“Wojtek” - 2007-07-13 10:26:49 - ComboFix 07-07-13 - Dodatek Service Pack 2 ((((((((((((((((((((((((( Files Created from 2007-06-13 to 2007-07-13 ))))))))))))))))))))))))))))))) 2007-07-12 23:51 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-12 22:44 962,612 --a------ C:\WINDOWS\system32\mfc42d.dll 2007-07-12 22:44 5,685 -ra------ C:\WINDOWS\system32\drivers\AsIO.sys 2007-07-12 22:44 5,120 --a------ C:\WINDOWS\system32\drivers\AsInsHelp64.sys 2007-07-12 22:44 434,252 --a------ C:\WINDOWS\system32\MSVCRTD.DLL 2007-07-12 22:44 3,328 --a------ C:\WINDOWS\system32\drivers\AsInsHelp32.sys 2007-07-12 22:44 24,576 -ra------ C:\WINDOWS\system32\AsIO.dll 2007-07-12 22:44 2007-07-12 20:52 2007-07-12 20:52 2007-07-09 18:07 2007-07-07 20:41 2007-07-07 20:28 2007-07-07 16:35 2007-07-07 12:12 2007-07-07 10:38 2007-07-07 10:22 2007-07-06 23:01 2007-07-06 18:41 2007-07-06 18:39 95,872 --a------ C:\WINDOWS\system32\AVASTSS.scr 2007-07-06 18:39 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-07-06 18:39 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-07-06 18:39 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-07-06 18:39 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-07-06 18:39 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-07-06 18:39 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-06-21 15:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2007-06-21 15:02 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2007-06-17 00:34 33,280 --a------ C:\WINDOWS\system32\drivers\AmdLLD.sys (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-07 14:49:12 -------- d-----w C:\Program Files\Winamp 2007-07-07 14:49:12 -------- d-----w C:\Program Files\QuickTime 2007-07-07 14:49:12 -------- d-----w C:\Program Files\Movie Maker 2007-07-06 21:27:35 -------- d-----w C:\Program Files\AMD 2007-06-04 22:22:00 67,078 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-04 22:22:00 435,978 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-04 22:20:31 -------- d-----w C:\Program Files\Realtek 2007-05-09 17:56:42 50 ----a-w C:\AUTOEXEC.BAT 2007-04-30 15:54:44 126,464 ----a-w C:\WINDOWS\system32\upx-adtp.exe 2007-04-30 15:54:43 22,016 ----a-w C:\WINDOWS\system32\hoko.dll 2007-04-30 15:54:42 4,096 ----a-w C:\WINDOWS\system32\hguard.dll 2007-04-19 11:26:00 888,832 ----a-w C:\WINDOWS\system32\nvmobls.dll 2007-04-19 11:26:00 86,016 ----a-w C:\WINDOWS\system32\nvmctray.dll 2007-04-19 11:26:00 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll 2007-04-19 11:26:00 7,700,480 ----a-w C:\WINDOWS\system32\nvcpl.dll 2007-04-19 11:26:00 581,632 ----a-w C:\WINDOWS\system32\nvhwvid.dll 2007-04-19 11:26:00 5,644,288 ----a-w C:\WINDOWS\system32\nvoglnt.dll 2007-04-19 11:26:00 5,619,712 ----a-w C:\WINDOWS\system32\nvdisps.dll 2007-04-19 11:26:00 5,255,168 ----a-w C:\WINDOWS\system32\nvdispsr.dll 2007-04-19 11:26:00 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll 2007-04-19 11:26:00 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll 2007-04-19 11:26:00 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2007-04-19 11:26:00 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe 2007-04-19 11:26:00 425,984 ----a-w C:\WINDOWS\system32\keystone.exe 2007-04-19 11:26:00 4,543,616 ----a-w C:\WINDOWS\system32\nv4_disp.dll 2007-04-19 11:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll 2007-04-19 11:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll 2007-04-19 11:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll 2007-04-19 11:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrshe.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrsar.dll 2007-04-19 11:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll 2007-04-19 11:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll 2007-04-19 11:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll 2007-04-19 11:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll 2007-04-19 11:26:00 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll 2007-04-19 11:26:00 3,203,072 ----a-w C:\WINDOWS\system32\nvgamesr.dll 2007-04-19 11:26:00 3,035,136 ----a-w C:\WINDOWS\system32\nvgames.dll 2007-04-19 11:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll 2007-04-19 11:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll 2007-04-19 11:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll 2007-04-19 11:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll 2007-04-19 11:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll 2007-04-19 11:26:00 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll 2007-04-19 11:26:00 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll 2007-04-19 11:26:00 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll 2007-04-19 11:26:00 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll 2007-04-19 11:26:00 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll 2007-04-19 11:26:00 278,528 ----a-w C:\WINDOWS\system32\nvrsfr.dll 2007-04-19 11:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrsit.dll 2007-04-19 11:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrses.dll 2007-04-19 11:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrsel.dll 2007-04-19 11:26:00 270,336 ----a-w C:\WINDOWS\system32\nvrsde.dll 2007-04-19 11:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrspt.dll 2007-04-19 11:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrsnl.dll 2007-04-19 11:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrsesm.dll 2007-04-19 11:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsru.dll 2007-04-19 11:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsptb.dll 2007-04-19 11:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsja.dll 2007-04-19 11:26:00 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll 2007-04-19 11:26:00 253,952 ----a-w C:\WINDOWS\system32\nvrshu.