ComboFix 07-11-08.1 - MarekL 2007-11-16 23:11:12.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.671 [GMT 1:00] Running from: C:\Documents and Settings\MarekL\Pulpit\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . E:\gamecopy.exe . ((((((((((((((((((((((((( Files Created from 2007-10-16 to 2007-11-16 ))))))))))))))))))))))))))))))) . 2007-11-16 23:10 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-11-15 23:49 2007-11-15 22:58 584,192 -----c— C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-11-15 22:11 2007-11-15 22:11 2007-11-14 21:12 2007-11-14 21:08 2007-11-14 21:08 2007-11-14 21:08 2007-11-14 21:08 27,662 --a------ C:\WINDOWS\system32\uninstall.exe 2007-11-14 20:55 2007-11-14 20:00 2007-11-14 20:00 2007-11-14 20:00 2007-11-14 20:00 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-11-14 20:00 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-11-14 20:00 60,273 --a------ C:\WINDOWS\system32\pthreadGC2.dll 2007-11-14 20:00 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-11-13 22:27 2007-11-13 20:31 2007-11-13 20:18 2007-11-13 20:18 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys 2007-11-13 20:18 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys 2007-11-13 19:22 26,496 --a–c— C:\WINDOWS\system32\dllcache\usbstor.sys 2007-11-12 22:53 2007-11-12 21:44 2007-11-12 21:33 2007-11-11 23:21 2007-11-11 23:05 2007-11-11 23:05 2007-11-11 23:05 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-11-11 23:05 15,104 --a–c— C:\WINDOWS\system32\dllcache\usbscan.sys 2007-11-11 23:01 2007-11-11 23:01 2007-11-11 23:01 2007-11-11 23:01 2007-11-11 23:01 2007-11-11 23:01 2007-11-11 23:00 212,480 --a------ C:\WINDOWS\pcdlib32.dll 2007-11-11 22:59 2007-11-11 22:59 212,480 --a------ C:\WINDOWS\system32\PCDLIB32.DLL 2007-11-11 22:59 77,312 --a------ C:\WINDOWS\system32\TWAIN_32.DLL 2007-11-11 22:58 389,180 --a------ C:\WINDOWS\system32\UCS32P.DLL 2007-11-11 22:58 339,968 --a------ C:\WINDOWS\system32\N067UFW.DLL 2007-11-11 22:58 36,864 --a------ C:\WINDOWS\system32\CNQU70.DLL 2007-11-11 22:23 2007-11-11 21:14 2007-11-11 21:05 1,802,240 --------- C:\WINDOWS\UNNMP.exe 2007-11-11 21:03 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-11-11 21:02 2007-11-11 21:02 1,814,528 --------- C:\WINDOWS\UNNeroVision.exe 2007-11-11 21:02 569,344 --a------ C:\WINDOWS\system32\imagr5.dll 2007-11-11 21:02 544,768 --a------ C:\WINDOWS\system32\imagx5.dll 2007-11-11 21:02 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-11-11 21:02 38,912 --a------ C:\WINDOWS\system32\picn20.dll 2007-11-11 21:01 2007-11-11 21:01 2007-11-11 21:01 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll 2007-11-11 20:59 2007-11-11 19:45 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-11-11 19:44 2007-11-11 19:43 2007-11-11 19:05 114,744 --a------ C:\WINDOWS\system32\hpzlnt04.dll 2007-11-11 19:04 2007-11-11 19:04 376 --a------ C:\WINDOWS\mozregistry.dat 2007-11-11 19:03 2007-11-11 18:50 2007-11-11 18:49 2007-11-11 18:44 60,928 --------- C:\WINDOWS\system32\logman.exe 2007-11-11 18:44 9,728 --------- C:\WINDOWS\system32\proxycfg.exe 2007-11-11 18:42 2007-11-11 18:37 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-11-11 18:34 2007-11-11 18:24 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr 2007-11-11 18:24 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-11-11 18:24 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-11-11 18:24 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-11-11 18:24 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-11-11 18:24 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-11-11 18:23 2007-11-11 18:23 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll 2007-11-11 18:23 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-11-11 18:23 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll 2007-11-11 18:23 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll 2007-11-11 18:23 3,790 --a------ C:\WINDOWS\unins000.dat 2007-11-11 17:06 24 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000003-00000000-00000005-00001102-00000004-005A1102}.dat 