quote]“kojot” - 2007-05-07 20:51:41 Dodatek Service Pack 2 ComboFix 07-05.07.3.V - Running from: “C:\Documents and Settings\kojot” ((((((((((((((((((((((((((((((( Files Created from 2007-04-07 to 2007-05-07 )))))))))))))))))))))))))))))))))) 2007-05-07 20:46 75,932 --a------ C:\WINDOWS\system32\drivers\klick.dat 2007-05-07 20:46 74,396 --a------ C:\WINDOWS\system32\drivers\klin.dat 2007-05-07 20:45 6,176 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2007-05-07 20:45 288 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2007-05-07 20:45 2007-05-07 20:45 2007-05-07 20:44 2007-05-07 20:25 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-05-07 16:37 2007-05-07 16:15 2007-05-07 16:06 143,552 --a------ C:\DOCUME~1\kojot\archives.dat 2007-05-07 15:01 2007-05-07 01:04 309,616 --a------ C:\WINDOWS\system32\wmv8dmod.dll 2007-05-07 01:04 2007-05-07 00:04 2007-05-06 18:33 271,360 --a------ C:\WINDOWS\system32\drivers\atksgt.sys 2007-05-06 18:33 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-05-06 18:33 18,048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys 2007-05-06 18:32 2007-05-06 18:32 2007-05-06 18:32 2007-05-06 18:31 2007-05-05 15:38 2007-05-05 15:37 2007-05-05 01:03 228,863 --a------ C:\WINDOWS\Alcohol_Toolbar_Uninstaller_2484.exe 2007-05-05 01:03 2007-05-05 01:02 2007-05-05 01:00 2007-05-05 00:51 2007-05-05 00:48 639,224 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-05-04 22:35 2007-05-04 20:51 2007-05-04 20:35 2007-05-04 20:33 2007-05-04 20:03 2007-05-04 19:34 2007-05-04 19:33 2007-05-04 19:31 2007-05-04 19:27 2007-05-04 19:26 2007-05-04 17:13 2007-05-04 16:55 2,977,792 --------- C:\WINDOWS\UNNMP.exe 2007-05-04 16:55 2007-05-04 16:54 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-05-04 16:54 2007-05-04 16:52 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2007-05-04 16:52 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2007-05-04 16:52 38,912 --------- C:\WINDOWS\system32\picn20.dll 2007-05-04 16:52 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2007-05-04 16:52 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2007-05-04 16:52 24,064 --------- C:\WINDOWS\system32\msxml3a.dll 2007-05-04 16:52 2,977,792 --------- C:\WINDOWS\UNNeroVision.exe 2007-05-04 16:52 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-05-04 16:52 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2007-05-04 16:52 2007-05-04 16:52 2007-05-04 16:52 2007-05-04 16:10 2007-05-04 12:24 2007-05-03 23:55 2007-05-03 22:48 2007-05-03 22:48 2007-05-03 18:14 2007-05-03 16:10 2007-05-03 00:18 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-05-03 00:08 2007-05-02 22:27 2007-05-02 20:42 2007-05-01 23:05 2007-05-01 19:44 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-05-01 19:44 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-05-01 19:06 2007-05-01 16:45 2007-04-30 22:12 2007-04-30 22:11 2007-04-30 16:14 2007-04-30 15:57 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-04-30 15:57 1,310,720 --ah----- C:\DOCUME~1\robert\NTUSER.DAT 2007-04-30 15:57 2007-04-30 15:57 2007-04-30 15:57 2007-04-30 15:57 2007-04-30 15:57 2007-04-30 15:57 2007-04-30 15:57 2007-04-30 15:57 2007-04-30 15:03 11,470,608 --a------ C:\avgas-setup-7.5.0.50.exe 2007-04-30 13:56 2007-04-30 11:29 2007-04-30 11:11 2007-04-30 00:44 2007-04-29 16:52 2007-04-29 15:58 2007-04-29 15:52 2007-04-29 15:32 2007-04-29 13:22 2007-04-29 13:11 2007-04-29 13:10 75,264 --a------ C:\WINDOWS\system32\MACDec.dll 2007-04-29 13:10 679,936 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-04-29 13:10 45,568 --a------ C:\WINDOWS\system32\huffyuv.dll 2007-04-29 13:10 446,464 --a------ C:\WINDOWS\system32\vp31vfw.dll 2007-04-29 13:10 438,272 --a------ C:\WINDOWS\system32\vp6vfw.dll 2007-04-29 13:10 421,888 --a------ C:\WINDOWS\system32\OpenQuicktimeLib.dll 2007-04-29 13:10 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll 2007-04-29 13:10 286,720 --a------ C:\WINDOWS\system32\3ivxVfWCodec.dll 2007-04-29 13:10 2,024,448 --a------ C:\WINDOWS\system32\divx.dll 2007-04-29 13:10 155,648 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-04-29 13:10 1,415,680 --a------ C:\WINDOWS\system32\WMV9VCM.dll 2007-04-29 13:10 1,024,000 --a------ C:\WINDOWS\system32\3ivx.dll 2007-04-29 13:09 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll 