ComboFix 07-08-14.4 - “B” 2007-08-17 19:49:04.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.8 [GMT 2:00] * Created a new restore point ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\DOCUME~1\B\DANEAP~1.\hidires C:\DOCUME~1\B\MENUST~1.\crazy girls.lnk C:\WINDOWS\dialerexe.ini C:\WINDOWS\exefld C:\WINDOWS\hosts C:\WINDOWS\svchost.exe C:\WINDOWS\system32\drivers\npf.sys C:\WINDOWS\system32\nvs2.inf C:\WINDOWS\system32\tzylvxf.dat C:\WINDOWS\system32\tzylvxf.exe C:\WINDOWS\system32\tzylvxf_nav.dat C:\WINDOWS\system32\tzylvxf_navps.dat ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\m_hook -------\NPF ((((((((((((((((((((((((( Files Created from 2007-07-17 to 2007-08-17 ))))))))))))))))))))))))))))))) 2007-08-17 19:29 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-08-15 13:14 360,448 --a------ C:\WINDOWS\system32\myodbc3.dll 2007-08-15 13:08 2007-08-15 13:06 2007-08-13 15:47 2007-08-11 22:09 2007-08-09 21:30 2007-08-09 19:19 2007-08-09 19:18 2007-08-09 19:18 2007-08-09 19:17 2007-08-03 18:19 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-17 20:05 42203424 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2007-08-17 20:05 1714720 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2007-08-17 20:03 571448 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx 2007-08-17 20:03 164840 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx 2007-08-17 20:01 --------- d-------- C:\Program Files\Kalendarz XP 2007-08-17 15:43 --------- d-------- C:\Program Files\eMule 2007-08-15 13:06 --------- d–h----- C:\Program Files\InstallShield Installation Information 2007-08-13 15:47 --------- d-------- C:\Program Files\Google 2007-08-11 22:23 --------- d-------- C:\Program Files\Picasa2 2007-08-09 20:27 --------- d-------- C:\Program Files\NAPI-PROJEKT 2007-07-15 18:00 --------- d-------- C:\Program Files\CDex_150 2007-07-15 12:51 --------- d-------- C:\DOCUME~1\B\DANEAP~1\Teleca 2007-07-15 12:43 --------- d-------- C:\DOCUME~1\B\DANEAP~1\Sony Ericsson 2007-07-15 12:42 --------- d-------- C:\Program Files\Sony Ericsson 2007-07-15 12:42 --------- d-------- C:\Program Files\Common Files\Teleca Shared 2007-07-15 12:42 --------- d-------- C:\Program Files\Common Files\Sony Ericsson Shared 2007-07-14 12:37 --------- d-------- C:\Program Files\Neostrada TP 2007-06-28 12:52 --------- d-------- C:\Program Files\Managed DirectX (0901) 2007-06-28 12:51 --------- d-------- C:\Program Files\FrostWire 2007-06-26 11:55 --------- d-------- C:\Program Files\Codec Pack - All In 1 2007-06-26 11:53 --------- d-------- C:\Program Files\Windows Media Connect 2 2007-05-14 17:48 477 --a------ C:\Program Files\INSTALL.LOG 2007-03-19 20:13 6422611 --a------ C:\Program Files\frostwire-4.13.1.6.windows.exe 2004-03-11 13:27 40960 --a------ C:\Program Files\Uninstall_CDS.exe 2007-05-04 10:09:29 6,144 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\10_credui.dll\Thumbs.db 2007-05-04 10:35:00 43,008 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\12_explorer.exe\Thumbs.db 2007-05-04 10:34:49 15,872 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\13_fontext.dll\Thumbs.db 2007-05-04 10:35:16 25,600 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\16_inetcplc.dll\Thumbs.db 2007-05-04 10:09:32 7,680 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\19_keymgr.dll\Thumbs.db 2007-05-04 10:09:38 32,768 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\20_logon.scr\Thumbs.db 2007-05-04 10:09:33 10,752 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\23_moricons.dll\Thumbs.db 2007-05-04 10:35:31 22,528 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\24_msgina.dll\Thumbs.db 2007-05-04 10:36:38 65,536 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\25_mshtml.dll\Thumbs.db 2007-05-04 10:35:24 13,824 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\26_mspaint.exe\Thumbs.db 2007-05-04 10:30:39 13,312 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\27_mstask.dll\Thumbs.db 2007-05-04 10:09:32 7,168 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\28_mstscax.dll\Thumbs.db 2007-05-04 12:08:59 10,240 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\29_mydocs.dll\Thumbs.db 2007-05-04 12:06:53 9,216 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\31_netid.dll\Thumbs.db 2007-05-04 10:09:31 9,216 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\32_netshell.dll\Thumbs.db 