“ja” - 2007-05-11 15:25:21 Dodatek Service Pack. 1 ComboFix 07-05.09.V - Running from: “C:\Program Files\Mozilla Thunderbird” ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-11 )))))))))))))))))))))))))))))))))) 2007-05-10 21:45 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-05-10 19:44 2007-05-09 21:30 9,856 --a------ C:\WINDOWS\system32\drivers\gameenum.sys 2007-05-09 21:30 57,856 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-05-09 21:30 134,272 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-05-09 21:29 10,240 --a------ C:\WINDOWS\CTDCRES.DLL 2007-05-09 21:26 2007-05-09 21:26 2007-05-09 21:26 2007-05-09 21:20 75,264 --a------ C:\WINDOWS\system32\MACDec.dll 2007-05-09 21:20 61,440 --a------ C:\WINDOWS\system32\libfaac.dll 2007-05-09 21:20 45,568 --a------ C:\WINDOWS\system32\huffyuv.dll 2007-05-09 21:20 446,464 --a------ C:\WINDOWS\system32\vp31vfw.dll 2007-05-09 21:20 438,272 --a------ C:\WINDOWS\system32\vp6vfw.dll 2007-05-09 21:20 421,888 --a------ C:\WINDOWS\system32\OpenQuicktimeLib.dll 2007-05-09 21:20 286,720 --a------ C:\WINDOWS\system32\3ivxVfWCodec.dll 2007-05-09 21:20 245,408 --a------ C:\WINDOWS\system32\unicows.dll 2007-05-09 21:20 1,024,000 --a------ C:\WINDOWS\system32\3ivx.dll 2007-05-09 16:14 8,192 --a------ C:\WINDOWS\system32\nap.exe 2007-05-09 16:08 0 --a------ C:\WINDOWS\system32\xkz.exe 2007-05-09 16:03 4,096 --a------ C:\WINDOWS\system32\ltb.exe 2007-05-09 15:57 4,096 --a------ C:\WINDOWS\system32\vsv.exe 2007-05-09 15:38 8,192 --a------ C:\WINDOWS\system32\mdc.exe 2007-05-09 14:00 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-05-09 14:00 2007-05-09 14:00 2007-05-09 14:00 2007-05-09 01:57 2007-05-08 22:17 0 --a------ C:\WINDOWS\system32\SBRC.dat 2007-05-08 22:17 0 --a------ C:\WINDOWS\system32\SBFC.dat 2007-05-08 21:51 2007-05-08 20:00 2007-05-08 19:04 2007-05-08 18:38 2007-05-08 18:18 2007-05-08 14:43 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-05-08 14:43 2007-05-08 14:43 2007-05-08 14:43 2007-05-08 14:43 2007-05-08 14:43 2007-05-08 14:43 2007-05-08 14:43 2007-05-04 17:44 774,656 --a------ C:\WINDOWS\system32\mmc.exe 2007-05-04 17:26 2007-05-04 17:01 2007-05-04 16:56 73,728 --a------ C:\WINDOWS\system32\dpl100.dll 2007-05-04 16:56 679,936 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-05-04 16:56 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-05-04 16:56 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll 2007-05-04 16:56 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll 2007-05-04 16:56 196,608 --a------ C:\WINDOWS\system32\dtu100.dll 2007-05-04 16:56 155,648 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-05-04 16:56 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll 2007-05-04 16:55 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-05-04 16:55 2007-05-02 18:18 2007-04-29 23:38 2007-04-29 23:31 77,824 --a------ C:\WINDOWS\system32\mplaw7.dll 2007-04-29 23:31 77,824 --a------ C:\WINDOWS\system32\mplaa6.dll 2007-04-29 23:31 65,536 --a------ C:\WINDOWS\system32\mplapx.dll 2007-04-29 23:31 65,536 --a------ C:\WINDOWS\system32\mplam6.dll 2007-04-29 23:31 1,650,688 --a------ C:\WINDOWS\system32\mplva6.dll 2007-04-29 23:31 1,581,056 --a------ C:\WINDOWS\system32\mplvw7.dll 2007-04-29 23:31 1,552,384 --a------ C:\WINDOWS\system32\mplvm6.dll 2007-04-29 23:31 1,122,304 --a------ C:\WINDOWS\system32\mplvpx.dll 2007-04-29 20:28 2007-04-28 18:18 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys 2007-04-28 