 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe 2007-10-04 16:14:00 425,984 ----a-w C:\WINDOWS\system32\keystone.exe 2007-10-04 16:14:00 364,544 ----a-w C:\WINDOWS\system32\nvapi.dll 2007-10-04 16:14:00 36,864 ----a-w C:\WINDOWS\system32\nvcodins.dll 2007-10-04 16:14:00 36,864 ----a-w C:\WINDOWS\system32\nvcod.dll 2007-10-04 16:14:00 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll 2007-10-04 16:14:00 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll 2007-10-04 16:14:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll 2007-10-04 16:14:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll 2007-10-04 16:14:00 327,680 ----a-w C:\WINDOWS\system32\nvrshe.dll 2007-10-04 16:14:00 327,680 ----a-w C:\WINDOWS\system32\nvrsar.dll 2007-10-04 16:14:00 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll 2007-10-04 16:14:00 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll 2007-10-04 16:14:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll 2007-10-04 16:14:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll 2007-10-04 16:14:00 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll 2007-10-04 16:14:00 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll 2007-10-04 16:14:00 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll 2007-10-04 16:14:00 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll 2007-10-04 16:14:00 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll 2007-10-04 16:14:00 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll 2007-10-04 16:14:00 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll 2007-10-04 16:14:00 3,629,056 ----a-w C:\WINDOWS\system32\nvvitvsr.dll 2007-10-04 16:14:00 3,551,232 ----a-w C:\WINDOWS\system32\nvvitvs.dll 2007-10-04 16:14:00 3,334,144 ----a-w C:\WINDOWS\system32\nvgames.dll 2007-10-04 16:14:00 3,166,208 ----a-w C:\WINDOWS\system32\nvgamesr.dll 2007-10-04 16:14:00 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll 2007-10-04 16:14:00 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll 2007-10-04 16:14:00 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll 2007-10-04 16:14:00 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll 2007-10-04 16:14:00 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll 2007-10-04 16:14:00 290,816 ----a-w C:\WINDOWS\system32\nvwrsth.dll 2007-10-04 16:14:00 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll 2007-10-04 16:14:00 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll 2007-10-04 16:14:00 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll 2007-10-04 16:14:00 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll 2007-10-04 16:14:00 282,624 ----a-w C:\WINDOWS\system32\nvrsfr.dll 2007-10-04 16:14:00 282,624 ----a-w C:\WINDOWS\system32\nvrses.dll 2007-10-04 16:14:00 282,624 ----a-w C:\WINDOWS\system32\nvrsel.dll 2007-10-04 16:14:00 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll 2007-10-04 16:14:00 278,528 ----a-w C:\WINDOWS\system32\nvrsit.dll 2007-10-04 16:14:00 278,528 ----a-w C:\WINDOWS\system32\nvrsde.dll 2007-10-04 16:14:00 274,432 ----a-w C:\WINDOWS\system32\nvrspt.dll 2007-10-04 16:14:00 274,432 ----a-w C:\WINDOWS\system32\nvrsnl.dll 2007-10-04 16:14:00 274,432 ----a-w C:\WINDOWS\system32\nvrsesm.dll 2007-10-04 16:14:00 270,336 ----a-w C:\WINDOWS\system32\nvrsru.dll 2007-10-04 16:14:00 266,240 ----a-w C:\WINDOWS\system32\nvrsptb.dll 2007-10-04 16:14:00 266,240 ----a-w C:\WINDOWS\system32\nvrsja.dll 2007-10-04 16:14:00 258,048 ----a-w C:\WINDOWS\system32\nvrstr.dll 2007-10-04 16:14:00 258,048 ----a-w C:\WINDOWS\system32\nvrssl.dll 2007-10-04 16:14:00 258,048 ----a-w C:\WINDOWS\system32\nvrssk.dll 2007-10-04 16:14:00 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll 2007-10-04 16:14:00 258,048 ----a-w C:\WINDOWS\system32\nvrshu.dll 2007-10-04 16:14:00 253,952 ----a-w C:\WINDOWS\system32\nvrsth.dll 2007-10-04 16:14:00 253,952 ----a-w C:\WINDOWS\system32\nvrssv.dll 2007-10-04 16:14:00 253,952 ----a-w C:\WINDOWS\system32\nvrspl.dll 2007-10-04 16:14:00 253,952 ----a-w C:\WINDOWS\system32\nvrsno.dll 2007-10-04 16:14:00 253,952 ----a-w C:\WINDOWS\system32\nvrsda.dll 2007-10-04 16:14:00 249,856 ----a-w C:\WINDOWS\system32\nvrsfi.dll 2007-10-04 16:14:00 249,856 ----a-w C:\WINDOWS\system32\nvrscs.dll 2007-10-04 16:14:00 245,760 ----a-w C:\WINDOWS\system32\nvrseng.dll 2007-10-04 16:14:00 