2007-04-29 13:09 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll 2007-04-29 13:09 245,408 --a------ C:\WINDOWS\system32\unicows.dll 2007-04-29 13:09 19,968 --a------ C:\WINDOWS\system32\cpuinf32.dll 2007-04-29 13:09 2007-04-29 12:50 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys 2007-04-29 12:50 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-04-29 12:50 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys 2007-04-29 12:50 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-04-29 12:50 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys 2007-04-29 12:49 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys 2007-04-29 12:49 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys 2007-04-29 12:49 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-04-29 12:49 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2007-04-29 12:49 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys 2007-04-29 12:49 4,096 --a------ C:\WINDOWS\system32\ksuser.dll 2007-04-29 12:49 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys 2007-04-29 12:49 171,776 --a------ C:\WINDOWS\system32\drivers\kmixer.sys 2007-04-29 12:49 15,872 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-04-29 12:49 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-04-29 12:49 141,824 -ra------ C:\WINDOWS\system32\drivers\viahduaa.sys 2007-04-29 12:48 331,184 --------- C:\WINDOWS\system32\difxapi.dll 2007-04-29 12:47 7,040 -ra------ C:\WINDOWS\system32\ntsim.sys 2007-04-29 12:47 42,496 -ra------ C:\WINDOWS\system32\drivers\fetnd5b.sys 2007-04-29 12:46 2007-04-29 12:44 9,728 -ra------ C:\WINDOWS\system32\drivers\videX32.sys 2007-04-29 12:44 11,264 -ra------ C:\WINDOWS\system32\drivers\xfilt.sys 2007-04-29 12:44 2007-04-29 12:44 2007-04-29 12:42 98,512 --a------ C:\WINDOWS\GREUninstall.exe 2007-04-29 12:42 9,602 --a------ C:\WINDOWS\mozver.dat 2007-04-29 12:42 335 --a------ C:\WINDOWS\nsreg.dat 2007-04-29 12:42 2007-04-29 12:42 2007-04-29 12:42 2007-04-29 12:23 520,192 --------- C:\WINDOWS\system32\ati2sgag.exe 2007-04-29 12:23 2007-04-29 12:23 2007-04-29 12:22 2007-04-29 12:22 2007-04-29 12:13 20,640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys 2007-04-29 12:12 2007-04-29 12:12 2007-04-29 12:11 24,072 --a------ C:\WINDOWS\system32\uxtuneup.dll 2007-04-29 12:11 2007-04-29 12:11 2007-04-29 12:10 2007-04-29 12:10 2007-04-29 12:07 2007-04-29 11:51 2007-04-29 11:45 15,399 -ra------ C:\WINDOWS\system32\drivers\netmotcm.sys 2007-04-29 11:44 3,145,728 --------- C:\DOCUME~1\kojot\ntuser.dat 2007-04-29 11:44 2007-04-29 11:44 2007-04-29 11:44 2007-04-29 11:44 2007-04-29 11:44 2007-04-29 11:44 2007-04-29 11:44 2007-04-29 11:44 2007-04-29 11:43 233,472 --a------ C:\DOCUME~1\LOCALS~1\NTUSER.DAT 2007-04-29 11:43 229,376 --a------ C:\DOCUME~1\NETWOR~1\NTUSER.DAT 2007-04-29 11:43 2007-04-29 11:43 2007-04-29 11:43 2007-04-29 11:43 2007-04-29 11:43 2007-04-29 11:43 2007-04-29 11:39 229,376 —h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT 2007-04-29 11:39 2007-04-29 11:39 2007-04-29 11:38 112,128 --a------ C:\WINDOWS\system32\mapi32.dll 2007-04-29 11:38 0 -rahs---- C:\MSDOS.SYS 2007-04-29 11:38 0 -rahs---- C:\IO.SYS 2007-04-29 11:38 0 --a------ C:\CONFIG.SYS 2007-04-29 11:38 0 --a------ C:\AUTOEXEC.BAT 2007-04-29 11:38 2007-04-29 11:37 11,264 --a------ C:\WINDOWS\system32\atrace.dll 2007-04-29 11:37 2007-04-29 11:37 2007-04-29 11:37 2007-04-29 11:37 2007-04-29 11:37 2007-04-29 11:36 86,016 --a------ C:\WINDOWS\system32\isign32.dll 2007-04-29 11:36 81,920 --a------ C:\WINDOWS\system32\ils.dll 2007-04-29 11:36 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll 2007-04-29 11:36 73,728 --a------ C:\WINDOWS\system32\icwdial.dll 2007-04-29 11:36 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys 2007-04-29 11:36 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll 2007-04-29 11:36 69,632 --a------ C:\WINDOWS\system32\msconf.dll 2007-04-29 11:36 678,400 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-04-29 11:36 67,584 --a------ C:\WINDOWS\system32\srclient.dll 2007-04-29 11:36 67,584 --a------ C:\WINDOWS\system32\acctres.dll 2007-04-29 11:36 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll 2007-04-29 11:36 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll 2007-04-29 11:36 49,664 --a------ C:\WINDOWS\system32\inetres.dll 2007-04-29 11:36 45,568 --a------ C:\WINDOWS\system32\safrslv.dll 2007-04-29 11:36 431,616 --a------ C:\WINDOWS\system32\wuapi.dll 2007-04-29 11:36 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll 2007-04-29 11:36 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll 2007-04-29 11:36 382,464 --a------ C:\WINDOWS\system32\qmgr.dll 2007-04-29 11:36 36,864 --a------ C:\WINDOWS\system32\wups.dll 2007-04-29 11:36 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll 2007-04-29 11:36 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe 2007-04-29 11:36 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll 2007-04-29 11:36 29,696 --a------ C:\WINDOWS\system32\safrdm.dll 2007-04-29 11:36 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll 2007-04-29 11:36 278,528 --a------ C:\WINDOWS\system32\mstask.dll 2007-04-29 11:36 278,528 --a------ C:\WINDOWS\system32\inetcfg.dll 2007-04-29 11:36 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll 2007-04-29 11:36 240,128 --a------ C:\WINDOWS\system32\srrstr.dll 2007-04-29 11:36 22,528 --a------ C:\WINDOWS\system32\fltMc.exe 2007-04-29 11:36 192,000 --a------ C:\WINDOWS\system32\schedsvc.dll 2007-04-29 11:36 184,320 --a------ C:\WINDOWS\system32\wuaueng1.dll 2007-04-29 11:36 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll 2007-04-29 11:36 171,008 --a------ C:\WINDOWS\system32\srsvc.dll 2007-04-29 11:36 168,960 --a------ C:\WINDOWS\system32\wuauclt1.exe 2007-04-29 11:36 16,896 --a------ C:\WINDOWS\system32\fltlib.dll 2007-04-29 11:36 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll 2007-04-29 11:36 124,800 --a------ C:\WINDOWS\system32\drivers\fltMgr.sys 2007-04-29 11:36 120,320 --a------ C:\WINDOWS\system32\wuweb.dll 2007-04-29 11:36 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll 2007-04-29 11:36 12,288 --a------ C:\WINDOWS\system32\mstinit.exe 2007-04-29 11:36 113,664 --a------ C:\WINDOWS\system32\wucltui.dll 2007-04-29 11:36 112,128 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-04-29 11:36 105,984 --a------ C:\WINDOWS\system32\msoert2.dll 2007-04-29 11:36 1,134,592 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-04-29 11:36 2007-04-29 11:36 2007-04-29 11:36 2007-04-29 11:36 2007-04-29 11:36 2007-04-29 11:36 2007-04-29 11:35 5,632 --a------ C:\WINDOWS\system32\write.exe 2007-04-29 11:35 21,856 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-04-29 11:35 2007-04-29 11:35 2007-04-29 11:35 2007-04-29 11:34 949,248 --a------ C:\WINDOWS\system32\msdtctm.dll 2007-04-29 11:34 94,720 --a------ C:\WINDOWS\system32\tscfgwmi.dll 2007-04-29 11:34 90,112 --a------ C:\WINDOWS\system32\mtxoci.dll 2007-04-29 11:34 9,728 --a------ C:\WINDOWS\system32\reset.exe 2007-04-29 11:34 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll 2007-04-29 11:34 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll 2007-04-29 11:34 82,432 --a------ C:\WINDOWS\system32\comrepl.dll 2007-04-29 11:34 80,896 --a------ C:\WINDOWS\system32\charmap.exe 2007-04-29 11:34 73,216 --a------ C:\WINDOWS\system32\avwav.dll 2007-04-29 11:34 67,072 --a------ C:\WINDOWS\system32\rdshost.exe 2007-04-29 11:34 655,360 --a------ C:\WINDOWS\system32\mstscax.dll 2007-04-29 11:34 628,224 --a------ C:\WINDOWS\system32\catsrvut.dll 2007-04-29 11:34 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe 2007-04-29 11:34 62,464 --a------ C:\WINDOWS\system32\colbact.dll 2007-04-29 11:34 605,696 --a------ C:\WINDOWS\system32\getuname.dll 2007-04-29 11:34 60,928 --a------ C:\WINDOWS\system32\remotepg.dll 2007-04-29 11:34 6,144 --a------ C:\WINDOWS\system32\msdtc.exe 2007-04-29 11:34 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll 2007-04-29 11:34 58,880 --a------ C:\WINDOWS\system32\licwmi.dll 2007-04-29 11:34 57,344 --a------ C:\WINDOWS\system32\sol.exe 2007-04-29 11:34 56,320 --a------ C:\WINDOWS\system32\servdeps.dll 2007-04-29 11:34 55,808 --a------ C:\WINDOWS\system32\freecell.exe 2007-04-29 11:34 540,160 --a------ C:\WINDOWS\system32\comuid.dll 2007-04-29 11:34 54,272 --a------ C:\WINDOWS\system32\stclient.dll 2007-04-29 11:34 539,136 --a------ C:\WINDOWS\system32\spider.exe 2007-04-29 11:34 501,248 --a------ C:\WINDOWS\system32\clbcatq.dll 2007-04-29 11:34 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe 2007-04-29 11:34 