2007-05-04 12:04:38 22,528 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\33_newdev.dll\Thumbs.db 2007-05-04 10:09:34 5,632 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\34_notepad.exe\Thumbs.db 2007-05-04 10:36:30 17,920 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\35_ntshrui.dll\Thumbs.db 2007-05-04 10:09:34 8,704 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\37_occache.dll\Thumbs.db 2007-05-04 10:09:34 9,216 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\39_printui.dll\Thumbs.db 2007-05-04 10:29:54 9,728 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\3_browseui.dll\Thumbs.db 2007-05-04 10:09:34 9,216 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\40_rasdlg.dll\Thumbs.db 2007-05-04 12:09:15 26,624 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\41_regedit.exe\Thumbs.db 2007-05-04 10:09:35 8,192 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\42_shdoclc.dll\Thumbs.db 2007-05-04 10:09:35 7,680 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\43_shdocvw.dll\Thumbs.db 2007-05-04 12:06:20 105,472 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\44_shell32.dll\Thumbs.db 2007-05-04 10:09:48 7,680 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\45_shimgvw.dll\Thumbs.db 2007-05-04 10:09:48 5,632 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\46_shlwapi.dll\Thumbs.db 2007-05-04 10:09:48 5,632 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\47_sndrec32.exe\Thumbs.db 2007-05-04 10:09:49 7,168 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\48_sndvol32.exe\Thumbs.db 2007-05-04 12:08:43 45,568 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\49_stobject.dll\Thumbs.db 2007-05-04 10:29:58 9,728 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\4_cabview.dll\Thumbs.db 2007-05-04 10:09:49 7,680 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\51_sysocmgr.exe\Thumbs.db 2007-05-04 10:09:49 8,704 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\52_syssetup.dll\Thumbs.db 2007-05-04 12:07:52 27,648 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\53_taskmgr.exe\Thumbs.db 2007-05-04 10:09:50 7,680 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\55_themeui.dll\Thumbs.db 2007-05-04 10:09:50 9,216 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\57_url.dll\Thumbs.db 2007-05-04 10:09:50 7,168 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\58_urlmon.dll\Thumbs.db 2007-05-04 10:09:51 8,192 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\59_webcheck.dll\Thumbs.db 2007-05-04 10:30:00 6,656 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\5_calc.exe\Thumbs.db 2007-05-04 10:09:51 8,704 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\60_wiaacmgr.exe\Thumbs.db 2007-05-04 12:09:52 29,184 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\61_wininet.dll\Thumbs.db 2007-05-04 10:09:52 7,168 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\63_winsrv.dll\Thumbs.db 2007-05-04 10:32:39 102,912 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\64_xpsp2res.dll\Thumbs.db 2007-05-04 10:31:29 18,432 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\65_zipfldr.dll\Thumbs.db 2007-05-04 10:09:52 6,656 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\66_logonui.exe\Thumbs.db 2007-05-04 10:09:52 9,216 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\67_iexplore.exe\Thumbs.db 2007-05-04 12:05:24 18,432 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\68_msimn.exe\Thumbs.db 2007-05-04 10:29:36 48,128 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\69_msoeres.dll\Thumbs.db 2007-05-04 10:30:02 9,728 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\6_cleanmgr.exe\Thumbs.db 2007-05-04 10:31:56 16,896 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\70_wmplayer.exe\Thumbs.db 2007-05-04 10:31:49 145,920 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\71_wmploc.dll\Thumbs.db 2007-05-04 10:09:29 5,120 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\7_cmd.exe\Thumbs.db 2007-05-04 10:30:06 9,216 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\8_cmdial32.dll\Thumbs.db 2007-05-04 10:09:29 5,120 -csha-w C:\WINDOWS\BricoPacks\Vista Inspirat\ResFiles\9_console.dll\Thumbs.db ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “InCD”=“C:\Program Files\Ahead\InCD\InCD.exe” [2004-04-06 19:36] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2003-12-13 