ComboFix 07-04-04.5 - Running from: “C:\Documents and Settings\Tomek\Pulpit\programy sciagniete” ((((((((((((((((((((((((((((((( Files Created from 2007-03-04 to 2007-04-04 )))))))))))))))))))))))))))))))))) 2007-04-04 12:49 2007-04-04 12:28 2007-04-04 12:19 41,473 -r-hs---- C:\WINDOWS\system\smsc.exe 2007-04-04 12:19 14,080 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys 2007-04-04 12:19 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2007-04-04 12:16 332 --a------ C:\WINDOWS\desctemp.dat 2007-04-04 11:51 2007-04-04 11:50 2007-04-04 11:50 2007-04-04 11:50 2007-04-04 11:50 2007-04-04 11:50 2007-04-04 11:48 2007-04-04 11:48 2007-04-04 11:44 2007-04-04 11:42 8,192 --a------ C:\WINDOWS\system32\tsbyuv.dll 2007-04-04 11:42 77,824 -ra------ C:\WINDOWS\system32\drivers\SioUi2k.dll 2007-04-04 11:42 63,488 -ra------ C:\WINDOWS\system32\drivers\wssbtr1f.sys 2007-04-04 11:42 57,344 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-04-04 11:42 51,169 -ra------ C:\WINDOWS\system32\drivers\OXSER.SYS 2007-04-04 11:42 50,688 --a------ C:\WINDOWS\system32\drivers\vfwwdm32.dll 2007-04-04 11:42 48,556 -ra------ C:\WINDOWS\system32\drivers\SktBt2k.sys 2007-04-04 11:42 48,076 -ra------ C:\WINDOWS\system32\drivers\Sio9502k.sys 2007-04-04 11:42 45,568 --a------ C:\WINDOWS\system32\iyuv_32.dll 2007-04-04 11:42 40,960 -ra------ C:\WINDOWS\system32\drivers\SCTray.exe 2007-04-04 11:42 135,040 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-04-04 11:41 82,148 --a------ C:\WINDOWS\system32\drivers\VcommMgr.sys 2007-04-04 11:41 7,680 --a------ C:\WINDOWS\system32\btinstall.dll 2007-04-04 11:41 61,312 --a------ C:\WINDOWS\system32\drivers\VComm.sys 2007-04-04 11:41 49,152 --a------ C:\WINDOWS\system32\btfunc.dll 2007-04-04 11:41 28,271 --a------ C:\WINDOWS\system32\drivers\BTHidMgr.sys 2007-04-04 11:41 23,000 --a------ C:\WINDOWS\system32\drivers\btcusb.sys 2007-04-04 11:41 20,480 --a------ C:\WINDOWS\system32\drivers\blueletaudio.sys 2007-04-04 11:41 182,880 --a------ C:\WINDOWS\system32\iuengine.dll 2007-04-04 11:41 148,830 --a------ C:\WINDOWS\system32\drivers\bcbthub.sys 2007-04-04 11:41 13,304 --a------ C:\WINDOWS\system32\drivers\BTNetFilter.sys 2007-04-04 11:41 116,021 --a------ C:\WINDOWS\system32\drivers\fw203x.sys 2007-04-04 11:41 11,860 --a------ C:\WINDOWS\system32\drivers\vbtenum.sys 2007-04-04 11:41 11,736 --a------ C:\WINDOWS\system32\drivers\VHIDMini.sys 2007-04-04 11:41 10,804 --a------ C:\WINDOWS\system32\drivers\BtNetDrv.sys 2007-04-04 11:41 2007-04-04 02:12 2007-04-03 23:03 2007-04-03 23:02 2007-04-03 23:01 83,968 --a------ C:\WINDOWS\system32\drivers\nabtsfec.sys 2007-04-03 23:01 52,096 --a------ C:\WINDOWS\system32\drivers\msdv.sys 2007-04-03 23:01 47,104 --a------ C:\WINDOWS\system32\wstdecod.dll 2007-04-03 23:01 354,816 --a------ C:\WINDOWS\system32\psisdecd.dll 2007-04-03 23:01 18,688 --a------ C:\WINDOWS\system32\drivers\wstcodec.sys 2007-04-03 23:01 16,896 --a------ C:\WINDOWS\system32\msyuv.dll 2007-04-03 23:01 16,384 --a------ C:\WINDOWS\system32\drivers\ccdecode.sys 2007-04-03 23:01 15,104 --a------ C:\WINDOWS\system32\drivers\mpe.sys 2007-04-03 23:01 14,976 --a------ C:\WINDOWS\system32\drivers\streamip.sys 2007-04-03 23:01 11,392 --a------ C:\WINDOWS\system32\drivers\bdasup.sys 2007-04-03 23:01 10,880 --a------ C:\WINDOWS\system32\drivers\slip.sys 2007-04-03 23:01 10,112 --a------ C:\WINDOWS\system32\drivers\ndisip.sys 2007-04-03 23:01 1,230,336 --a------ C:\WINDOWS\system32\msvidctl.dll 2007-04-03 23:00 2007-04-03 23:00 2007-04-03 22:58 2007-04-03 22:55 2007-04-03 21:52 2007-04-03 21:49 2007-04-03 21:29 2007-04-03 21:29 2007-04-03 18:05 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-04-03 18:00 2007-04-03 18:00 2007-04-03 17:59 2007-04-03 17:57 90,112 --a------ C:\WINDOWS\system32\AVASTSS.scr 2007-04-03 17:56 2007-04-03 17:53 94,424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-04-03 17:53 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-04-03 17:53 689,280 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-04-03 17:53 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-04-03 17:53 31,560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-04-03 17:53 23,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-04-03 17:28 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll 2007-04-03 17:28 2007-04-03 17:26 79,616 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys 2007-04-03 17:26 57,472 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys 2007-04-03 17:26 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys 2007-04-03 17:26 50,048 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-04-03 17:26 5,632 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-04-03 17:26 2,816 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys 2007-04-03 17:26 159,232 --a------ C:\WINDOWS\system32\drivers\kmixer.sys 2007-04-03 17:26 122,472 --a------ C:\WINDOWS\system32\drivers\aec.sys 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:23 2007-04-03 17:19 765,952 --a------ C:\WINDOWS\system\crlds3d.dll 2007-04-03 17:19 65,536 --a------ C:\WINDOWS\system32\Audio3D.dll 2007-04-03 17:19 65,536 --a------ C:\WINDOWS\system32\a3d.dll 2007-04-03 17:19 65,024 --a------ C:\WINDOWS\SOUNDMAN.EXE 2007-04-03 17:19 611,441 --a------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2007-04-03 17:19 5,867,008 --a------ C:\WINDOWS\system32\RTLCPL.EXE 2007-04-03 17:19 391,424 --a------ C:\WINDOWS\system32\drivers\ALCXSENS.SYS 2007-04-03 17:19 208,896 --------- C:\WINDOWS\alcupd.exe 2007-04-03 17:19 155,648 --a------ C:\WINDOWS\system32\RTLCPAPI.dll 2007-04-03 17:19 139,264 --------- C:\WINDOWS\alcrmv.exe 2007-04-03 17:19 1,032 --------- C:\WINDOWS\system32\drivers\alcxinit.dat 2007-04-03 17:19 2007-04-03 17:19 2007-04-03 17:19 2007-04-03 17:17 3,000 -ra------ C:\WINDOWS\system32\SetupNT.sys 2007-04-03 17:17 2007-04-03 17:17 2007-04-03 17:17 2007-04-03 17:17 2007-04-03 17:13 2007-04-03 16:43 2007-04-03 16:43 2007-04-03 16:40 2007-04-03 16:36 4,313 --a------ C:\WINDOWS\mozver.dat 2007-04-03 16:31 57,088 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-04-03 16:31 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-04-03 16:30 70,144 --a------ C:\WINDOWS\system32\usbui.dll 2007-04-03 16:30 23,070 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2007-04-03 16:29 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-04-03 16:29 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-04-03 16:29 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-04-03 16:29 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-04-03 16:29 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-04-03 16:29 71,680 --a------ C:\WINDOWS\system32\storprop.dll 2007-04-03 16:29 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-04-03 16:29 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-04-03 16:29 69,712 