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll 2007-10-04 16:14:00 225,280 ----a-w C:\WINDOWS\system32\nvrszhc.dll 2007-10-04 16:14:00 212,992 ----a-w C:\WINDOWS\system32\nvwrsja.dll 2007-10-04 16:14:00 2,854,912 ----a-w C:\WINDOWS\system32\nvmoblsr.dll 2007-10-04 16:14:00 2,441,216 ----a-w C:\WINDOWS\system32\nvwssr.dll 2007-10-04 16:14:00 2,371,584 ----a-w C:\WINDOWS\system32\nvwss.dll 2007-10-04 16:14:00 196,608 ----a-w C:\WINDOWS\system32\nvwrsko.dll 2007-10-04 16:14:00 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll 2007-10-04 16:14:00 167,936 ----a-w C:\WINDOWS\system32\nvwrszht.dll 2007-10-04 16:14:00 163,840 ----a-w C:\WINDOWS\system32\nvwrszhc.dll 2007-10-04 16:14:00 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe 2007-10-04 16:14:00 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe 2007-10-04 16:14:00 126,976 ----a-w C:\WINDOWS\system32\nvrszht.dll 2007-10-04 16:14:00 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll 2007-10-04 16:14:00 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe 2007-10-04 16:14:00 1,478,656 ----a-w C:\WINDOWS\system32\nview.dll 2007-10-04 16:14:00 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe 2007-10-04 16:14:00 1,150,976 ----a-w C:\WINDOWS\system32\nvmobls.dll 2007-10-04 16:14:00 1,073,152 ----a-w C:\WINDOWS\system32\nvcpluir.dll 2007-10-04 16:14:00 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll 2007-10-03 15:38:00 -------- d-----w C:\Program Files\SopCast 2007-10-02 19:02:24 -------- d-----w C:\Program Files\TVUPlayer 2007-10-02 18:11:21 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\ppStream 2007-10-02 17:54:57 -------- d-----w C:\Program Files\Common Files\Real 2007-10-02 17:54:57 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\Real 2007-10-02 17:48:52 -------- d-----w C:\Program Files\Real 2007-10-02 17:18:03 -------- d-----w C:\Program Files\PPMate 2007-10-02 17:04:31 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\PPMate 2007-10-02 17:04:28 -------- d-----w C:\Program Files\Common Files\Synacast 2007-10-02 09:04:05 -------- d-----w C:\Program Files\AC3Filter 2007-09-22 19:09:45 -------- d-----w C:\Program Files\QuickTime 2007-09-22 14:19:14 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\Teleca 2007-09-22 14:16:20 -------- d-----w C:\DOCUME~1\Admin\DANEAP~1\Sony Ericsson 2007-09-15 17:14:49 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2007-09-06 10:09:49 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-09-06 10:00:07 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr 2007-09-02 12:52:45 1,876 -c–a-w C:\WINDOWS\mozver.dat 2007-08-26 11:30:10 23 --sha-w C:\WINDOWS\system32\cedcdcb5_r.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 00:56] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 02:43] {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2006-10-17 15:04] {CC59E0F9-7E43-44FA-9FAA-8377850BF205}=C:\Program Files\Free Download Manager\iefdm2.dll [2007-08-21 22:44] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 11:06] “HP Component Manager”=“C:\Program Files\HP\hpcoretech\hpcmpmgr.exe” [2003-12-22 07:38] “Logitech Hardware Abstraction Layer”=“KHALMNPR.EXE” [] “ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe” [2004-06-16 05:03] “ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [2004-06-16 05:03] “Kernel and Hardware Abstraction Layer”=“KHALMNPR.EXE” [] “nwiz”=“nwiz.exe” [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Dzieńdobry!”=“C:\Program Files\VSD Software\Dzieńdobry!\dziendobry.exe” [] “Free Uploader Oe Integration”=“C:\Program Files\Free Download Manager\FUM\fumoei.exe” [2007-06-10 18:02] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Spyware Doctor”= [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2006-09-28 15:13] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “appinit_dlls”= [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs* Contents of the ‘Scheduled Tasks’ folder 2007-11-18 18:04:09 C:\WINDOWS\tasks\AppleSoftwareUpdate.job ******************************************************************** catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-20 23:10:16 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ******************************************************************** Completion time: 2007-11-20 23:10:46 C:\ComboFix-quarantined-files.txt … 2007-11-20 23:10 — E O F —