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrstr.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrssl.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrssk.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrspl.dll 2007-04-19 11:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrsno.dll 2007-04-19 11:26:00 245,760 ----a-w C:\WINDOWS\system32\nvrssv.dll 2007-04-19 11:26:00 245,760 ----a-w C:\WINDOWS\system32\nvrsda.dll 2007-04-19 11:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrsfi.dll 2007-04-19 11:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrseng.dll 2007-04-19 11:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrscs.dll 2007-04-19 11:26:00 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll 2007-04-19 11:26:00 221,184 ----a-w C:\WINDOWS\system32\nvrszhc.dll 2007-04-19 11:26:00 212,992 ----a-w C:\WINDOWS\system32\nvwrsja.dll 2007-04-19 11:26:00 212,992 ----a-w C:\WINDOWS\system32\nvapi.dll 2007-04-19 11:26:00 2,973,696 ----a-w C:\WINDOWS\system32\nvvitvsr.dll 2007-04-19 11:26:00 2,924,544 ----a-w C:\WINDOWS\system32\nvvitvs.dll 2007-04-19 11:26:00 2,859,008 ----a-w C:\WINDOWS\system32\nvmoblsr.dll 2007-04-19 11:26:00 196,608 ----a-w C:\WINDOWS\system32\nvwrsko.dll 2007-04-19 11:26:00 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll 2007-04-19 11:26:00 167,936 ----a-w C:\WINDOWS\system32\nvwrszht.dll 2007-04-19 11:26:00 163,840 ----a-w C:\WINDOWS\system32\nvwrszhc.dll 2007-04-19 11:26:00 159,810 ----a-w C:\WINDOWS\system32\nvsvc32.exe 2007-04-19 11:26:00 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe 2007-04-19 11:26:00 118,784 ----a-w C:\WINDOWS\system32\nvrszht.dll 2007-04-19 11:26:00 1,732,608 ----a-w C:\WINDOWS\system32\nvwssr.dll 2007-04-19 11:26:00 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll 2007-04-19 11:26:00 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe 2007-04-19 11:26:00 1,474,560 ----a-w C:\WINDOWS\system32\nview.dll 2007-04-19 11:26:00 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe 2007-04-19 11:26:00 1,236,992 ----a-w C:\WINDOWS\system32\nvwss.dll 2007-04-19 11:26:00 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll 2007-02-07 09:30:06 97 ----a-w C:\Program Files\Common Files\7.ini ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2004-12-14 12:56 63136 -ra------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE~\Browser Helper Objects{CD8BFE70-5809-4C73-9EEE-E5672C2B79D7}] C:\Program Files\Deepdo\DeepdoBar\Favorite\FavBlock.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “InCD”=“C:\Program Files\Ahead\InCD\InCD.exe” [2005-07-08 16:25] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2005-03-13 17:30] “nwiz”=“nwiz.exe” [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe] “Detect”=“E:\Program Files\iNTERNET Turbo\idetect.exe” [] “RTHDCPL”=“RTHDCPL.EXE” [2006-08-23 14:08 C:\WINDOWS\RTHDCPL.exe] “SkyTel”=“SkyTel.EXE” [2006-05-16 12:04 C:\WINDOWS\SkyTel.exe] “Alcmtr”=“ALCMTR.EXE” [2005-05-03 12:43 C:\WINDOWS\Alcmtr.exe] “NvMediaCenter”=“NvMCTray.dll” [2007-04-19 13:26 C:\WINDOWS\system32\nvmctray.dll] “amd_dc_opt”=“C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe” [2006-11-17 16:49] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-04-30 17:42] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NBJ”=“C:\Program Files\Ahead\Nero BackItUp\NBJ.exe” [2005-06-02 17:03] “PowerBar”="" [] “win msdt service”=“mswindtc.exe” [] “Gadu-Gadu”=“E:\Program Files\Gadu-Gadu\gg.exe” [2007-01-30 16:58] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices] “win msdt service”=mswindtc.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices] “Detect”=E:\Program Files\iNTERNET Turbo\idetect.exe /auto [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “appinit_dlls”=NVDESK32.DLL [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Image Zone - szybkie uruchamianie.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Image Zone - szybkie uruchamianie.lnk backup=C:\WINDOWS\pss\HP Image Zone - szybkie uruchamianie.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Dialer Toolkit Pro] E:\Program Files\Anti-Dialer Toolkit Pro\ADTP.EXE /t [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager] E:\Program Files\Free Download Manager\fdm.exe -autorun [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu] “E:\Program Files\Gadu-Gadu\gg.exe” /tray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] “C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU] “E:\Program Files\lg_fwupdate\fwupdate.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] “C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant] “C:\Program Files\Unlocker\UnlockerAssistant.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WheelMouse] E:\PROGRA~1\A4Tech\Mouse\Amoumain.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] E:\Program Files\Winamp\winampa.exe HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs Gentad Navoct jkuowmr gkazgj Contents of the ‘Scheduled Tasks’ folder 2007-07-12 10:26:00 C:\WINDOWS\tasks{79D88C1F-5E7F-4E28-A107-0230893F762C}_A-BB9DW74DAQYY7_p.job ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-13 10:27:33 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … HKCU\Software\Microsoft\Windows\CurrentVersion\Run PowerBar = ?:?w???s???D???sd???D???d???g;?w0???K;?wt?@?l?@? ?y?.??w???wpO?w???K;?w?=?w???s???>?w???l?@???e?w???t?@?x?v???l?@?l?@???C?w???t?@???l?@?8?@?l?@???s??? scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-13 10:28:12 C:\ComboFix-quarantined-files.txt … 2007-07-13 10:27 — E O F —