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe 2007-04-29 11:34 44,544 --a------ C:\WINDOWS\system32\hticons.dll 2007-04-29 11:34 425,472 --a------ C:\WINDOWS\system32\msdtcprx.dll 2007-04-29 11:34 408,576 --a------ C:\WINDOWS\system32\mstsc.exe 2007-04-29 11:34 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys 2007-04-29 11:34 4,608 --a------ C:\WINDOWS\system32\rdpcfgex.dll 2007-04-29 11:34 4,096 --a------ C:\WINDOWS\system32\mtxex.dll 2007-04-29 11:34 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll 2007-04-29 11:34 35,328 --a------ C:\WINDOWS\system32\winchat.exe 2007-04-29 11:34 349,696 --a------ C:\WINDOWS\system32\hypertrm.dll 2007-04-29 11:34 345,088 --a------ C:\WINDOWS\system32\mspaint.exe 2007-04-29 11:34 33,792 --a------ C:\WINDOWS\system32\regini.exe 2007-04-29 11:34 296,448 --a------ C:\WINDOWS\system32\termsrv.dll 2007-04-29 11:34 25,600 --a------ C:\WINDOWS\system32\comaddin.dll 2007-04-29 11:34 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll 2007-04-29 11:34 231,424 --a------ C:\WINDOWS\system32\avtapi.dll 2007-04-29 11:34 229,888 --a------ C:\WINDOWS\system32\catsrv.dll 2007-04-29 11:34 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe 2007-04-29 11:34 22,528 --a------ C:\WINDOWS\system32\msg.exe 2007-04-29 11:34 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys 2007-04-29 11:34 20,992 --a------ C:\WINDOWS\system32\qprocess.exe 2007-04-29 11:34 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll 2007-04-29 11:34 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys 2007-04-29 11:34 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll 2007-04-29 11:34 187,904 --a------ C:\WINDOWS\system32\cmprops.dll 2007-04-29 11:34 187,904 --a------ C:\WINDOWS\system32\accwiz.exe 2007-04-29 11:34 17,920 --a------ C:\WINDOWS\system32\tsshutdn.exe 2007-04-29 11:34 17,920 --a------ C:\WINDOWS\system32\mmfutil.dll 2007-04-29 11:34 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe 2007-04-29 11:34 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll 2007-04-29 11:34 16,384 --a------ C:\WINDOWS\system32\tskill.exe 2007-04-29 11:34 16,384 --a------ C:\WINDOWS\system32\rwinsta.exe 2007-04-29 11:34 16,384 --a------ C:\WINDOWS\system32\avmeter.dll 2007-04-29 11:34 15,872 --a------ C:\WINDOWS\system32\logoff.exe 2007-04-29 11:34 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll 2007-04-29 11:34 15,360 --a------ C:\WINDOWS\system32\tsdiscon.exe 2007-04-29 11:34 15,360 --a------ C:\WINDOWS\system32\tscon.exe 2007-04-29 11:34 15,360 --a------ C:\WINDOWS\system32\shadow.exe 2007-04-29 11:34 147,968 --a------ C:\WINDOWS\system32\rdchost.dll 2007-04-29 11:34 147,456 --a------ C:\WINDOWS\system32\comsnap.dll 2007-04-29 11:34 141,824 --a------ C:\WINDOWS\system32\sessmgr.exe 2007-04-29 11:34 139,400 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys 2007-04-29 11:34 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe 2007-04-29 11:34 132,608 --a------ C:\WINDOWS\system32\sndrec32.exe 2007-04-29 11:34 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe 2007-04-29 11:34 128,000 --a------ C:\WINDOWS\system32\mshearts.exe 2007-04-29 11:34 124,928 --a------ C:\WINDOWS\system32\mplay32.exe 2007-04-29 11:34 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys 2007-04-29 11:34 119,808 --a------ C:\WINDOWS\system32\winmine.exe 2007-04-29 11:34 115,200 --a------ C:\WINDOWS\system32\calc.exe 2007-04-29 11:34 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll 2007-04-29 11:34 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll 2007-04-29 11:34 11,264 --a------ C:\WINDOWS\system32\icaapi.dll 2007-04-29 11:34 103,424 --a------ C:\WINDOWS\system32\clipbrd.exe 2007-04-29 11:34 1,251,840 --a------ C:\WINDOWS\system32\comsvcs.dll 2007-04-29 11:34 1,225 --a------ C:\WINDOWS\system32\usrlogon.cmd 2007-04-29 11:34 2007-04-29 11:34 2007-04-29 11:34 2007-04-29 11:32 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-04-29 11:31 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-04-29 11:31 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-04-29 11:31 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys 2007-04-29 11:30 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS 2007-04-29 11:29 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-04-29 11:29 