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-04-03 16:29 67,072 --a------ C:\WINDOWS\NOTEPAD.EXE 2007-04-03 16:29 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-04-03 16:29 6,656 --a------ C:\WINDOWS\system32\batt.dll 2007-04-03 16:29 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-04-03 16:29 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-04-03 16:29 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-04-03 16:29 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-04-03 16:29 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-04-03 16:29 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-04-03 16:29 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-04-03 16:29 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-04-03 16:29 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-04-03 16:29 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-04-03 16:29 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-04-03 16:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-04-03 16:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-04-03 16:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll 2007-04-03 16:29 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-04-03 16:29 5,632 --a------ C:\WINDOWS\system32\kbdro.dll 2007-04-03 16:29 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll 2007-04-03 16:29 5,120 --a------ C:\WINDOWS\system\SHELL.DLL 2007-04-03 16:29 33,376 --a------ C:\WINDOWS\system\COMMDLG.DLL 2007-04-03 16:29 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-04-03 16:29 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL 2007-04-03 16:29 19,200 --a------ C:\WINDOWS\system\TAPI.DLL 2007-04-03 16:29 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll 2007-04-03 16:29 15,360 --a------ C:\WINDOWS\TASKMAN.EXE 2007-04-03 16:29 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-04-03 16:29 127,008 --a------ C:\WINDOWS\system\MSVIDEO.DLL 2007-04-03 16:29 109,488 --a------ C:\WINDOWS\system\AVIFILE.DLL 2007-04-03 16:29 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll 2007-04-03 16:29 10,496 --a------ C:\WINDOWS\system32\drivers\irenum.sys 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:29 2007-04-03 16:28 2007-04-03 16:28 2007-04-03 16:27 2007-04-03 16:17 2007-04-03 16:17 2007-04-03 16:10 41,068 --------- C:\WINDOWS\system32\ActPanel.dll 2007-04-03 16:10 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll 2007-04-03 16:10 2007-04-03 16:10 2007-04-03 16:09 2007-04-03 16:09 2007-04-03 16:06 65,001 --a------ C:\WINDOWS\system32\clockz.exe 2007-04-03 16:06 2007-04-03 16:05 2007-04-03 15:59 0 --a------ C:\WINDOWS\nsreg.dat 2007-04-03 15:56 64,000 --a------ C:\WINDOWS\system32\drivers\e4ldr.sys 2007-04-03 15:56 50,007 --a------ C:\WINDOWS\system32\drivers\adildr.sys 2007-04-03 15:56 46,892 --a------ C:\WINDOWS\system32\ADADIX16.DLL 2007-04-03 15:56 4,981 --a------ C:\WINDOWS\system32\ADADIX2K.DLL 2007-04-03 15:56 24,576 --a------ C:\WINDOWS\enddisk32.exe 2007-04-03 15:56 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin 2007-04-03 15:56 176,128 --a------ C:\WINDOWS\autoclk.exe 2007-04-03 15:56 155,648 --a------ C:\WINDOWS\system32\adadix32.dll 2007-04-03 15:56 152,220 -r------- C:\WINDOWS\system32\drivers\L1E4I2.BIN 2007-04-03 15:56 152,220 -r------- C:\WINDOWS\system32\drivers\L1E4I1.BIN 2007-04-03 15:56 152,220 -r------- C:\WINDOWS\system32\drivers\L1E4I0.BIN 2007-04-03 15:56 152,132 -r------- C:\WINDOWS\system32\drivers\L1E4P2.BIN 2007-04-03 15:56 152,132 -r------- C:\WINDOWS\system32\drivers\L1E4P1.BIN 2007-04-03 15:56 152,132 -r------- C:\WINDOWS\system32\drivers\L1E4P0.BIN 2007-04-03 15:56 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P2.BIN 2007-04-03 15:56 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P1.BIN 2007-04-03 15:56 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9P0.BIN 2007-04-03 15:56 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I2.BIN 2007-04-03 15:56 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I1.BIN 2007-04-03 15:56 152,126 --a------ C:\WINDOWS\system32\drivers\L1E9I0.BIN 2007-04-03 15:56 152,036 --a------ C:\WINDOWS\system32\drivers\L1E4D2.BIN 2007-04-03 15:56 152,034 --a------ C:\WINDOWS\system32\drivers\L1E4D1.BIN 2007-04-03 15:56 152,034 --a------ C:\WINDOWS\system32\drivers\L1E4D0.BIN 2007-04-03 15:56 143,360 --a------ C:\WINDOWS\adiras.exe 2007-04-03 15:56 135,168 --a------ C:\WINDOWS\system32\unaddrv.exe 2007-04-03 15:56 127,456 --a------ C:\WINDOWS\system32\IPDETECT.EXE 2007-04-03 15:56 126,976 --a------ C:\WINDOWS\system32\coclassfast.dll 2007-04-03 15:56 126,489 --a------ C:\WINDOWS\system32\drivers\adiusbaw.sys 2007-04-03 15:56 116,992 --a------ C:\WINDOWS\system32\drivers\e4usbaw.sys 2007-04-03 15:56 2007-04-03 15:53 787,456 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys 2007-04-03 15:53 294,912 -ra------ C:\WINDOWS\system32\atiiiexx.dll 2007-04-03 15:53 151,552 -ra------ C:\WINDOWS\system32\ATIDEMGR.dll 2007-04-03 15:50 2007-04-03 15:49 516,096 --------- C:\WINDOWS\system32\ati2sgag.exe 2007-04-03 15:48 2007-04-03 15:48 2007-04-03 15:48 2007-04-03 15:48 2007-04-03 15:48 2007-04-03 15:47 23,040 -ra------ C:\WINDOWS\system32\drivers\GVCplDrv.sys 2007-04-03 15:45 2007-04-03 15:43 1,048,576 --ah----- C:\DOCUME~1\Tomek\NTUSER.DAT 2007-04-03 15:43 2007-04-03 15:43 2007-04-03 15:43 2007-04-03 15:43 2007-04-03 15:43 2007-04-03 15:43 2007-04-03 15:43 2007-04-03 15:43 2007-04-03 15:41 237,568 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT 2007-04-03 15:41 237,568 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT 2007-04-03 15:41 2007-04-03 15:41 2007-04-03 15:41 2007-04-03 15:41 2007-04-03 15:41 2007-04-03 15:41 2007-04-03 15:39 2007-04-03 15:39 2007-04-03 15:38 237,568 —h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT 2007-04-03 15:38 112,128 --a------ C:\WINDOWS\system32\mapi32.dll 2007-04-03 15:38 0 -rahs---- C:\MSDOS.SYS 2007-04-03 15:38 0 -rahs---- C:\IO.SYS 2007-04-03 15:38 0 --a------ C:\CONFIG.SYS 2007-04-03 15:38 0 --a------ C:\AUTOEXEC.BAT 2007-04-03 15:38 2007-04-03 15:38 2007-04-03 15:38 2007-04-03 15:37 40,960 --a------ C:\WINDOWS\system32\safrslv.dll 2007-04-03 15:37 39,424 --a------ C:\WINDOWS\system32\safrcdlg.dll 2007-04-03 15:37 33,792 --a------ C:\WINDOWS\system32\racpldlg.dll 2007-04-03 15:37 26,624 --a------ C:\WINDOWS\system32\safrdm.dll 2007-04-03 15:37 179,200 --a------ C:\WINDOWS\system32\qmgr.dll 2007-04-03 15:37 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll 2007-04-03 15:37 11,264 --a------ C:\WINDOWS\system32\atrace.dll 2007-04-03 15:37 2007-04-03 15:37 2007-04-03 15:37 2007-04-03 15:37 2007-04-03 15:36 90,624 --a------ C:\WINDOWS\system32\msoert2.dll 2007-04-03 15:36 9,728 --a------ C:\WINDOWS\system32\mstinit.exe 2007-04-03 15:36 81,920 --a------ C:\WINDOWS\system32\isign32.dll 2007-04-03 15:36 73,728 --a------ C:\WINDOWS\system32\ils.dll 2007-04-03 