ComboFix 08-04-20.5 - Agnieszka 2008-04-29 16:13:06.9 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.1.1250.1.1045.18.187 [GMT 2:00] Running from: C:\Documents and Settings\Agnieszka\Moje dokumenty\ComboFix.exe Command switches used :: C:\Documents and Settings\Agnieszka\Pulpit\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED FILE :: C:\WINDOWS\System32\fanfkmur.dll C:\WINDOWS\System32\mdm.exe C:\WINDOWS\System32\veiblyyw.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\cookies.ini C:\WINDOWS\pskt.ini C:\WINDOWS\system32\a.exe C:\WINDOWS\system32\cbXQkIxV.dll C:\WINDOWS\System32\fanfkmur.dll C:\WINDOWS\system32\hgGawwUN.dll C:\WINDOWS\system32\hgGwVMFV.dll C:\WINDOWS\System32\mdm.exe C:\WINDOWS\system32\NnpYcMoq.ini C:\WINDOWS\system32\NnpYcMoq.ini2 C:\WINDOWS\system32\pmnmnklm.dll C:\WINDOWS\system32\qoMcYpnN.dll C:\WINDOWS\System32\veiblyyw.dll C:\WINDOWS\system32\wyylbiev.ini . ((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-29 ))))))))))))))))))))))))))))))) . 2008-04-29 09:47 . 2008-04-29 10:01 109,747 --a------ C:\WINDOWS\BM7befb606.xml 2008-04-27 10:37 . 2008-04-27 10:37 2008-04-27 10:37 . 2005-04-28 21:35 1,190,400 --a------ C:\WINDOWS\system32\ole32.dll 2008-04-27 10:37 . 2005-04-28 21:35 1,190,400 --a–c— C:\WINDOWS\system32\dllcache\ole32.dll 2008-04-27 10:37 . 2004-03-06 04:21 535,552 --a------ C:\WINDOWS\system32\rpcrt4.dll 2008-04-27 10:37 . 2004-03-06 04:21 535,552 --a–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll 2008-04-27 10:37 . 2005-04-28 21:35 275,456 --a------ C:\WINDOWS\system32\rpcss.dll 2008-04-27 10:37 . 2005-04-28 21:35 275,456 --a–c— C:\WINDOWS\system32\dllcache\rpcss.dll 2008-04-27 10:37 . 2005-04-28 21:35 69,120 --a------ C:\WINDOWS\system32\olecli32.dll 2008-03-30 14:17 . 2008-04-27 10:37 2008-03-30 14:17 . 2002-08-29 01:48 14,208 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2008-03-30 14:17 . 2002-08-29 01:48 14,208 --a–c— C:\WINDOWS\system32\dllcache\usbscan.sys 2008-03-29 20:11 . 2008-03-29 20:11 2008-03-29 18:43 . 2008-03-29 18:43 2008-03-29 18:43 . 2008-03-29 18:45 2008-03-29 18:43 . 2008-03-29 18:43 2008-03-29 18:43 . 2004-12-29 16:59 24,576 -r------- C:\WINDOWS\system32\RSRC32.DLL 2008-03-29 18:43 . 2004-12-29 16:59 8,944 -ra------ C:\WINDOWS\system32\drivers\OLD41.tmp 2008-03-29 18:43 . 2004-12-29 16:59 1,312 -r------- C:\WINDOWS\system32\RSRC16.DLL . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-29 08:16 --------- d-----w C:\Program Files\Gadu-Gadu 2008-04-25 08:48 --------- d-----w C:\Program Files\Capture-A-ScreenShot 2008-04-04 19:28 --------- d-----w C:\Program Files\Ganymede 2008-03-29 16:43 --------- d–h--w C:\Program Files\InstallShield Installation Information 2008-03-20 13:17 --------- d-----w C:\Documents and Settings\Agnieszka\Dane aplikacji\GanymedeNet 2008-03-19 17:54 --------- d-----w C:\Program Files\SopCast 2008-03-19 13:50 --------- d-----w C:\Documents and Settings\Agnieszka\Dane aplikacji\BearShare 2008-03-19 13:31 --------- d-----w C:\Documents and Settings\Agnieszka\Dane aplikacji\Skype 2008-03-19 10:20 --------- d-----w C:\Documents and Settings\Agnieszka\Dane aplikacji\skypePM 2008-02-12 19:57 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat 2006-08-28 15:21 36 ----a-w C:\Documents and Settings\Agnieszka\klextlock.dat . ((((((((((((((((((((((((((((( snapshot@2008-04-21_17.34.22,73 ))))))))))))))))))))))))))))))))))))))))) . + 2005-04-28 19:32:51 1,284,608 ----a-w C:\WINDOWS$hf_mig$\KB894391\SP2GDR\ole32.dll + 2005-04-28 19:32:51 75,264 ----a-w C:\WINDOWS$hf_mig$\KB894391\SP2GDR\olecli32.dll + 2005-04-28 19:32:51 37,888 ----a-w C:\WINDOWS$hf_mig$\KB894391\SP2GDR\olecnv32.dll + 2005-04-28 19:32:51 395,776 ----a-w C:\WINDOWS$hf_mig$\KB894391\SP2GDR\rpcss.dll + 2005-04-28 10:38:10 1,286,144 ----a-w C:\WINDOWS$hf_mig$\KB894391\SP2QFE\ole32.dll + 2005-04-28 19:38:08 75,264 ----a-w C:\WINDOWS$hf_mig$\KB894391\SP2QFE\olecli32.dll + 2005-04-28 19:38:08 37,376 ----a-w C:\WINDOWS$hf_mig$\KB894391\SP2QFE\olecnv32.dll + 2005-04-28 19:38:08 396,288 ----a-w C:\WINDOWS$hf_mig$\KB894391\SP2QFE\rpcss.dll + 2005-02-25 03:36:06 16,096 ----a-w C:\WINDOWS$hf_mig$\KB894391\spmsg.dll + 2005-02-25 03:36:06 212,704 ----a-w C:\WINDOWS$hf_mig$\KB894391\spuninst.exe + 2005-02-25 03:36:06 22,240 ----a-w C:\WINDOWS$hf_mig$\KB894391\update\spcustom.dll + 2005-02-25 03:36:06 725,728 ----a-w C:\WINDOWS$hf_mig$\KB894391\update\update.exe + 2005-02-25 03:36:07 387,296 ----a-w C:\WINDOWS$hf_mig$\KB894391\update\updspapi.dll - 2008-04-21 15:22:17 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-04-29 14:15:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2007-12-20 14:27:10 249,856 ----a-w C:\WINDOWS\Downloaded Program Files\UGDCPL_0001_N122M2012NetInstaller.exe - 2007-03-13 08:57:10 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE + 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE + 2007-07-30 17:19:20 92,504 ------w C:\WINDOWS\SoftwareDistribution\WebSetup\cdm.dll + 2007-07-30 17:19:36 549,720 ------w C:\WINDOWS\SoftwareDistribution\WebSetup\wuapi.dll + 2007-07-30 17:19:16 53,080 ------w C:\WINDOWS\SoftwareDistribution\WebSetup\wuauclt.exe + 2007-07-30 17:19:42 1,712,984 ------w C:\WINDOWS\SoftwareDistribution\WebSetup\wuaueng.dll + 2007-07-30 17:19:32 325,976 ------w C:\WINDOWS\SoftwareDistribution\WebSetup\wucltui.dll + 2007-07-30 17:18:40 33,624 ------w C:\WINDOWS\SoftwareDistribution\WebSetup\wups.dll + 2007-07-30 17:19:12 43,352 ------w C:\WINDOWS\SoftwareDistribution\WebSetup\wups2.dll - 2008-04-21 15:22:18 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2008-04-29 13:54:52 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - 2008-04-21 15:22:18 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat + 2008-04-29 13:54:52 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat + 2008-04-23 15:34:22 7,854 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\9JK3MEXP\mixit[3].exe - 2008-04-21 15:22:18 49,152 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat + 2008-04-29 13:54:52 49,152 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat + 2008-04-21 18:59:33 40,704 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\VTF1O4V2\mixit[6].exe + 2008-04-24 11:46:27 7,854 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\VTF1O4V2\mixit[7].exe + 2008-04-26 09:16:29 3,953 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\VTF1O4V2\mixit[8].exe + 2008-04-26 14:24:34 7,854 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\VTF1O4V2\mixit[9].exe + 2008-04-22 06:58:57 40,704 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\VXOISAQT\mixit[1].exe + 2008-04-22 08:40:27 3,953 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\VXOISAQT\mixit[2].exe + 2008-04-22 14:12:48 11,755 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\VXOISAQT\mixit[3].exe + 2008-04-26 07:35:03 11,755 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\VXOISAQT\mixit[4].exe - 2001-10-26 17:29:40 69,120 -c–a-w C:\WINDOWS\system32\dllcache\olecli32.dll + 2005-04-28 19:35:21 69,120 -c–a-w C:\WINDOWS\system32\dllcache\olecli32.dll - 2001-10-26 17:29:40 34,304 -c–a-w C:\WINDOWS\system32\dllcache\olecnv32.dll + 2005-04-28 19:35:21 35,328 -c–a-w C:\WINDOWS\system32\dllcache\olecnv32.dll - 2001-10-26 17:29:40 34,304 ----a-w C:\WINDOWS\system32\olecnv32.dll + 2005-04-28 19:35:21 35,328 ----a-w C:\WINDOWS\system32\olecnv32.dll - 2004-06-24 16:16:30 8,704 ------w C:\WINDOWS\system32\spmsg.dll + 2005-02-25 03:36:06 16,096 ------w C:\WINDOWS\system32\spmsg.dll + 2007-07-30 17:19:46 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll + 2008-04-29 14:15:52 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_464.dat . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-05-10 16:36 2111176] “IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe” [] “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2008-04-05 19:50 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “nwiz”=“nwiz.exe” [2004-07-15 12:42 843776 C:\WINDOWS\system32\nwiz.exe] “NvMediaCenter”=“C:\WINDOWS\System32\NvMcTray.dll” [2004-07-15 12:42 81920] “HP Component Manager”=“C:\Program Files\HP\hpcoretech\hpcmpmgr.exe” [2003-12-22 09:38 241664] “HPDJ Taskbar Utility”=“C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe” [2004-03-04 16:46 172032] “HP Software Update”=“C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe” [2004-02-18 19:55 49152] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2004-12-20 20:41 33792] “PhiBtn”=“C:\WINDOWS\System32\drivers\PhiBtn.exe” [] “Traymin900”=“C:\WINDOWS\System32\drivers\Tray900.exe” [] “msnappau”=“C:\Program Files\MSN Apps\Updater\01.02.3000.1001\pl-pl\msnappau.exe” [2004-08-13 17:41 86016] “NBKeyScan”=“C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe” [] “Google Desktop Search”=“C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” [2008-01-16 13:00 1838592] “BM7befb606”=“C:\WINDOWS\System32\fanfkmur.dll” [] “NvCplDaemon”=“C:\WINDOWS\System32\NvCpl.dll” [2004-07-15 12:42 4112384] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “Windows Networking Monitoring”=“C:\WINDOWS\System32\mdm.exe” [] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Enable Labtec Wireless Desktop.lnk - C:\Program Files\Labtec Wireless Desktop\MagicKey.exe [2007-11-24 16:41:27 258048] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56 65588] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgGawwUN] hgGawwUN.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “AppInit_DLLs”=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] “msacm.scg726”= scg726.acm “msacm.alf2cd”= alf2cd.acm “msacm.ac3acm”= AC3ACM.acm “vidc.dvsd”= mcdvd_32.dll “MSACM.MI-SC4”= MI-SC4.acm [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] --a------ 2002-08-02 20:00 46592 C:\WINDOWS\SOUNDMAN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] --a------ 2004-12-20 20:41 33792 C:\Program Files\Winamp\winampa.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “wuauserv”=2 (0x2) “Messenger”=2 (0x2) “srservice”=2 (0x2) “SharedAccess”=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] “UpdatesDisableNotify”=dword:00000001 “AntiVirusDisableNotify”=dword:00000001 “AntiVirusOverride”=dword:00000001 “FirewallOverride”=dword:00000001 R1 aswSP;avast! Self Protection;C:\WINDOWS\System32\drivers\aswSP.sys [2008-03-29 19:31] R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\System32\drivers\kbfilter.sys [2003-03-27 14:55] R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\System32\drivers\moufiltr.sys [2004-10-11 16:28] R1 MUsbFltr;WayTechUSBFilterDriver;C:\WINDOWS\System32\drivers\MUsbFltr.sys [2005-12-21 22:32] R1 UsbFltr;WayTechUSBFilterDriver;C:\WINDOWS\System32\drivers\UsbFltr.sys [2005-12-21 22:31] R3 camvid40;Philips SPC 900NC PC Camera;C:\WINDOWS\System32\DRIVERS\camdrv41.sys [2005-08-25 18:28] . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-29 16:16:14 Windows 5.1.2600 Dodatek Service Pack. 1 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Labtec Wireless Desktop\MulMouse.exe C:\Program Files\Labtec Wireless Desktop\OSD.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe . ************************************************************************** . Completion time: 2008-04-29 16:18:53 - machine was rebooted ComboFix-quarantined-files.txt 2008-04-29 14:18:49 ComboFix2.txt 2008-04-21 15:34:42 ComboFix3.txt 2007-09-25 16:42:49 Pre-Run: 8,961,290,240 bajtów wolnych Post-Run: 8,969,969,664 bajt˘w wolnych 211