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-04-29 11:29 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-04-29 11:29 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-04-29 11:29 8,704 --a------ C:\WINDOWS\system32\batt.dll 2007-04-29 11:29 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-04-29 11:29 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-04-29 11:29 70,144 --a------ C:\WINDOWS\NOTEPAD.EXE 2007-04-29 11:29 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-04-29 11:29 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-04-29 11:29 69,552 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-04-29 11:29 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-04-29 11:29 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-04-29 11:29 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-04-29 11:29 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-04-29 11:29 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-04-29 11:29 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-04-29 11:29 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-04-29 11:29 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-04-29 11:29 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-04-29 11:29 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-04-29 11:29 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-04-29 11:29 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-04-29 11:29 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-04-29 11:29 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-04-29 11:29 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-04-29 11:29 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-04-29 11:29 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-04-29 11:29 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-04-29 11:29 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-04-29 11:29 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-04-29 11:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-04-29 11:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-04-29 11:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll 2007-04-29 11:29 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-04-29 11:29 5,632 --a------ C:\WINDOWS\system32\kbdro.dll 2007-04-29 11:29 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll 2007-04-29 11:29 5,120 --a------ C:\WINDOWS\system\SHELL.DLL 2007-04-29 11:29 33,376 --a------ C:\WINDOWS\system\COMMDLG.DLL 2007-04-29 11:29 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-04-29 11:29 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL 2007-04-29 11:29 19,200 --a------ C:\WINDOWS\system\TAPI.DLL 2007-04-29 11:29 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll 2007-04-29 11:29 15,360 --a------ C:\WINDOWS\TASKMAN.EXE 2007-04-29 11:29 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-04-29 11:29 127,008 --a------ C:\WINDOWS\system\MSVIDEO.DLL 2007-04-29 11:29 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys 2007-04-29 11:29 109,488 --a------ C:\WINDOWS\system\AVIFILE.DLL 2007-04-29 11:29 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:29 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-29 11:22 2007-04-26 10:21 72,624 --a------ C:\WINDOWS\system32\drivers\khips.sys 2007-04-26 10:21 302,000 --a------ C:\WINDOWS\system32\drivers\fwdrv.sys 2007-04-13 16:07 73,928 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-05-04 17:34:18 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\SlySoft 2007-05-04 17:27:12 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\Elaborate Bytes 2007-05-04 14:09:32 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-05-03 20:48:44 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\FlashGet 2007-04-30 20:12:30 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\Lavasoft 2007-04-29 22:44:34 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\PCToolsFirewallPlus 2007-04-29 13:52:06 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\DMCache 2007-04-29 11:11:12 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\Media Player Classic 2007-04-29 10:50:36 74,230 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-04-29 10:50:36 448,004 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-04-29 10:46:16 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\ATI 2007-04-29 10:42:24 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\Talkback 2007-04-29 10:11:02 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\TuneUp Software 2007-04-29 09:51:04 -------- d-----w C:\DOCUME~1\kojot\DANEAP~1.