15:36 70,400 --a------ C:\WINDOWS\system32\drivers\sr.sys 2007-04-03 15:36 69,632 --a------ C:\WINDOWS\system32\icwdial.dll 2007-04-03 15:36 67,584 --a------ C:\WINDOWS\system32\acctres.dll 2007-04-03 15:36 65,536 --a------ C:\WINDOWS\system32\msconf.dll 2007-04-03 15:36 61,952 --a------ C:\WINDOWS\system32\srclient.dll 2007-04-03 15:36 61,440 --a------ C:\WINDOWS\system32\icwphbk.dll 2007-04-03 15:36 593,920 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-04-03 15:36 49,152 --a------ C:\WINDOWS\system32\inetres.dll 2007-04-03 15:36 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe 2007-04-03 15:36 32,384 --a------ C:\WINDOWS\system32\mnmdd.dll 2007-04-03 15:36 28,672 --a------ C:\WINDOWS\system32\isrdbg32.dll 2007-04-03 15:36 270,336 --a------ C:\WINDOWS\system32\inetcfg.dll 2007-04-03 15:36 253,440 --a------ C:\WINDOWS\system32\mstask.dll 2007-04-03 15:36 24,576 --a------ C:\WINDOWS\system32\nmmkcert.dll 2007-04-03 15:36 228,864 --a------ C:\WINDOWS\system32\msoeacct.dll 2007-04-03 15:36 219,136 --a------ C:\WINDOWS\system32\srrstr.dll 2007-04-03 15:36 21,856 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-04-03 15:36 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll 2007-04-03 15:36 159,744 --a------ C:\WINDOWS\system32\schedsvc.dll 2007-04-03 15:36 155,648 --a------ C:\WINDOWS\system32\srsvc.dll 2007-04-03 15:36 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll 2007-04-03 15:36 2007-04-03 15:36 2007-04-03 15:36 2007-04-03 15:36 2007-04-03 15:36 2007-04-03 15:35 99,328 --a------ C:\WINDOWS\system32\clipbrd.exe 2007-04-03 15:35 95,744 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-04-03 15:35 9,728 --a------ C:\WINDOWS\system32\xolehlp.dll 2007-04-03 15:35 9,728 --a------ C:\WINDOWS\system32\reset.exe 2007-04-03 15:35 89,600 --a------ C:\WINDOWS\system32\tscfgwmi.dll 2007-04-03 15:35 869,376 --a------ C:\WINDOWS\system32\msdtctm.dll 2007-04-03 15:35 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll 2007-04-03 15:35 83,968 --a------ C:\WINDOWS\system32\mtxoci.dll 2007-04-03 15:35 82,432 --a------ C:\WINDOWS\system32\comrepl.dll 2007-04-03 15:35 80,896 --a------ C:\WINDOWS\system32\charmap.exe 2007-04-03 15:35 8,704 --a------ C:\WINDOWS\system32\icaapi.dll 2007-04-03 15:35 73,864 --a------ C:\WINDOWS\system32\rdpwsx.dll 2007-04-03 15:35 73,216 --a------ C:\WINDOWS\system32\avwav.dll 2007-04-03 15:35 61,952 --a------ C:\WINDOWS\system32\rdshost.exe 2007-04-03 15:35 605,696 --a------ C:\WINDOWS\system32\getuname.dll 2007-04-03 15:35 6,144 --a------ C:\WINDOWS\system32\msdtc.exe 2007-04-03 15:35 583,168 --a------ C:\WINDOWS\system32\catsrvut.dll 2007-04-03 15:35 57,344 --a------ C:\WINDOWS\system32\sol.exe 2007-04-03 15:35 57,344 --a------ C:\WINDOWS\system32\licwmi.dll 2007-04-03 15:35 56,832 --a------ C:\WINDOWS\system32\remotepg.dll 2007-04-03 15:35 56,832 --a------ C:\WINDOWS\system32\colbact.dll 2007-04-03 15:35 55,808 --a------ C:\WINDOWS\system32\freecell.exe 2007-04-03 15:35 54,784 --a------ C:\WINDOWS\system32\msdtclog.dll 2007-04-03 15:35 54,272 --a------ C:\WINDOWS\system32\stclient.dll 2007-04-03 15:35 534,016 --a------ C:\WINDOWS\system32\spider.exe 2007-04-03 15:35 53,248 --a------ C:\WINDOWS\system32\servdeps.dll 2007-04-03 15:35 503,296 --a------ C:\WINDOWS\system32\mstscax.dll 2007-04-03 15:35 5,632 --a------ C:\WINDOWS\system32\write.exe 2007-04-03 15:35 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe 2007-04-03 15:35 