ComboFix 07-06-13.3 - BĄd CScript: Dost©p do Hosta skrypt˘w systemu Windows jest wyĄczony na tym komputerze. Skontaktuj si© z administratorem, aby uzyska† szczeg˘owe informacje. “Leszek” - 2007-06-22 14:46:08 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2007-05-22 to 2007-06-22 ))))))))))))))))))))))))))))))) 2007-06-21 23:31 2007-06-21 22:41 2007-06-18 23:03 2007-06-18 14:53 52,736 --a------ C:\WINDOWS\ipuninst.exe 2007-06-18 12:08 2007-06-17 01:50 2007-06-17 01:22 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-17 00:39 786,432 --ah----- C:\DOCUME~1\ADMINI~1.000\NTUSER.DAT 2007-06-17 00:39 2007-06-17 00:39 2007-06-17 00:39 2007-06-17 00:39 2007-06-17 00:39 2007-06-17 00:39 2007-06-17 00:39 2007-06-16 13:32 524,288 --ah----- C:\DOCUME~1\ADMINI~1.CAS\NTUSER.DAT 2007-06-16 13:32 2007-06-16 13:32 2007-06-16 13:32 2007-06-16 13:32 2007-06-16 13:32 2007-06-16 13:32 2007-06-16 13:32 2007-06-16 11:54 2007-06-13 14:04 52 --a------ C:\WINDOWS\system\ACD2.CMD 2007-06-13 14:04 52 --a------ C:\WINDOWS\system\ACD.CMD 2007-06-11 21:33 24,626 --a------ C:\WINDOWS\system32\scrrntr.dll 2007-06-11 21:33 20,480 --a------ C:\WINDOWS\system32\PAC.EXE 2007-06-11 21:33 180,224 --a------ C:\WINDOWS\system32\Ijl11.dll 2007-06-02 13:22 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys 2007-06-02 13:22 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys 2007-06-02 13:22 2007-06-02 13:08 2007-06-01 15:49 2007-06-01 15:49 2007-05-25 22:37 2007-05-25 22:32 2007-05-25 22:32 2007-05-25 22:30 2007-05-25 22:28 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll 2007-05-25 22:28 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe 2007-05-25 22:28 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe 2007-05-25 22:28 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll 2007-05-25 22:28 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-05-25 22:28 282,680 --a------ C:\WINDOWS\system32\HPZidr12.dll 2007-05-25 22:28 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll 2007-05-25 22:27 2007-05-25 22:22 77,824 -ra------ C:\WINDOWS\system32\hpzids01.dll 2007-05-25 22:22 48,640 --a------ C:\WINDOWS\system32\hpzll4pi.dll 2007-05-25 22:22 14,916 --------- C:\WINDOWS\hphmdl12.dat 2007-05-25 22:22 126,804 --a------ C:\WINDOWS\HPHins12.dat 2007-05-22 15:52 376,832 —hs---- C:\WINDOWS\system32\activexdebugger32.exe (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-21 09:02:15 -------- d-----w C:\DOCUME~1\Leszek\DANEAP~1\foobar2000 2007-06-20 18:41:48 -------- d-----w C:\Program Files\StrongDC++ 2007-06-18 09:29:52 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-06-17 09:34:29 -------- d-----w C:\Program Files\AIDA32 - Enterprise System Information 2007-06-16 23:28:49 -------- d-----w C:\Program Files\freeCommander2006 2007-06-15 00:39:15 -------- d-----w C:\DOCUME~1\Leszek\DANEAP~1\Tlen.pl 2007-06-12 20:07:22 1,080 ----a-w C:\WINDOWS\AUTOLNCH.REG 2007-06-03 09:50:29 -------- d-----w C:\Program Files\Opera 2007-05-25 20:29:42 -------- d-----w C:\Program Files\Hewlett-Packard 2007-05-21 13:42:35 -------- d-----w C:\Program Files\TweakRAM 2007-05-20 17:20:02 -------- d-----w C:\Program Files\Gadu-Gadu 2007-05-17 16:23:42 -------- d-----w C:\Program Files\IrfanView 2007-05-17 11:31:00 -------- d-----w C:\Program Files\Ashampoo 2007-05-15 11:49:51 -------- d-----w C:\Program Files\iViVo 2007-05-14 21:35:30 -------- d-----w C:\DOCUME~1\Leszek\DANEAP~1\ivivo 2007-05-11 08:13:49 -------- d-----w C:\Program Files\ffdshow 2007-05-09 09:49:18 -------- d-----w C:\Program Files\Tlen.pl 2007-05-03 07:56:58 -------- d-----w C:\Program Files\Google 2007-05-03 07:56:57 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-05-02 21:37:02 -------- d-----w C:\Program Files\SiSoftware 2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr 2007-04-27 10:26:17 -------- d-----w C:\DOCUME~1\Leszek\DANEAP~1\Help 2007-04-21 19:33:34 205 ----a-w C:\WINDOWS\system32\lsprst7.dll 2007-04-21 19:26:05 1,025 ----a-w C:\WINDOWS\system32\sysprs7.dll 2007-04-21 19:25:25 1,024 ----a-w C:\WINDOWS\system32\clauth2.dll 2007-04-21 19:25:25 1,024 ----a-w C:\WINDOWS\system32\clauth1.dll 2007-04-21 19:25:25 0 ----a-w C:\WINDOWS\system32\ssprs.dll 2007-04-21 19:25:25 0 ----a-w C:\WINDOWS\system32\serauth2.dll 2007-04-21 19:25:25 0 ----a-w C:\WINDOWS\system32\serauth1.dll 2007-04-21 19:25:25 0 ----a-w C:\WINDOWS\system32\nsprs.dll 2007-04-19 12:14:14 208,896 ----a-w C:\WINDOWS\system32\nvunrm.exe 2007-04-19 11:26:00 888,832 ----a-w C:\WINDOWS\system32\nvmobls.dll 2007-04-19 11:26:00 86,016 ----a-w C:\WINDOWS\system32\nvmctray.dll 2007-04-19 11:26:00 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll 2007-04-19 11:26:00 794,624 ----a-w C:\WINDOWS\system32\nvcplui.exe 2007-04-19 11:26:00 7,700,480 ----a-w C:\WINDOWS\system32\nvcpl.dll 2007-04-19 11:26:00 581,632 ----a-w C:\WINDOWS\system32\nvhwvid.dll 2007-04-19 11:26:00 5,644,288 ----a-w C:\WINDOWS\system32\nvoglnt.dll 2007-04-19 11:26:00 5,619,712 ----a-w C:\WINDOWS\system32\nvdisps.dll 2007-04-19 11:26:00 5,255,168 ----a-w C:\WINDOWS\system32\nvdispsr.dll 2007-04-19 11:26:00 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll 2007-04-19 11:26:00 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll 2007-04-19 11:26:00 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2007-04-19 11:26:00 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe 2007-04-19 11:26:00 425,984 ----a-w C:\WINDOWS\system32\keystone.exe 2007-04-19 11:26:00 4,543,616 ----a-w C:\WINDOWS\system32\nv4_disp.dll 2007-04-19 11:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcodins.dll 2007-04-19 11:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcod.dll 2007-04-19 11:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll 2007-04-19 11:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll 2007-04-19 11:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll 2007-04-19 11:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrshe.