ComboFix 07-05.27.BV - Running from: “D:\Documents and Settings\Kasia\Pulpit\waľne narz©dzia” (((((((((((((((((((((((((((((((((((((((((((((((((( V Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))) D:\WINDOWS\system32\pmnnm.dll D:\WINDOWS\system32\mnnmp.ini * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * ((((((((((((((((((((((((((((((( Files Created from 2007-05-05 to 2007-06-05 )))))))))))))))))))))))))))))))))) 2007-06-05 12:11 2,580 --a------ D:\WINDOWS\system32\mtgxceos.exe 2007-06-05 12:09 131,124 --a------ D:\WINDOWS\system32\hjvlxfnh.dll 2007-06-05 12:02 33,302 --a------ D:\WINDOWS\system32\hggddcc.dll.vir 2007-06-05 11:52 64,000 --a------ D:\WINDOWS\system32\drivers\e4ldr.sys 2007-06-05 11:52 50,007 --a------ D:\WINDOWS\system32\drivers\adildr.sys 2007-06-05 11:52 46,892 --a------ D:\WINDOWS\system32\ADADIX16.DLL 2007-06-05 11:52 4,981 --a------ D:\WINDOWS\system32\ADADIX2K.DLL 2007-06-05 11:52 24,576 --a------ D:\WINDOWS\enddisk32.exe 2007-06-05 11:52 22,395 --a------ D:\WINDOWS\system32\drivers\fpga.bin 2007-06-05 11:52 176,128 --a------ D:\WINDOWS\autoclk.exe 2007-06-05 11:52 155,648 --a------ D:\WINDOWS\system32\adadix32.dll 2007-06-05 11:52 152,220 --a------ D:\WINDOWS\system32\drivers\L1E4I2.BIN 2007-06-05 11:52 152,220 --a------ D:\WINDOWS\system32\drivers\L1E4I1.BIN 2007-06-05 11:52 152,220 --a------ D:\WINDOWS\system32\drivers\L1E4I0.BIN 2007-06-05 11:52 152,132 --a------ D:\WINDOWS\system32\drivers\L1E4P2.BIN 2007-06-05 11:52 152,132 --a------ D:\WINDOWS\system32\drivers\L1E4P1.BIN 2007-06-05 11:52 152,132 --a------ D:\WINDOWS\system32\drivers\L1E4P0.BIN 2007-06-05 11:52 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9P2.BIN 2007-06-05 11:52 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9P1.BIN 2007-06-05 11:52 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9P0.BIN 2007-06-05 11:52 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9I2.BIN 2007-06-05 11:52 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9I1.BIN 2007-06-05 11:52 152,126 --a------ D:\WINDOWS\system32\drivers\L1E9I0.BIN 2007-06-05 11:52 152,036 --a------ D:\WINDOWS\system32\drivers\L1E4D2.BIN 2007-06-05 11:52 152,034 --a------ D:\WINDOWS\system32\drivers\L1E4D1.BIN 2007-06-05 11:52 152,034 --a------ D:\WINDOWS\system32\drivers\L1E4D0.BIN 2007-06-05 11:52 143,360 --a------ D:\WINDOWS\adiras.exe 2007-06-05 11:52 135,168 --a------ D:\WINDOWS\system32\unaddrv.exe 2007-06-05 11:52 127,456 --a------ D:\WINDOWS\system32\IPDETECT.EXE 2007-06-05 11:52 126,976 --a------ D:\WINDOWS\system32\coclassfast.dll 2007-06-05 11:52 126,489 --a------ D:\WINDOWS\system32\drivers\adiusbaw.sys 2007-06-05 11:52 116,992 --a------ D:\WINDOWS\system32\drivers\e4usbaw.sys 2007-06-05 11:52 2007-06-04 16:47 94,890 --ahs---- D:\WINDOWS\system32\urdvxc.exe 2007-06-01 18:45 37,376 --a------ D:\WINDOWS\system32\kp.exe 2007-06-01 12:48 37,376 -r-hs---- D:\WINDOWS\system\csrrs.exe 2007-05-31 10:55 57,344 --ahs---- D:\WINDOWS\system32\irdvxc.exe 2007-05-31 00:30 2007-05-29 21:24 49,152 --a------ D:\WINDOWS\nircmd.exe 2007-05-26 09:56 2007-05-11 21:46 2007-05-11 12:11 2007-05-10 21:11 2007-05-10 20:08 2007-05-10 19:35 2007-05-10 10:52 2007-05-06 19:05 73,728 --a------ D:\WINDOWS\system32\pv.exe 2007-05-06 19:05 39,184 --a------ D:\WINDOWS\system32\Ntrights.exe 2007-05-06 19:05 175,616 --a------ D:\WINDOWS\system32\strings.exe 2007-05-06 19:05 16,384 --a------ D:\WINDOWS\system32\restart.exe 2007-05-06 19:05 