\Gadu-Gadu 2007-04-29 09:37:44 -------- d-----w C:\Program Files\Usługi online 2007-04-01 12:34:22 86,016 ----a-w C:\WINDOWS\system32\ElbyCDIO.dll 2007-03-15 01:58:38 315,392 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll 2007-03-15 01:57:36 267,776 ----a-w C:\WINDOWS\system32\ati2dvag.dll 2007-03-15 01:57:16 1,986,560 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys 2007-03-15 01:55:38 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll 2007-03-15 01:50:40 122,880 ----a-w C:\WINDOWS\system32\atipdlxx.dll 2007-03-15 01:50:28 114,688 ----a-w C:\WINDOWS\system32\Oemdspif.dll 2007-03-15 01:50:20 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe 2007-03-15 01:50:14 42,496 ----a-w C:\WINDOWS\system32\ati2edxx.dll 2007-03-15 01:50:00 114,688 ----a-w C:\WINDOWS\system32\ati2evxx.dll 2007-03-15 01:48:40 450,560 ----a-w C:\WINDOWS\system32\ati2evxx.exe 2007-03-15 01:47:54 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL 2007-03-15 01:40:12 2,820,544 ----a-w C:\WINDOWS\system32\ati3duag.dll 2007-03-15 01:29:48 1,315,712 ----a-w C:\WINDOWS\system32\ativvaxx.dll 2007-03-15 01:29:32 3,107,788 ----a-w C:\WINDOWS\system32\ativvaxx.dat 2007-03-15 01:19:34 5,402,624 ----a-w C:\WINDOWS\system32\atioglxx.dll 2007-03-15 01:16:16 258,048 ----a-w C:\WINDOWS\system32\atikvmag.dll 2007-03-15 01:14:44 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll 2007-03-15 01:10:30 356,352 ----a-w C:\WINDOWS\system32\ati2cqag.dll 2007-03-09 18:52:52 200,768 ----a-w C:\WINDOWS\system32\klogon.dll 2007-03-06 22:04:54 143,676 ----a-w C:\WINDOWS\system32\atiicdxx.dat (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] “{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}”=“C:\Program Files\FlashGet\jccatch.dll” “{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}”=“C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll” “{8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489}”=“C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll” “{F156768E-81EF-470C-9057-481BA8380DBA}”=“C:\Program Files\FlashGet\getflash.dll” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “HDAudDeck”=“C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1” “SunJavaUpdateSched”="“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe”" “AVP”="“C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe”" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] @="" “StartCCC”=“C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” “SpeedX”=“C:\PROGRA~1\MyPortal\Speed-X\SpeedX.exe” “Gadu-Gadu”="“C:\Program Files\Gadu-Gadu\gg.exe” /tray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] “appinit_dlls”=“C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll” HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages msv1_0\0\0 Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages scecli\0\0 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” “AnyDVD”=“C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” “CloneCDTray”="“C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” /s" “Flashget”=“C:\Program Files\FlashGet\FlashGet.exe /min” [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter HTTPFilter\0\0 LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService DnsCache\0\0 DcomLaunch DcomLaunch\0TermService\0\0 rpcss RpcSs\0\0 imgsvc StiSvc\0\0 termsvcs TermService\0\0 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost UxTuneUp *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVG_ANTI-SPYWARE_GUARD Contents of the ‘Scheduled Tasks’ folder C:\WINDOWS\tasks\1-Click Maintenance.job ******************************************************************** catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-07 20:58:31 Windows 5.1.2600 Dodatek Service Pack 2 FAT scanning hidden processes … scanning hidden services … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run HDAudDeck = C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1??? scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 2007-05-07 20:58:42 C:\ComboFix-quarantined-files.txt … 2007-05-07 20:58