18:18 298,104 --a------ C:\WINDOWS\system32\imon.dll 2007-04-28 18:18 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys 2007-04-28 17:47 2007-04-27 16:30 2007-04-27 15:39 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2007-04-27 15:16 2007-04-27 12:26 2007-04-27 12:20 2007-04-26 14:32 2007-04-25 19:34 2007-04-25 19:02 2007-04-25 18:15 2007-04-25 18:14 2007-04-23 23:08 2007-04-23 23:07 2007-04-23 23:07 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-05-11 13:24:26 -------- d-----w C:\Program Files\Mozilla Thunderbird 2007-05-09 19:30:52 -------- d-----w C:\Program Files\Creative 2007-05-09 19:29:58 -------- d-----w C:\DOCUME~1\ja\DANEAP~1\Creative 2007-04-27 09:03:00 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-04-23 21:08:13 4,908 ----a-w C:\WINDOWS\mozver.dat 2007-04-21 11:18:00 -------- d-----w C:\Program Files\Soulseek 2007-04-10 08:45:58 -------- d-----w C:\Program Files\FxTrading 2007-04-01 22:41:11 -------- d-----w C:\Program Files\KodyPocztowe 2007-04-01 22:40:29 74,230 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-04-01 22:40:29 448,004 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-04-01 20:16:32 -------- d-----w C:\DOCUME~1\ja\DANEAP~1\AdobeUM 2007-04-01 20:16:32 -------- d-----w C:\DOCUME~1\ja\DANEAP~1\AdobeAUM 2007-04-01 17:58:28 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll 2007-03-30 12:22:11 -------- d-----w C:\Program Files\activePDF 2007-03-30 12:19:34 -------- d-----w C:\Program Files\pdf995 2007-03-30 12:16:49 51,716 ----a-w C:\WINDOWS\system32\pdf995mon.dll 2007-03-30 12:16:49 122,880 ----a-w C:\WINDOWS\system32\pdfmona.dll 2007-03-30 12:10:45 -------- d-----w C:\Program Files\PDF4Free 2007-03-30 10:43:17 -------- d–h--w C:\Program Files\WindowsUpdate 2007-03-27 12:56:59 -------- d-----w C:\DOCUME~1\ja\DANEAP~1\PTC 2007-03-27 12:54:50 -------- d-----w C:\Program Files\proeWildfire 2.0 2007-03-20 19:59:02 -------- d-----w C:\Program Files\Pando Networks 2007-03-19 11:29:54 -------- d-----w C:\Program Files\Ahead 2007-03-19 11:29:53 -------- d-----w C:\Program Files\Common Files\Ahead 2007-03-15 13:49:28 -------- d-----w C:\DOCUME~1\ja\DANEAP~1\GanymedeNet 2007-03-15 13:19:18 -------- d-----w C:\Program Files\Ganymede 2007-03-15 10:23:16 497,496 ----a-w C:\WINDOWS\system32\XceedZip.dll 2007-03-15 10:19:58 526,184 ----a-w C:\WINDOWS\system32\XceedCry.dll 2007-03-15 10:00:36 466,432 ----a-w C:\WINDOWS\system32\SkanerOnline.dll 2007-03-15 09:04:24 -------- d-----w C:\Program Files\Gadu-Gadu 2007-03-14 16:54:07 -------- d-----w C:\Program Files\Microsoft.NET 2007-03-14 16:37:26 -------- d-----w C:\Program Files\D-Tools 2007-03-14 11:10:53 -------- d-----w C:\DOCUME~1\ja\DANEAP~1\Talkback 2007-03-14 11:10:47 -------- d-----w C:\DOCUME~1\ja\DANEAP~1\Thunderbird 2007-03-07 15:13:38 81 ----a-w C:\CTX.DAT 2007-03-07 15:08:31 -------- d-----w C:\Program Files\MultiResource Client 2007-03-07 15:08:26 737,280 ----a-w C:\WINDOWS\iun6002.exe 2007-03-06 23:05:06 -------- d-----w C:\DOCUME~1\ja\DANEAP~1\Help 2007-03-06 21:05:36 -------- d-----w C:\Program Files\Common Files\DirectX 2007-03-06 20:57:05 -------- d-----w C:\Program Files\SCi Games 2007-03-06 17:14:35 -------- d-----w C:\Program Files\Python 2007-03-05 12:44:48 4 ----a-w C:\WINDOWS\system32\proc1795523372.bin 2007-03-01 18:34:58 0 ----a-w C:\WINDOWS\nsreg.dat 2007-03-01 11:14:50 0 --sha-r C:\MSDOS.SYS 2007-03-01 11:14:50 0 --sha-r C:\IO.SYS 2007-03-01 11:14:50 0 ----a-w C:\CONFIG.SYS 2007-03-01 