495,616 --a------ C:\WINDOWS\system32\comuid.dll 2007-04-03 15:35 494,592 --a------ C:\WINDOWS\system32\hypertrm.dll 2007-04-03 15:35 468,480 --a------ C:\WINDOWS\system32\clbcatq.dll 2007-04-03 15:35 44,544 --a------ C:\WINDOWS\system32\hticons.dll 2007-04-03 15:35 41,984 --a------ C:\WINDOWS\system32\rdpclip.exe 2007-04-03 15:35 40,448 --a------ C:\WINDOWS\system32\tscupgrd.exe 2007-04-03 15:35 4,608 --a------ C:\WINDOWS\system32\rdpcfgex.dll 2007-04-03 15:35 4,096 --a------ C:\WINDOWS\system32\wuauserv.dll 2007-04-03 15:35 4,096 --a------ C:\WINDOWS\system32\mtxex.dll 2007-04-03 15:35 387,072 --a------ C:\WINDOWS\system32\mstsc.exe 2007-04-03 15:35 37,896 --a------ C:\WINDOWS\system32\drivers\termdd.sys 2007-04-03 15:35 360,960 --a------ C:\WINDOWS\system32\msdtcprx.dll 2007-04-03 15:35 35,328 --a------ C:\WINDOWS\system32\winchat.exe 2007-04-03 15:35 342,016 --a------ C:\WINDOWS\system32\mspaint.exe 2007-04-03 15:35 33,792 --a------ C:\WINDOWS\system32\regini.exe 2007-04-03 15:35 32,768 --a------ C:\WINDOWS\system32\cfgbkend.dll 2007-04-03 15:35 25,600 --a------ C:\WINDOWS\system32\comaddin.dll 2007-04-03 15:35 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll 2007-04-03 15:35 231,424 --a------ C:\WINDOWS\system32\avtapi.dll 2007-04-03 15:35 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe 2007-04-03 15:35 22,528 --a------ C:\WINDOWS\system32\msg.exe 2007-04-03 15:35 215,040 --a------ C:\WINDOWS\system32\catsrv.dll 2007-04-03 15:35 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll 2007-04-03 15:35 20,232 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys 2007-04-03 15:35 198,656 --a------ C:\WINDOWS\system32\termsrv.dll 2007-04-03 15:35 19,456 --a------ C:\WINDOWS\system32\qprocess.exe 2007-04-03 15:35 183,296 --a------ C:\WINDOWS\system32\accwiz.exe 2007-04-03 15:35 181,632 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys 2007-04-03 15:35 177,152 --a------ C:\WINDOWS\system32\cmprops.dll 2007-04-03 15:35 17,920 --a------ C:\WINDOWS\system32\tsshutdn.exe 2007-04-03 15:35 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe 2007-04-03 15:35 16,896 --a------ C:\WINDOWS\system32\mmfutil.dll 2007-04-03 15:35 16,384 --a------ C:\WINDOWS\system32\tskill.exe 2007-04-03 15:35 16,384 --a------ C:\WINDOWS\system32\rwinsta.exe 2007-04-03 15:35 16,384 --a------ C:\WINDOWS\system32\avmeter.dll 2007-04-03 15:35 151,040 --a------ C:\WINDOWS\system32\msdtcuiu.dll 2007-04-03 15:35 15,872 --a------ C:\WINDOWS\system32\logoff.exe 2007-04-03 15:35 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll 2007-04-03 15:35 15,360 --a------ C:\WINDOWS\system32\tsdiscon.exe 2007-04-03 15:35 15,360 --a------ C:\WINDOWS\system32\tscon.exe 2007-04-03 15:35 15,360 --a------ C:\WINDOWS\system32\shadow.exe 2007-04-03 15:35 147,456 --a------ C:\WINDOWS\system32\comsnap.dll 2007-04-03 15:35 14,848 --a------ C:\WINDOWS\system32\rdpsnd.dll 2007-04-03 15:35 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe 2007-04-03 15:35 134,656 --a------ C:\WINDOWS\system32\rdchost.dll 2007-04-03 15:35 131,072 --a------ C:\WINDOWS\system32\sessmgr.exe 2007-04-03 15:35 128,000 --a------ C:\WINDOWS\system32\mshearts.exe 2007-04-03 15:35 125,440 --a------ C:\WINDOWS\system32\sndrec32.exe 2007-04-03 15:35 12,288 --a------ C:\WINDOWS\system32\rdsaddin.exe 2007-04-03 15:35 119,808 --a------ C:\WINDOWS\system32\winmine.exe 2007-04-03 15:35 118,272 --a------ C:\WINDOWS\system32\mplay32.exe 