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrsar.dll 2007-04-19 11:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll 2007-04-19 11:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll 2007-04-19 11:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll 2007-04-19 11:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll 2007-04-19 11:26:00 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll 2007-04-19 11:26:00 311,296 ----a-w C:\WINDOWS\system32\nvexpbar.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll 2007-04-19 11:26:00 3,203,072 ----a-w C:\WINDOWS\system32\nvgamesr.dll 2007-04-19 11:26:00 3,035,136 ----a-w C:\WINDOWS\system32\nvgames.dll 2007-04-19 11:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll 2007-04-19 11:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll 2007-04-19 11:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll 2007-04-19 11:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll 2007-04-19 11:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll 2007-04-19 11:26:00 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll 2007-04-19 11:26:00 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll 2007-04-19 11:26:00 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll 2007-04-19 11:26:00 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll 2007-04-19 11:26:00 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll 2007-04-19 11:26:00 278,528 ----a-w C:\WINDOWS\system32\nvrsfr.dll 2007-04-19 11:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrsit.dll 2007-04-19 11:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrses.dll 2007-04-19 11:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrsel.dll 2007-04-19 11:26:00 270,336 ----a-w C:\WINDOWS\system32\nvrsde.dll 2007-04-19 11:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrspt.dll 2007-04-19 11:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrsnl.dll 2007-04-19 11:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrsesm.dll 2007-04-19 11:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsru.dll 2007-04-19 11:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsptb.dll 2007-04-19 11:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsja.dll 2007-04-19 11:26:00 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll 2007-04-19 11:26:00 253,952 ----a-w C:\WINDOWS\system32\nvrshu.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrstr.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrssl.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrssk.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrspl.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2007-06-15 10:41] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [2004-12-22 11:09 C:\WINDOWS\SOUNDMAN.EXE] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-04-30 17:42] “nwiz”=“nwiz.exe” [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe] “WheelMouse”=“C:\Program Files\A4Tech\Mouse\Amoumain.exe” [2006-05-14 10:37] “NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2007-04-19 13:26] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Komunikator”=“C:\Program Files\Tlen.pl\tlen.exe” [2007-02-12 12:01] “SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe” [2007-06-15 10:41] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “ClearRecentDocsOnExit”=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] “C:\Program Files\D-Tools\daemon.exe” -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{1f5bc5b8-127c-11dc-a9f1-0014858b370e}] Auto\command- I:\activexdebugger32.exe f AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe f explore\Command- I:\activexdebugger32.exe f open\Command- I:\activexdebugger32.exe f [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{4a130ec2-9375-11db-99e8-0014858b370e}] Auto\command- I:\activexdebugger32.exe f AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe f explore\Command- I:\activexdebugger32.exe f open\Command- I:\activexdebugger32.exe f [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{78d60be4-e2a0-11db-9ac3-0014858b370e}] AutoRun\command- J:\LaunchU3.exe Contents of the ‘Scheduled Tasks’ folder 2007-06-21 21:06:59 C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job 2007-06-21 21:06:59 C:\WINDOWS\tasks\Uniblue SpyEraser.job ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-22 14:48:42 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-22 14:50:19 — E O F —