ComboFix 07-11-19.3 - Olszewski 2006-11-21 20:22:56.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1652 [GMT 1:00] Running from: D:\Documents and Settings\Olszewski\Pulpit\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 ))))))))))))))))))))))))))))))) . 2007-11-21 20:06 2007-11-21 20:06 2007-11-21 19:30 2007-11-21 19:06 2007-11-21 19:06 1,060,864 --a------ D:\WINDOWS\system32\MFC71.dll 2007-11-21 19:06 93,264 --a------ D:\WINDOWS\system32\drivers\aswmon.sys 2007-11-21 19:06 26,624 --a------ D:\WINDOWS\system32\drivers\aavmker4.sys 2007-11-21 18:28 2007-11-21 18:25 2007-11-21 18:24 2007-11-20 21:02 2007-11-20 20:46 2007-11-20 20:40 2007-11-20 20:34 2007-11-20 19:07 2007-11-20 19:06 2007-11-19 17:23 2007-11-19 17:23 2007-11-19 17:23 29,704 --a------ D:\WINDOWS\system32\uxtuneup.dll 2007-11-18 16:24 2007-11-18 16:10 2007-11-18 15:37 2007-11-18 15:21 2007-11-17 21:05 2007-11-17 18:39 2007-11-17 18:37 2007-11-17 18:33 2007-11-17 15:42 2007-11-16 21:38 2007-11-11 16:16 2007-11-10 14:02 2007-11-09 19:47 2007-11-06 19:56 2007-11-06 19:51 2007-11-06 18:40 0 --a------ D:\WINDOWS\ativpsrm.bin 2007-11-05 22:21 2007-11-05 21:02 2007-11-05 19:46 3,497,832 --a------ D:\WINDOWS\system32\d3dx9_34.dll 2007-11-05 19:46 3,495,784 --a------ D:\WINDOWS\system32\d3dx9_33.dll 2007-11-05 19:46 3,426,072 --a------ D:\WINDOWS\system32\d3dx9_32.dll 2007-11-05 19:46 2,414,360 --a------ D:\WINDOWS\system32\d3dx9_31.dll 2007-11-05 19:46 1,124,720 --a------ D:\WINDOWS\system32\D3DCompiler_34.dll 2007-11-05 19:46 1,123,696 --a------ D:\WINDOWS\system32\D3DCompiler_33.dll 2007-11-05 19:46 443,752 --a------ D:\WINDOWS\system32\d3dx10_34.dll 2007-11-05 19:46 443,752 --a------ D:\WINDOWS\system32\d3dx10_33.dll 2007-11-05 16:14 2007-11-04 17:01 2007-11-04 16:51 2007-11-04 16:49 2007-11-04 16:49 2007-11-04 16:49 2007-11-04 16:49 1,757,184 --a------ D:\WINDOWS\system32\imagX7.dll 2007-11-04 16:49 802,816 --a------ D:\WINDOWS\system32\imagXRA7.dll 2007-11-04 16:49 497,296 --a------ D:\WINDOWS\system32\imagXpr7.dll 2007-11-04 16:49 368,640 --a------ D:\WINDOWS\system32\TwnLib4.dll 2007-11-04 16:49 258,048 --a------ D:\WINDOWS\system32\imagXR7.dll 2007-11-04 16:17 2007-11-04 16:17 2007-11-04 16:11 2007-11-04 15:24 289,144 --a------ D:\WINDOWS\system32\VCCLSID.exe 2007-11-04 15:24 288,417 --a------ D:\WINDOWS\system32\SrchSTS.exe 2007-11-04 15:24 51,200 --a------ D:\WINDOWS\system32\dumphive.exe 2007-11-04 15:24 25,600 --a------ D:\WINDOWS\system32\WS2Fix.exe 2007-11-04 15:24 2,034 --a------ D:\WINDOWS\system32\tmp.reg 2007-11-04 15:24 0 --a------ D:\WINDOWS\system32\tmp.txt 2007-11-03 21:53 0 --ah----- D:\WINDOWS\system32\sx.inf 2007-11-03 20:44 2007-11-02 23:25 2007-11-02 22:27 2007-10-31 17:41 2007-10-31 17:41 2007-10-31 17:41 65,536 --a------ D:\WINDOWS\system32\QuickTimeVR.qtx 2007-10-31 17:41 49,152 --a------ D:\WINDOWS\system32\QuickTime.qts 2007-10-31 17:38 2007-10-31 17:38 7,680 --a------ D:\WINDOWS\system32\ff_vfw.dll 2007-10-31 17:38 547 --a------ D:\WINDOWS\system32\ff_vfw.dll.manifest 2007-10-31 17:36 2007-10-28 12:55 2007-10-26 19:52 582,656 -----c— D:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-10-26 