2007-11-11 17:06 24 --a------ C:\WINDOWS\system32\DVCState-{00000003-00000000-00000005-00001102-00000004-005A1102}.dat 2007-11-11 17:05 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll 2007-11-11 17:03 2007-11-11 17:03 70,688 --a------ C:\WINDOWS\system32\drivers\alcaudsl.sys 2007-11-11 17:03 53,600 --a------ C:\WINDOWS\system32\drivers\alcan5wn.sys 2007-11-11 17:03 5,606 --a------ C:\WINDOWS\system32\stci.dll 2007-11-11 17:03 5,280 --a------ C:\WINDOWS\system32\drivers\alcawh.sys 2007-11-11 17:03 3,968 --a------ C:\WINDOWS\system32\drivers\alcacr.sys 2007-11-11 17:02 2007-11-11 15:58 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys 2007-11-11 15:57 2007-11-11 15:57 2007-11-11 15:57 2007-11-11 15:57 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-15 21:11 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-11-13 19:32 --------- d-----w C:\Program Files\Common Files\Adobe 2007-11-11 15:59 --------- d-----w C:\Program Files\Creative 2007-11-11 15:59 --------- d-----w C:\Documents and Settings\MarekL\Dane aplikacji\Creative 2007-11-11 15:57 --------- d-----w C:\Documents and Settings\MarekL\Dane aplikacji\InterTrust 2007-11-11 15:51 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Creative 2007-11-11 15:43 --------- d-----w C:\Program Files\Intel 2007-11-11 15:34 --------- d-----w C:\Program Files\ATI Technologies 2007-11-11 15:33 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-11-11 15:29 --------- d-----w C:\Program Files\SEC 2007-11-11 15:10 --------- d-----w C:\Program Files\microsoft frontpage 2007-11-11 15:06 --------- d-----w C:\Program Files\Usługi online 2007-10-22 02:39 267,272 ----a-w C:\WINDOWS\system32\xactengine2_10.dll 2007-10-22 02:37 17,928 ----a-w C:\WINDOWS\system32\X3DAudio1_2.dll 2007-10-12 14:14 3,734,536 ----a-w C:\WINDOWS\system32\d3dx9_36.dll 2007-10-12 14:14 1,374,232 ----a-w C:\WINDOWS\system32\D3DCompiler_36.dll 2007-10-02 08:56 444,776 ----a-w C:\WINDOWS\system32\d3dx10_36.dll 2007-09-03 12:35 966,656 ----a-w C:\WINDOWS\system32\VSFilter.dll 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2003-09-12 21:10] “WINDVDPatch”=“CTHELPER.EXE” [2002-07-02 10:56 C:\WINDOWS\system32\CTHELPER.EXE] “UpdReg”=“C:\WINDOWS\UpdReg.EXE” [2000-05-11 01:00] “Jet Detection”=“C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe” [2001-11-29 01:00] “CTStartup”=“C:\Program Files\Creative\Splash Screen\CTEaxSpl.exe” [2001-12-20 01:00] “WooCnxMon”=“C:\PROGRA~1\NEOSTR~1\CnxMon.exe” [2003-10-16 19:07] “SpeedTouch USB Diagnostics”=“C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” [2004-01-26 11:38] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2003-10-16 19:07] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [2003-10-16 19:07] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-04-30 17:42] “HPDJ Taskbar Utility”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe” [2001-09-12 17:38] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50] “Omnipage”=“C:\Program Files\ScanSoft\OmniPageSE\opware32.exe” [2002-06-03 11:38] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “TaskTray”=“C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe” [2001-06-29 01:00] “TaskBar”=“C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe” [2002-05-08 01:00] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Color Calibration.lnk - C:\Program Files\SEC\MagicTune 2.5\GammaTray.exe [2007-11-11 16:29:44] Szybkie uruchamianie programu Microsoft Office OneNote 2003.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2003-08-06 21:23:32] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] @= *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-16 23:13:02 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run CTStartup = C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run???h???s???w? ?w???w???w4???.??w4???4???TA?s4???.???T:7???6~??6~.???U?6~??6~???X?a???C@???s.???s???8:7?A??s8:7??C@?x???`|?w???@ scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-16 23:13:58 . — E O F —