2007-04-03 15:35 115,200 --a------ C:\WINDOWS\system32\calc.exe 2007-04-03 15:35 113,664 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-04-03 15:35 11,144 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys 2007-04-03 15:35 107,912 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys 2007-04-03 15:35 100,864 --a------ C:\WINDOWS\system32\clbcatex.dll 2007-04-03 15:35 1,225 --a------ C:\WINDOWS\system32\usrlogon.cmd 2007-04-03 15:35 1,139,200 --a------ C:\WINDOWS\system32\comsvcs.dll 2007-04-03 15:35 2007-04-03 15:35 2007-04-03 15:35 2007-04-03 15:35 2007-04-03 15:35 2007-04-03 15:35 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-04-04 12:18 68334 --a------ C:\WINDOWS\system32\perfc015.dat 2007-04-04 12:18 439194 --a------ C:\WINDOWS\system32\perfh015.dat 2007-04-03 16:29 62 --ahs---- C:\DOCUME~1\Tomek\DANEAP~1\desktop.ini 2007-04-03 15:37 -------- d-------- C:\Program Files\usˆugi online (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries legit default entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] @="" “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^ATI CATALYST System Tray.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ATI CATALYST System Tray.lnk” “backup”=“C:\WINDOWS\pss\ATI CATALYST System Tray.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\ATITEC~1\ATI.ACE\CLI.exe SystemTray” “item”=“ATI CATALYST System Tray” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^BlueSoleil.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\BlueSoleil.lnk” “backup”=“C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\IVTCOR~1\BLUESO~1\BLUESO~1.EXE " “item”=“BlueSoleil” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^DSLMON.lnk] “path”=“C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\DSLMON.lnk” “backup”=“C:\WINDOWS\pss\DSLMON.lnkCommon Startup” “location”=“Common Startup” “command”=“C:\PROGRA~1\SAGEM\SAGEMF~1\dslmon.exe " “item”=“DSLMON” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“cli” “hkey”=“HKLM” “command”=”“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“atiptaxx” “hkey”=“HKLM” “command”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Internet Explorer] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“iexplore” “hkey”=“HKLM” “command”=“C:\WINDOWS\System32\iexplore.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“PDVDServ” “hkey”=“HKLM” “command”="“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“Application Launcher” “hkey”=“HKLM” “command”="“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“SOUNDMAN” “hkey”=“HKLM” “command”=“SOUNDMAN.EXE” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“CnxMon” “hkey”=“HKLM” “command”=“C:\PROGRA~1\NEOSTR~1\CnxMon.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“TaskbarIcon” “hkey”=“HKLM” “command”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“Watch” “hkey”=“HKLM” “command”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” “inimapping”=“0” [HKEY_USERS.default\software\microsoft\windows\currentversion\run] @="" “ATICCC”="“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages REG_MULTI_SZ msv1_0\0\0 Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages REG_MULTI_SZ scecli\0\0 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 ******************************************************************** catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-04-04 13:36:52 C:\ComboFix-quarantined-files.txt … 07-04-04 13:36