ComboFix 07-08-30.3 - “Monika” 2007-09-06 19:55:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.199 [GMT 2:00]
ADS removed - C:\WINDOWS\system32\ntoskrnl.exe: Nie można odnaleźć określonego pliku.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Tomek\DANEAP~1\microsoft\internet explorer\quick launch\intern~1.lnk
C:\WINDOWS\exefld
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\drivers\srosa.sys
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))
2007-09-06 19:52
2007-09-06 18:43 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-06 14:31 11,776 --a–c— C:\WINDOWS\system32\dllcache\chkdsk.exe
2007-09-06 14:31 11,776 --a------ C:\WINDOWS\system32\chkdsk.exe
2007-09-06 09:16
2007-09-06 09:00
2007-09-03 13:20
2007-09-03 09:10
2007-09-03 06:58 287 --a------ C:\WINDOWS\EReg072.dat
2007-09-02 15:52
2007-09-02 15:52
2007-09-02 10:40 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-09-02 10:39
2007-09-02 10:31
2007-09-01 15:45
2007-09-01 08:32
2007-09-01 08:32
2007-09-01 08:03 83,968 --a------ C:\WINDOWS\system32\Skbase40.dll
2007-09-01 08:03 8,704 --a------ C:\WINDOWS\system32\vidccleaner.exe
2007-09-01 08:03 217,088 --a------ C:\WINDOWS\system32\skjpeg40.dll
2007-08-31 14:07
2007-08-31 13:36
2007-08-31 12:38
2007-08-31 12:37 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2007-08-31 12:37 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2007-08-31 12:37 1,230,336 --a------ C:\WINDOWS\system32\msxml4.dll
2007-08-31 12:37
2007-08-31 12:37
2007-08-31 07:03
2007-08-31 06:58
2007-08-31 06:57 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-08-31 06:57
2007-08-27 07:31 49,536 --a------ C:\WINDOWS\system32\drivers\ajqejcwx.sys
2007-08-26 16:56
2007-08-22 23:33
2007-08-21 18:37
2007-08-19 21:16 12 --a------ C:\WINDOWS\lang_e86.dll
2007-08-12 07:12
2007-08-09 21:15
2007-08-08 21:19
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-06 19:54 --------- d-------- C:\DOCUME~1\Monika\DANEAP~1\Launchy
2007-09-06 14:30 --------- d-------- C:\DOCUME~1\Tomek\DANEAP~1\Launchy
2007-09-06 12:33 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-05 13:23 --------- d-------- C:\DOCUME~1\Monika\DANEAP~1\LimeWire
2007-09-04 17:23 --------- d-------- C:\DOCUME~1\Tomek\DANEAP~1\Tlen.pl
2007-09-04 10:32 --------- d-------- C:\DOCUME~1\Monika\DANEAP~1\Skype
2007-09-02 19:38 --------- d-------- C:\DOCUME~1\Monika\DANEAP~1\Tlen.pl
2007-09-02 15:51 --------- d-------- C:\DOCUME~1\Monika\DANEAP~1\uTorrent
2007-09-01 21:51 --------- d-------- C:\DOCUME~1\Tomek\DANEAP~1\X-Chat 2
2007-09-01 10:25 2855 --a------ C:\WINDOWS\pif\NFS_DOS.PIF
2007-09-01 08:03 --------- d–h----- C:\Program Files\InstallShield Installation Information
2007-08-30 23:41 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\Tlen.pl
2007-08-30 22:05 --------- d-------- C:\DOCUME~1\Monika\DANEAP~1\Winamp
2007-08-24 06:49 --------- d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\FLEXnet
2007-08-23 08:16 --------- d-------- C:\DOCUME~1\Tomek\DANEAP~1\Azureus
2007-08-18 03:07 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\Skype
2007-08-08 21:19 --------- d-------- C:\Program Files\Common Files\Real
2007-08-06 13:40 --------- d-------- C:\Program Files\QuickTime
2007-08-04 10:57 --------- d-------- C:\Program Files\Foxit
2007-08-02 17:48 108144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-08-02 17:48 --------- dr-h----- C:\DOCUME~1\Monika\DANEAP~1\SecuROM
2007-08-02 17:39 --------- d-------- C:\DOCUME~1\Monika\DANEAP~1\Azureus
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-20 18:46 --------- d-------- C:\Program Files\Windows Media Connect 2
2007-07-17 16:05 682232 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-07-14 13:27 --------- d-------- C:\Program Files\uTorrent
2007-07-13 09:36 166912 --a------ C:\WINDOWS\system32\libmcrypt.dll
2007-07-07 22:37 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\Netscape
2007-07-07 13:36 --------- d-------- C:\DOCUME~1\Tomek\DANEAP~1\Netscape
2007-07-06 21:14 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\Winamp
2007-07-06 21:14 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\Real
2007-07-06 21:14 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\PC Suite
2007-07-06 21:14 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\Nokia
2007-07-06 21:14 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\ImageBadger
2007-07-06 21:06 --------- d-------- C:\DOCUME~1\OLDSCH~1\DANEAP~1\ATI
2007-07-06 18:57 --------- d-------- C:\DOCUME~1\Tomek\DANEAP~1\FlashFXP
2007-07-06 18:38 --------- d-------- C:\DOCUME~1\Tomek\DANEAP~1\GlobalSCAPE
2007-07-06 15:56 --------- d-------- C:\DOCUME~1\Monika\DANEAP~1\Canon
2007-06-12 09:28 545280 --a------ C:\WINDOWS\flashax.exe
2007-06-12 09:28 12288 --a------ C:\WINDOWS\impborl.dll
2001-11-23 12:08 712704 --a------ C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{112AB43D-32C4-3B21-53BA-13A46743BC34}]
2002-03-27 14:25 48128 --a------ C:\WINDOWS\system32\mousegex.dll
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{73c7d5b0-7b03-444a-84c7-ce1ba03b5573}]
2007-06-26 17:54 1383448 --a------ C:\Program Files\Foxit\tbFoxi.dll
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{7428F943-BC4F-4A39-3B43-AB433C523B34}]
