“Sensation22” - 2007-06-09 19:36:54 Dodatek Service Pack 2 NTFS ComboFix 07-06-3B - Running from: “C:\Documents and Settings\Basienka\Pulpit” ((((((((((((((((((((((((( Files Created from 2007-05-09 to 2007-06-09 ))))))))))))))))))))))))))))))) 2007-06-07 09:56 2007-06-05 09:38 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys 2007-06-05 09:38 81,920 -ra------ C:\WINDOWS\system32\VM305STI.dll 2007-06-05 09:38 61,440 -ra------ C:\WINDOWS\VM305_STI.EXE 2007-06-05 09:38 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys 2007-06-05 09:38 49,152 -ra------ C:\WINDOWS\amcap.exe 2007-06-05 09:38 392,316 -ra------ C:\WINDOWS\system32\drivers\usbVM305.sys 2007-06-05 09:38 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS 2007-06-05 09:38 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys 2007-06-05 09:38 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys 2007-06-05 09:38 114,688 -ra------ C:\WINDOWS\VM305Cap.exe 2007-06-05 09:38 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys 2007-06-05 09:38 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys 2007-06-05 09:37 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll 2007-06-04 15:05 10 --a------ C:\WINDOWS\popcinfo.dat 2007-06-04 14:48 2007-06-04 11:10 2007-06-03 15:04 2007-06-03 14:39 2007-06-03 14:22 2007-06-02 22:01 2007-06-02 18:29 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2007-06-02 18:28 2007-06-01 23:41 2007-06-01 23:20 2,916,352 --------- C:\WINDOWS\UNNMP.exe 2007-06-01 23:18 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-06-01 23:17 2007-06-01 23:16 24,064 --------- C:\WINDOWS\system32\msxml3a.dll 2007-06-01 23:16 2,977,792 --------- C:\WINDOWS\UNNeroVision.exe 2007-06-01 23:15 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2007-06-01 23:15 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2007-06-01 23:15 38,912 --------- C:\WINDOWS\system32\picn20.dll 2007-06-01 23:15 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2007-06-01 23:15 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2007-06-01 23:15 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-06-01 23:15 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2007-06-01 23:15 2007-06-01 23:15 2007-06-01 23:11 2007-06-01 23:01 1,156 --a------ C:\WINDOWS\mozver.dat 2007-06-01 22:53 2007-06-01 22:53 2007-06-01 22:53 2007-06-01 22:52 2007-06-01 22:34 2007-06-01 22:11 2007-06-01 22:08 2007-06-01 19:03 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-06-01 19:02 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-06-01 19:02 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll 2007-06-01 19:02 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2007-06-01 19:02 1,897,408 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys 2007-06-01 19:01 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-06-01 19:01 5,504 --a------ C:\WINDOWS\system32\drivers\intelide.sys 2007-06-01 19:01 42,368 --a------ C:\WINDOWS\system32\drivers\AGP440.SYS 2007-06-01 19:01 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys 2007-06-01 18:56 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-06-01 18:56 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-06-01 18:56 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-06-01 18:56 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-06-01 18:56 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-06-01 18:56 2007-06-01 18:56 2007-06-01 18:56 2007-06-01 18:56 2007-06-01 18:55 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-06-01 18:55 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-06-01 18:55 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-06-01 18:55 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-06-01 18:55 8,704 --a------ C:\WINDOWS\system32\batt.dll 2007-06-01 18:55 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-06-01 18:55 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-06-01 18:55 70,144 --a------ C:\WINDOWS\NOTEPAD.EXE 2007-06-01 18:55 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-06-01 18:55 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-06-01 18:55 69,552 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-06-01 18:55 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-06-01 18:55 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-06-01 18:55 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-06-01 18:55 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-06-01 18:55 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-06-01 18:55 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-06-01 18:55 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-06-01 18:55 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-06-01 18:55 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-06-01 18:55 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-06-01 18:55 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-06-01 18:55 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-06-01 18:55 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-06-01 18:55 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-06-01 18:55 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-06-01 18:55 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-06-01 18:55 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-06-01 18:55 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-06-01 18:55 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll 2007-06-01 18:55 5,632 --a------ C:\WINDOWS\system32\kbdro.dll 2007-06-01 18:55 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll 2007-06-01 18:55 5,120 --a------ C:\WINDOWS\system\SHELL.DLL 2007-06-01 18:55 33,376 --a------ C:\WINDOWS\system\COMMDLG.DLL 2007-06-01 18:55 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-01 15:42:26 67,078 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-01 15:42:26 435,978 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-01 15:11:15 -------- d-----w C:\Program Files\Usługi online 2007-04-18 16:14:32 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-03-17 13:45:36 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}=D:\Program Files\FlashGet\jccatch.dll [2007-05-16 11:03] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] {F156768E-81EF-470C-9057-481BA8380DBA}=D:\Program Files\FlashGet\getflash.dll [2007-05-16 07:05] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SunJavaUpdateSched”=“D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43] “SoundMan”=“SOUNDMAN.EXE” [2002-09-17 04:17 C:\WINDOWS\SOUNDMAN.EXE] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2004-08-23 14:49] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\GestMaj.exe” [2004-10-14 16:55] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 14:00] HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs* ************************************************************************** catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-09 19:40:18 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-09 19:41:56 — E O F —