“Krystian” - 2007-07-19 12:50:30 - ComboFix 07-07-17.8 - Dodatek Service Pack 2 FAT32 ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32.exe ((((((((((((((((((((((((( Files Created from 2007-06-19 to 2007-07-19 ))))))))))))))))))))))))))))))) 2007-07-19 12:50 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-19 12:46 6,870 --a------ C:\dnsbak.reg 2007-07-16 21:00 2007-07-16 20:07 2007-07-13 20:29 2007-07-13 19:36 72,234 --a------ C:\WINDOWS\BricoPackUninst.cmd 2007-07-13 19:34 5,376 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd 2007-07-13 19:34 2007-07-12 22:33 2007-07-12 22:32 2007-07-12 22:27 2007-07-12 15:33 2007-07-12 13:45 60,273 --a------ C:\WINDOWS\system32\pthreadGC2.dll 2007-07-11 20:14 2007-07-07 10:29 2007-07-05 10:33 111,104 --a------ C:\WINDOWS\system32\uharc.exe 2007-07-04 14:43 2007-07-04 14:39 2,321,408 --a------ C:\WINDOWS\system32\TUKernel.exe 2007-07-03 17:17 2007-07-03 16:21 24,072 --a------ C:\WINDOWS\system32\uxtuneup.dll 2007-07-03 16:21 2007-07-03 16:21 2007-07-02 21:41 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe 2007-07-02 21:41 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-07-02 21:41 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll 2007-07-02 21:41 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll 2007-07-02 21:37 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll 2007-07-02 21:37 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll 2007-07-02 21:37 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll 2007-07-02 21:37 740,442 --a------ C:\WINDOWS\system32\DivX.dll 2007-07-02 21:37 73,728 --a------ C:\WINDOWS\system32\dpl100.dll 2007-07-02 21:37 593,920 --a------ C:\WINDOWS\system32\dpuGUI11.dll 2007-07-02 21:37 57,344 --a------ C:\WINDOWS\system32\dpv11.dll 2007-07-02 21:37 53,248 --a------ C:\WINDOWS\system32\dpuGUI10.dll 2007-07-02 21:37 344,064 --a------ C:\WINDOWS\system32\dpus11.dll 2007-07-02 21:37 294,912 --a------ C:\WINDOWS\system32\dpu11.dll 2007-07-02 21:37 294,912 --a------ C:\WINDOWS\system32\dpu10.dll 2007-07-02 21:37 196,608 --a------ C:\WINDOWS\system32\dtu100.dll 2007-07-02 21:36 124,472 --a------ C:\WINDOWS\system32\DivXCodecUpdateChecker.exe 2007-07-02 21:36 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll 2007-07-02 14:55 45,568 --a------ C:\WINDOWS\UniFish3.exe 2007-06-29 08:29 23 --ahs---- C:\WINDOWS\system32\fe6_r.dll 2007-06-28 13:38 2007-06-28 13:29 2007-06-27 15:11 98,304 --a------ C:\WINDOWS\system32\N2PUtil.dll 2007-06-27 15:11 28,672 --a------ C:\WINDOWS\system32\N2PAuto.exe 2007-06-27 15:11 2007-06-27 15:11 2007-06-27 12:17 2007-06-26 15:52 2007-06-26 14:24 2007-06-24 10:46 2007-06-24 10:46 2007-06-24 10:46 2007-06-24 10:46 2007-06-24 10:46 2007-06-23 18:57 2007-06-23 18:06 2007-06-19 19:28 2007-06-19 19:25 2007-06-19 16:35 569,344 --a------ C:\WINDOWS\system32\imagr5.dll 2007-06-19 16:35 544,768 --a------ C:\WINDOWS\system32\imagx5.dll 2007-06-19 16:35 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll 2007-06-19 16:35 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-06-19 16:15 2007-06-19 15:02 2007-06-19 14:10 5 --ahs---- C:\WINDOWS\system32\ddaecdf3_g.dll 2007-06-19 14:04 8,192 --a------ C:\WINDOWS\system32\cidaemon.exe 2007-06-19 08:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-13 17:36:46 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll 2007-07-11 18:13:52 10,368 ----a-w C:\WINDOWS\system32\drivers\pfc.sys 2007-07-11 08:26:16 79,408 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-07-11 08:26:16 458,022 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-07-01 09:35:34 737,280 ----a-w C:\WINDOWS\iun6002.exe 2007-06-20 06:46:18 0 ----a-w C:\adware.exe 2007-06-19 09:16:26 682,232 ----a-w C:\WINDOWS\system32\drivers\sptd.sys 2007-06-17 17:57:06 129,522 ----a-w C:\WINDOWS\system32\otjshx.exe 2007-06-17 15:04:28 0 ----a-w C:\CONFIG.SYS 2007-06-17 15:04:28 0 ----a-w C:\AUTOEXEC.BAT 2007-06-14 12:00:06 -------- d-----w C:\DOCUME~1\Krystian\DANEAP~1\Gadu-Gadu 2007-06-04 13:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys 2007-06-04 13:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys 2007-06-04 13:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys 2007-05-31 13:53:32 27 ----a-w C:\WINDOWS\tamer.bat 2007-05-16 15:18:58 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-05-08 18:23:10 10,752 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{00C6482D-C502-44C8-8409-FCE54AD9C208}] 2007-02-06 09:08 63048 --a------ C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2003-11-04 01:17 54248 --a------ D:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{53707962-6F74-2D53-2644-206D7942484F}] 2005-05-31 02:04 853672 --a------ D:\PROGRA~2\SPYBOT~1\SDHelper.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] C:\Program Files\Java\jre1.6.0\bin\ssv.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Gadu-Gadu”=“D:\Programy sciagniete\Gadu-Gadu\gg.exe” [2006-11-14 11:12] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices] “Office XP hack”=c:\office_patch.exe hack C:\DOCUME~1\ALLUSE~1\MENUST~1\Programy\AUTOST~1 Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-07-13 21:40:15] Kalendarz XP.lnk - D:\Program Files\Kalendarz XP\Kalendarz.exe [2007-07-17 16:12:52] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2007-05-30 14:29] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^F-Secure Anti-Virus 2006.lnk] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Krystian^Menu Start^Programy^Autostart^UniSpiker-2.6.lnk] backup=C:\WINDOWS\pss\UniSpiker-2.6.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Manager] “D:\Program Files\F-Secure Internet Security\Common\FSM32.EXE” /splash [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Startup Wizard] “D:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE” /reboot [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure TNB] “D:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe” /CHECKALL /WAITFORSW [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MKSRegmon] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mkstray] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mks_mail] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msvcc25] svcchost.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mysvcig38] mysvcc.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Odkurzacz-MCD] D:\Program Files\Odkurzacz\odk_mcd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs UxTuneUp [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{3b7d5448-9c2c-11db-8360-0020ed839b95}] AutoRun\command- F:\Autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{74c184a1-9a8c-11db-9b73-806d6172696f}] AutoRun\command- E:\setup.exe Contents of the ‘Scheduled Tasks’ folder 2007-07-13 15:39:38 C:\WINDOWS\tasks\1-Click Maintenance.job ************************************************************************** catchme 0.3.1040 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-19 12:51:33 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden registry entries … disk error: C:\WINDOWS\system32\config\software disk error: C:\Documents and Settings\KRYSTIAN\ntuser.dat scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-19 12:51:52 C:\ComboFix-quarantined-files.txt … 2007-07-19 12:51 — E O F —