2002-08-15 08:23 57856 --a------ C:\WINDOWS\system32\WebMon.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
“{73C7D5B0-7B03-444A-84C7-CE1BA03B5573}”= C:\Program Files\Foxit\tbFoxi.dll [2007-06-26 17:54 1383448]
[HKEY_CLASSES_ROOT\CLSID{73C7D5B0-7B03-444A-84C7-CE1BA03B5573}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2006-01-02 16:41]
“QuickTime Task”=“C:\Program Files\QuickTime\QTTask.exe” [2007-06-29 06:24]
“iTunesHelper”=“D:\Programy\iTunes\iTunesHelper.exe” [2007-09-05 18:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Komunikator”=“D:\Programy\Tlen.pl\tlen.exe” []
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44]
“Mmm”=“D:\Programy\Mmm+\MmmTray.exe” [2007-05-24 13:49]
“mule_st_key”=“C:\Documents and Settings\Monika\Dane aplikacji\m\flec006.exe” []
C:\DOCUME~1\OLDSCH~1\MENUST~1\Programy\AUTOST~1\
Tworzenie wycink˘w ekranu i uruchamianie programu OneNote 2007.lnk - D:\Programy\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
“NoResolveTrack”=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoRecentDocsMenu”=1 (0x1)
“NoResolveTrack”=1 (0x1)
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@=“Driver Group”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
@=“Service”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E967-E325-11CE-BFC1-08002BE10318}]
@=“DiskDrive”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@=“Hdc”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@=“Keyboard”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@=“Mouse”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@=“System”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@=“Volume”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Acrobat Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Acrobat Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Monitor Apache Servers.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Monitor Apache Servers.lnk
backup=C:\WINDOWS\pss\Monitor Apache Servers.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Monika^Menu Start^Programy^Autostart^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk]
path=C:\Documents and Settings\Monika\Menu Start\Programy\Autostart\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
backup=C:\WINDOWS\pss\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AAWTray]
D:\Programy\Ad-Aware 2007\AAWTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
“D:\Programy\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM]
C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]
RunDll32 cmicnfg.cpl,CMICtrlWnd
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
“D:\Programy\DAEMON Tools\daemon.exe” -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
“D:\Programy\DAEMON Tools\daemon.exe” -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
“C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe” -t
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\East-Tec Backup 2007]
“D:\Programy\East-Tec Backup 2007\etBackup.exe” /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
“D:\Programy\Microsoft Office\Office12\GrooveMonitor.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
“D:\Programy\iTunes\iTunesHelper.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator]
D:\Programy\Tlen.pl\tlen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pb_scheduler_agent]
rem D:\Programy\Premium Booster\scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
D:\Programy\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
D:\Programy\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
“C:\Program Files\QuickTime\QTTask.exe” -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Soundlibs]
C:\WINDOWS\soundlib.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
“D:\Programy\Java JRE\bin\jusched.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
“ServiceLayer”=3 (0x3)
“ose”=3 (0x3)
“odserv”=3 (0x3)
“Microsoft Office Groove Audit Service”=3 (0x3)
“iPod Service”=3 (0x3)
“gusvc”=3 (0x3)
“FLEXnet Licensing Service”=3 (0x3)
“Bonjour Service”=2 (0x2)
“ATI Smart”=2 (0x2)
“Adobe Version Cue CS3”=3 (0x3)
“Apple Mobile Device”=2 (0x2)
“WMPNetworkSvc”=3 (0x3)
“idsvc”=3 (0x3)
“PDAgent”=2 (0x2)
“PDEngine”=3 (0x3)
“PDExchange”=3 (0x3)
“aawservice”=2 (0x2)
“MDM”=2 (0x2)
S1 srosa;Megadrv3;??\C:\WINDOWS\system32\drivers\srosa.sys
S3 MSIRCOMM;Microsoft IR Communications Driver;C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
S4 msvsmon80;Visual Studio 2005 Remote Debugger;“D:\Programy\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe” /service msvsmon80
S4 PDExchange;PDExchange;D:\Programy\PerfectDisk\PDExchange.exe
Contents of the ‘Scheduled Tasks’ folder
2007-09-04 15:58:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-09-03 19:00:02 C:\WINDOWS\Tasks\SyncBackSE Bookmarks.job - D:\Programy\SyncBackSE\SyncBackSE.exe
2007-09-04 19:00:00 C:\WINDOWS\Tasks\SyncBackSE Tlen Archiwum.job - D:\Programy\SyncBackSE\SyncBackSE.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 20:01:40
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-06 20:02:37 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-06 20:02
— E O F —
W msconfig mam powywalane śmieci.