19:43 43,352 --a------ D:\WINDOWS\system32\wups2.dll 2007-10-26 19:43 38,232 --a------ D:\WINDOWS\system32\wucltui.dll.mui 2007-10-26 19:43 30,040 --a------ D:\WINDOWS\system32\wuaucpl.cpl.mui 2007-10-26 19:43 30,040 --a------ D:\WINDOWS\system32\wuapi.dll.mui 2007-10-26 19:43 21,336 --a------ D:\WINDOWS\system32\wuaueng.dll.mui 2007-10-22 18:25 2007-10-22 18:25 75,324 --a------ D:\WINDOWS\system32\EBPMON2.DLL 2007-10-22 18:25 64,000 --a------ D:\WINDOWS\system32\ECBTEG.DLL 2007-10-22 18:25 34,304 --a------ D:\WINDOWS\system32\EBPCHP.DLL 2007-10-22 18:25 182 --a------ D:\WINDOWS\system32\EBPPORT.DAT 2007-10-22 14:16 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-21 19:13 --------- d-----w D:\Program Files\eMule 2007-11-21 17:57 --------- d-----w D:\Program Files\AIMP2 2007-11-21 17:18 --------- d–h--w D:\Program Files\InstallShield Installation Information 2007-11-19 19:23 --------- d-----w D:\Documents and Settings\Olszewski\Dane aplikacji\uTorrent 2007-11-17 17:53 22,328 ----a-w D:\WINDOWS\system32\drivers\PnkBstrK.sys 2007-11-17 17:53 103,736 ----a-w D:\WINDOWS\system32\PnkBstrB.exe 2007-11-17 17:36 --------- d-----w D:\Program Files\FlashGet 2007-11-17 15:28 66,872 ----a-w D:\WINDOWS\system32\PnkBstrA.exe 2007-11-11 15:18 --------- d-----w D:\Program Files\Windows Media Connect 2 2007-11-11 15:18 --------- d-----w D:\Program Files\uTorrent 2007-11-06 18:52 --------- d-----w D:\Program Files\Common Files\InstallShield 2007-11-03 16:20 --------- d-----w D:\Program Files\NAPI-PROJEKT 2007-10-25 17:05 94,416 ----a-w D:\WINDOWS\system32\drivers\aswmon2.sys 2007-10-25 17:03 23,152 ----a-w D:\WINDOWS\system32\drivers\aswRdr.sys 2007-10-25 17:01 42,912 ----a-w D:\WINDOWS\system32\drivers\aswTdi.sys 2007-10-25 16:24 815,480 ----a-w D:\WINDOWS\system32\aswBoot.exe 2007-10-25 16:14 95,608 ----a-w D:\WINDOWS\system32\AvastSS.scr 2007-10-18 16:10 --------- d-----w D:\Program Files\TaskSwitchXP 2007-10-18 16:08 219,648 ----a-w D:\WINDOWS\system32\uxtheme.dll 2007-10-18 11:24 --------- d-----w D:\Documents and Settings\Olszewski\Dane aplikacji\Downloaded Installations 2007-10-18 11:19 --------- d-----w D:\Documents and Settings\Olszewski\Dane aplikacji\Autodesk 2007-10-18 11:18 --------- d-----w D:\Program Files\AutoCAD 2007 2007-10-18 11:00 --------- d-----w D:\Program Files\Common Files\Autodesk Shared 2007-10-18 10:57 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\Autodesk 2007-10-18 10:55 --------- d-----w D:\Program Files\Autodesk 2007-10-15 17:30 --------- d-----w D:\Program Files\Shareaza 2007-10-15 17:30 --------- d-----w D:\Documents and Settings\Olszewski\Dane aplikacji\Shareaza 2007-10-15 17:10 --------- d-----w D:\Program Files\Cinema Player 1.6 2007-10-15 16:16 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\FLEXnet 2007-10-15 16:08 --------- d-----w D:\Program Files\Common Files\Adobe 2007-10-15 16:01 --------- d-----w D:\Program Files\Common Files\Macrovision Shared 2007-10-15 15:20 --------- d-----w D:\Program Files\Microsoft.NET 2007-10-15 14:25 --------- d-----w D:\Program Files\ScanSoft 2007-10-15 14:24 --------- d-----w