ComboFix 07-06-11.3 - C:\Documents and Settings\mateo\Pulpit\ComboFix.exe “mateo” - 2007-06-12 17:36:00 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2007-05-12 to 2007-06-12 ))))))))))))))))))))))))))))))) 2007-06-12 18:32 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-06-12 18:32 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-06-12 18:32 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-06-12 18:31 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-06-12 18:31 524,567 --a------ C:\WINDOWS\system32\ati3d1ag.dll 2007-06-12 18:31 516,768 --a------ C:\WINDOWS\system32\ativvaxx.dll 2007-06-12 18:31 385,152 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys 2007-06-12 18:31 229,376 --a------ C:\WINDOWS\system32\ati2cqag.dll 2007-06-12 18:31 215,040 --a------ C:\WINDOWS\system32\ati2dvag.dll 2007-06-12 18:31 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys 2007-06-12 18:31 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll 2007-06-12 18:29 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-06-12 18:29 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-06-12 18:29 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-06-12 18:29 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-06-12 18:29 8,704 --a------ C:\WINDOWS\system32\batt.dll 2007-06-12 18:29 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-06-12 18:29 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-06-12 18:29 70,144 --a------ C:\WINDOWS\NOTEPAD.EXE 2007-06-12 18:29 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-06-12 18:29 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-06-12 18:29 69,552 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-06-12 18:29 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-06-12 18:29 5,632 --a------ C:\WINDOWS\system32\kbdro.dll 2007-06-12 18:29 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll 2007-06-12 18:29 5,120 --a------ C:\WINDOWS\system\SHELL.DLL 2007-06-12 18:29 33,376 --a------ C:\WINDOWS\system\COMMDLG.DLL 2007-06-12 18:29 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-06-12 18:29 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL 2007-06-12 18:29 19,200 --a------ C:\WINDOWS\system\TAPI.DLL 2007-06-12 18:29 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll 2007-06-12 18:29 15,360 --a------ C:\WINDOWS\TASKMAN.EXE 2007-06-12 18:29 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-06-12 18:29 127,008 --a------ C:\WINDOWS\system\MSVIDEO.DLL 2007-06-12 18:29 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys 2007-06-12 18:29 109,488 --a------ C:\WINDOWS\system\AVIFILE.DLL 2007-06-12 18:29 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:28 2007-06-12 18:28 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 2007-06-12 18:23 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-12 14:47:19 49,492 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-12 14:47:19 355,486 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-12 14:40:30 -------- d-----w C:\Program Files\Usługi online ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Cmaudio”=“cmicnfg.cpl” [] “AtiPTA”=“atiptaxx.exe” [2002-02-15 11:42 C:\WINDOWS\system32\atiptaxx.exe] “HydarVisionDesktopManager”="" [] “!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-05-30 14:30] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-05-10 16:36] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2007-05-30 14:29] *Newly Created Service* - AVGASCLN ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-12 17:36:44 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-12 17:37:20 — E O F —