02:50] “ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe” [2004-04-17 12:41] “ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [2004-04-13 06:07] “RemoteControl”=“C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe” [2003-12-08 17:35] “SunJavaUpdateSched”=“C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe” [2004-06-03 23:05] “mouseElf”=“C:\PROGRA~1\GENIUS~1\GNETMOUS.EXE” [2003-05-13 11:41] “CHotkey”=“mHotkey.exe” [2002-07-05 17:37 C:\WINDOWS\mHotkey.exe] “Pop3trap.exe”=“C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe” [] “pccguide.exe”=“C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe” [] “PCCClient.exe”=“C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe” [] “ASUS Probe”=“C:\Program Files\ASUS\Probe\AsusProb.exe” [2002-12-06 17:07] “AGRSMMSG”=“AGRSMMSG.exe” [2004-06-29 10:06 C:\WINDOWS\AGRSMMSG.exe] “CnxDslTaskBar”=“c:\program files\zte corporation\zxdsl852\CnxDslTb.exe” [2005-07-21 22:52] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2005-07-21 08:33] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [2005-07-21 08:33] “Onet.pl AutoUpdate”=“C:\Program Files\Common Files\Onet.pl\AutoUpdate.exe” [] “aol”=“C:\Program Files\AOL\Active Virus Shield\avp.exe” [2006-05-30 13:13] “Picasa Media Detector”=“C:\Program Files\Picasa2\PicasaMediaDetector.exe” [2007-06-16 01:15] “Sony Ericsson PC Suite”=“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2007-05-28 10:14] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 09:44] “VD”="" [] “Komunikator”=“C:\PROGRA~1\Tlen.pl\tlen.exe” [] “AMP Agent”=“C:\Program Files\Common Files\ARS Company\Agent\Agent.exe” [] “MailScanner”=“C:\Program Files\MKS_VIR_2006\Mks_mail.exe” [] “SUPERAntiSpyware”=“C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe” [2007-08-11 22:03] “spyprodetector”=“C:\Program Files\Spyware Process Detector\spydetector.exe” [2007-06-15 20:50] “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-08-13 19:35] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Kalendarz XP.lnk - C:\Program Files\Kalendarz XP\Kalendarz.exe [2006-10-26 17:10:00] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 22:05:56] Microtek Scanner Finder.lnk - C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe [2004-12-18 21:59:16] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll SafeBoot registry key needs repairs. This machine cannot enter Safe Mode. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system] @=“Driver Group” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] @=“Service” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys] @=“Driver” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E967-E325-11CE-BFC1-08002BE10318}] @=“DiskDrive” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96A-E325-11CE-BFC1-08002BE10318}] @=“Hdc” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96B-E325-11CE-BFC1-08002BE10318}] @=“Keyboard” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E96F-E325-11CE-BFC1-08002BE10318}] @=“Mouse” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{4D36E97D-E325-11CE-BFC1-08002BE10318}] @=“System” [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @=“Volume” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “Tmntsrv”=2 (0x2) “PCCPFW”=2 (0x2) R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys R2 eventloganalyzer;ManageEngine EventLog Analyzer 4.0;C:\AdventNet\ME\EventLog\bin\wrapper.exe -s C:\AdventNet\ME\EventLog\bin\…\server\default\conf\wrapper.conf R2 spydetector;spydetector;??\C:\Program Files\Spyware Process Detector\spydetector.sys R3 CnxEtP;ZTE ZXDSL852 Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys R3 CnxEtU;ZTE ZXDSL852 Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys R3 CnxTgNW;ZTE ZXDSL852 WAN PPPoA Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgNW.sys R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys R3 genmcmn;Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gmfiltr.sys S3 FETNDIS;Sterownik NT karty VIA PCI 10/100Mb Fast Ethernet;C:\WINDOWS\system32\DRIVERS\fetnd5.sys S3 NTSIM;NTSIM;??\C:\WINDOWS\System32\ntsim.sys S3 SABProcEnum;SABProcEnum;??\C:\PROGRA~1\MOZILL~1\SABProcEnum.sys ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-08-17 20:07:41 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-08-17 20:14:46 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-08-17 20:14 — E O F —