11:14:50 0 ----a-w C:\AUTOEXEC.BAT 2007-03-01 11:11:59 21,856 ----a-w C:\WINDOWS\system32\emptyregdb.dat (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] “{53707962-6F74-2D53-2644-206D7942484F}”=“C:\PROGRA~1\SPYBOT~1\SDHelper.dll” “{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}”=“C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “NVMixerTray”="“C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe”" “Adobe Photo Downloader”="“C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe”" “NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup” “nwiz”=“nwiz.exe /install” “NvMediaCenter”=“RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit” “SunJavaUpdateSched”="“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe”" “DAEMON Tools-1033”="“C:\Program Files\D-Tools\daemon.exe” -lang 1033" “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” “TkBellExe”="“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot" “SpywareBot”=“C:\Program Files\SpywareBot\SpywareBot.exe -boot” “nod32kui”="“C:\Program Files\Eset\nod32kui.exe” /WAITSERVICE" “CTHelper”=“CTHELPER.EXE” “!AVG Anti-Spyware”="“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\System32\ctfmon.exe” “Gadu-Gadu”="“C:\Program Files\Gadu-Gadu\gg.exe” /tray" @="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] “NoColorChoice”=dword:00000000 “NoSizeChoice”=dword:00000000 “NoDispScrSavPage”=dword:00000000 “NoDispCPL”=dword:00000000 “NoVisualStyleChoice”=dword:00000000 “NoDispSettingsPage”=dword:00000000 “NoDispAppearancePage”=dword:00000000 “NoDispBackgroundPage”=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoActiveDesktopChanges”=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoSaveSettings”=dword:00000000 “NoThemesTab”=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages msv1_0\0\0 Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages scecli\0\0 HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^menu start^programy^autostart^adobe reader speed launch.lnk C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^menu start^programy^autostart^adobe reader synchronizer.lnk C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^ja^menu start^programy^autostart^openoffice.org 2.0.lnk C:\PROGRA~1\OPENOF~1.0\program\QUICKS~1.EXE HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pando “C:\Program Files\Pando Networks\Pando\Pando.exe” /Minimized HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winampagent C:\Program Files\Winamp\winampa.exe [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService DnsCache\0\0 rpcss RpcSs\0\0 imgsvc StiSvc\0\0 termsvcs TermService\0\0 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost ~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ backup-20070510-214221-788 O9 - Extra ‘Tools’ menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm backup-20070510-214221-936 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm Contents of the ‘Scheduled Tasks’ folder C:\WINDOWS\tasks\RegCure Program Check.job C:\WINDOWS\tasks\RegCure.job C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job C:\WINDOWS\tasks\XoftSpySE 2.job C:\WINDOWS\tasks\XoftSpySE.job ******************************************************************** catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-11 15:27:07 Windows 5.1.2600 Dodatek Service Pack. 1 NTFS scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 2007-05-11 15:27:15 C:\ComboFix-quarantined-files.txt … 2007-05-11 15:27