126,976 --a------ D:\WINDOWS\system32\zip.exe 2007-05-06 19:05 11,254 --a------ D:\WINDOWS\system32\locate.com 2007-05-05 19:39 76,560 --a------ D:\WINDOWS\system32\drivers\tmcomm.sys 2007-05-05 19:39 2007-05-05 09:53 25,992 --a------ D:\WINDOWS\system32\pgdfgsvc.exe (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-05 16:02:18 50,748 ----a-w D:\WINDOWS\system32\perfc015.dat 2007-06-05 16:02:18 358,702 ----a-w D:\WINDOWS\system32\perfh015.dat 2007-05-26 07:58:36 12,400 ----a-w D:\WINDOWS\system32\drivers\secdrv.sys 2007-05-04 20:02:48 -------- d-----w D:\Program Files\Odkurzacz 2007-05-04 14:41:38 -------- d-----w D:\Program Files\Lavalys 2007-05-02 13:35:14 -------- d-----w D:\Program Files\Moko Interactive 2007-05-02 13:35:12 -------- d-----w D:\Program Files\jv16 PowerTools 2007-05-02 11:23:06 -------- d-----w D:\Program Files\jv16 PowerTools(2) 2007-05-01 15:45:20 -------- d-----w D:\Program Files\Support Tools 2007-05-01 09:45:58 -------- d-----w D:\Program Files\SiteAdvisor 2007-05-01 09:43:54 -------- d-----w D:\DOCUME~1\Kasia\DANEAP~1\SiteAdvisor 2007-04-27 20:39:52 26,622 ----a-w D:\WINDOWS\system32\lr86.exe 2007-04-16 14:58:40 0 ----a-w D:\WINDOWS\system32\CMMGR32.EXE 2007-04-14 17:02:50 726,920 ----a-w D:\Program Files\WindowsXP-KB935448-x86-PLK.exe 2007-04-14 16:57:24 4,709,688 ----a-w D:\Program Files\WindowsXP-KB922760-x86-PLK.exe 2007-04-14 14:50:36 23,016 ----a-w D:\WINDOWS\system32\emptyregdb.dat 2007-04-14 14:30:24 37,860,928 ----a-w D:\Program Files\iTunesSetup.exe 2007-04-10 18:54:30 -------- d-----w D:\DOCUME~1\Kasia\DANEAP~1\FunkyFarm 2007-04-10 18:32:16 -------- d-----w D:\Program Files\Play 2007-04-10 17:58:26 -------- d-----w D:\Program Files\Calaris 2007-04-06 09:53:20 -------- d-----w D:\Program Files\PITy (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {089FD14D-132B-48FC-8861-0048AE113215}=D:\Program Files\SiteAdvisor\6066\SiteAdv.dll [2007-03-30 17:41] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SiteAdvisor”=“D:\Program Files\SiteAdvisor\6066\SiteAdv.exe” [2007-03-30 17:42] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Odkurzacz-MCD”=“D:\Program Files\Odkurzacz\odk_mcd.exe” [2007-05-03 10:02] “Spyware Doctor”=“D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe” [2007-03-26 21:09] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Spyware Doctor”=“D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe” /Q [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk] path=c:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk backup=D:\WINDOWS\pss\DSLMON.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^VIA RAID TOOL.lnk] backup=D:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^Kasia^Menu Start^Programy^Autostart^Trend Micro Anti-Spyware.lnk] backup=D:\WINDOWS\pss\Trend Micro Anti-Spyware.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “D:\Program Files\Messenger\msmsgs.exe” /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor] “D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe” /Q HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs* ******************************************************************** catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-05 20:17:58 Windows 5.1.2600 FAT NTAPI scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 2007-06-05 20:18:13 D:\ComboFix-quarantined-files.txt … 2007-06-05 20:18 D:\ComboFix3.txt … 2007-05-31 00:35 D:\ComboFix2.txt … 2007-06-05 13:52 — E O F —