D:\Program Files\ivo 2007-10-15 14:24 --------- d-----w D:\Documents and Settings\Olszewski\Dane aplikacji\Expressivo 2007-10-15 14:12 737,280 ----a-w D:\WINDOWS\iun6002.exe 2007-10-15 14:12 --------- d-----w D:\Program Files\FireTune 2007-10-15 13:44 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\TuneUp Software 2007-10-15 10:09 98,304 ----a-w D:\WINDOWS\system32\CmdLineExt.dll 2007-10-15 09:46 685,816 ----a-w D:\WINDOWS\system32\drivers\sptd.sys 2007-10-14 19:17 --------- d-----w D:\Program Files\SlySoft 2007-10-14 19:12 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\Ahead 2007-10-14 18:54 --------- d-----w D:\Program Files\Total Commander 2007-10-14 18:29 --------- d-----w D:\Program Files\Ray Adams 2007-10-14 18:29 --------- d-----w D:\Program Files\Java 2007-10-14 18:29 --------- d-----w D:\Documents and Settings\Olszewski\Dane aplikacji\atitray 2007-10-14 18:28 --------- d-----w D:\Program Files\Common Files\Java 2007-10-14 16:30 --------- d-----w D:\Program Files\Lavalys 2007-10-14 16:27 360,576 ----a-w D:\WINDOWS\system32\drivers\tcpip.sys 2007-10-14 16:17 --------- d-----w D:\Documents and Settings\Olszewski\Dane aplikacji\Gadu-Gadu 2007-10-14 16:16 --------- d-----w D:\Program Files\Gadu-Gadu 2007-10-14 15:44 --------- d-----w D:\Program Files\Usługi online 2007-09-29 05:46 47,376 ----a-w D:\WINDOWS\system32\drivers\ativvpxx.vp 2007-09-29 03:21 9,854,976 ----a-w D:\WINDOWS\system32\atioglx2.dll 2007-09-29 03:07 356,352 ----a-w D:\WINDOWS\system32\ATIDEMGX.dll 2007-09-29 03:06 268,800 ----a-w D:\WINDOWS\system32\ati2dvag.dll 2007-09-29 03:05 2,456,064 ----a-w D:\WINDOWS\system32\drivers\ati2mtag.sys 2007-09-29 02:58 43,520 ----a-w D:\WINDOWS\system32\ati2edxx.dll 2007-09-29 02:58 26,112 ----a-w D:\WINDOWS\system32\Ati2mdxx.exe 2007-09-29 02:58 143,360 ----a-w D:\WINDOWS\system32\atipdlxx.dll 2007-09-29 02:58 122,880 ----a-w D:\WINDOWS\system32\Oemdspif.dll 2007-09-29 02:57 122,880 ----a-w D:\WINDOWS\system32\ati2evxx.dll 2007-09-29 02:56 483,328 ----a-w D:\WINDOWS\system32\ati2evxx.exe 2007-09-29 02:55 53,248 ----a-w D:\WINDOWS\system32\ATIDDC.DLL 2007-09-29 02:49 307,200 ----a-w D:\WINDOWS\system32\atiiiexx.dll 2007-09-29 02:47 3,130,720 ----a-w D:\WINDOWS\system32\ati3duag.dll 2007-09-29 02:47 172,032 ----a-w D:\WINDOWS\system32\atiok3x2.dll 2007-09-29 02:36 1,593,600 ----a-w D:\WINDOWS\system32\ativvaxx.dll 2007-09-29 02:23 5,435,392 ----a-w D:\WINDOWS\system32\atioglxx.dll 2007-09-29 02:22 376,832 ----a-w D:\WINDOWS\system32\atikvmag.dll 2007-09-29 02:20 17,408 ----a-w D:\WINDOWS\system32\atitvo32.dll 2007-09-29 02:19 49,152 ----a-w D:\WINDOWS\system32\drivers\ati2erec.dll 2007-09-29 02:14 499,712 ----a-w D:\WINDOWS\system32\ati2cqag.dll 2007-09-28 20:05 593,920 ------w D:\WINDOWS\system32\ati2sgag.exe 2007-09-19 14:26 39,768 ----a-w D:\WINDOWS\system32\drivers\pctmp.sys 2007-09-19 14:26 195,928 ----a-w D:\WINDOWS\system32\drivers\pctfw2.sys 2007-09-19 14:26 17,752 ----a-w D:\WINDOWS\system32\drivers\pctssipc.sys 2007-09-19 14:26 114,008 ----a-w D:\WINDOWS\system32\drivers\pctfw.sys 2007-08-21 06:26 683,520 ----a-w D:\WINDOWS\system32\inetcomm.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “AtiTrayTools”=“D:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe” [2007-05-22 10:04] “ctfmon.exe”=“D:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “TaskSwitchXP”=“D:\Program Files\TaskSwitchXP\TaskSwitchXP.exe” [2006-08-04 23:29] “RocketDock”=“D:\Program Files\RocketDock\RocketDock.exe” [2007-09-02 13:58] “DAEMON Tools”=“D:\Program Files\DAEMON Tools\daemon.exe” [2007-11-16 13:28] “SpeedX”=“D:\PROGRA~1\MyPortal\Speed-X\SpeedX.exe” [2006-06-27 13:11] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “High Definition Audio Property Page Shortcut”=“HDAShCut.exe” [2004-10-27 14:21 D:\WINDOWS\system32\HdAShCut.exe] “avast!”=“D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-10-25 17:20] “00PCTFW”=“D:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe” [2007-09-19 15:27] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“D:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoResolveTrack”= 0 (0x0) “NoFileAssociate”= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoSharedDocuments”= 00000000 “NoRecentDocsHistory”= 1 (0x1) “NoTrayItemsDisplay”= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] backup=D:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk] backup=D:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Przyspieszenie uruchomienia programu AutoCAD.lnk] path=D:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Przyspieszenie uruchomienia programu AutoCAD.lnk backup=D:\WINDOWS\pss\Przyspieszenie uruchomienia programu AutoCAD.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray] D:\Program Files\SlySoft\CloneCD\CloneCDTray.exe /s [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock] 2007-09-02 13:58 495616 --a------ D:\Program Files\RocketDock\RocketDock.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2007-09-25 00:11 132496 --a------ D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe R1 atitray;atitray;??\D:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys R1 pctfw2;pctfw2;??\D:\WINDOWS\system32\drivers\pctfw2.sys R1 pctmp;PC Tools Firewall Memory Protection Driver;D:\WINDOWS\system32\drivers\pctmp.sys R1 pctssipc;PC Tools Security Suite IPC Driver;D:\WINDOWS\system32\drivers\pctssipc.sys R2 UxTuneUp;TuneUp Theme Extension;D:\WINDOWS\System32\svchost.exe -k netsvcs S2 AVUpdate;ArcaBit Update Service;D:\PROGRA~1\ArcaBit\ARCAUP~1\update.exe S3 ps_drv;ps_drv;??\D:\Documents and Settings\Olszewski\ps_drv.sys S3 USBSTOR;Sterownik magazynu masowego USB;D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS S3 WimFltr;WimFltr;D:\WINDOWS\system32\DRIVERS\wimfltr.sys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp *Newly Created Service* - PCTOOLSFIREWALLPLUS . Contents of the ‘Scheduled Tasks’ folder “2007-11-19 16:23:44 D:\WINDOWS\Tasks\1-Click Maintenance.job” - D:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe . ************************************************************************** catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-19 20:24:03 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-19 20:24:30 . — E O F —