“Krzysiek” - 2007-07-25 19:42:55 [GMT 2:00] - ComboFix 07-07-24 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2007-06-25 to 2007-07-25 ))))))))))))))))))))))))))))))) 2007-07-25 19:42 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-25 18:09 2007-07-25 15:54 307,200 --a------ C:\WINDOWS\IsUn0415.exe 2007-07-25 15:54 228,352 --------- C:\WINDOWS\system32\DECO_32.DLL 2007-07-25 15:54 17,920 --------- C:\WINDOWS\system32\IMPLODE.DLL 2007-07-25 15:54 2007-07-25 15:54 2007-07-25 12:41 2007-07-25 11:54 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-07-25 11:44 2007-07-25 11:43 2007-07-25 11:43 2007-07-25 11:28 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll 2007-07-25 11:28 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll 2007-07-25 11:28 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-07-25 11:28 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll 2007-07-25 11:28 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll 2007-07-25 11:28 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll 2007-07-25 11:28 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll 2007-07-25 11:28 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll 2007-07-25 11:24 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-07-25 11:24 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll 2007-07-25 11:24 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll 2007-07-25 11:24 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll 2007-07-25 11:24 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll 2007-07-25 11:24 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll 2007-07-25 11:24 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-07-25 11:24 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll 2007-07-25 11:24 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-07-25 11:24 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll 2007-07-25 11:24 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-07-25 11:17 2007-07-25 11:17 2007-07-25 11:13 2007-07-25 11:08 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-07-25 11:08 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-07-25 11:08 21,504 --a------ C:\WINDOWS\system32\hidserv.dll 2007-07-25 11:07 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-07-25 11:07 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-07-25 11:06 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-07-25 11:06 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-07-25 11:06 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-07-25 11:06 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-07-25 11:06 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-07-25 11:06 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-07-25 11:06 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-07-25 11:06 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-07-25 11:06 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-07-25 11:06 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-07-25 11:06 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll 2007-07-25 11:06 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-07-25 11:06 2007-07-25 11:06 2007-07-25 11:06 2007-07-25 11:06 2007-07-25 11:05 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-07-25 11:05 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-07-25 11:05 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-07-25 11:05 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-07-25 11:05 8,704 --a------ C:\WINDOWS\system32\batt.dll 2007-07-25 11:05 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-07-25 11:05 70,144 --a------ C:\WINDOWS\NOTEPAD.EXE 2007-07-25 11:05 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-07-25 11:05 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-07-25 11:05 69,552 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-07-25 11:05 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-07-25 11:05 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-07-25 11:05 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-07-25 11:05 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-07-25 11:05 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-07-25 11:05 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-07-25 11:05 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-07-25 11:05 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-07-25 11:05 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-07-25 11:05 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-07-25 11:05 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-07-25 11:05 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-07-25 11:05 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-07-25 11:05 5,632 --a------ C:\WINDOWS\system32\kbdro.dll 2007-07-25 11:05 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll 2007-07-25 11:05 5,120 --a------ C:\WINDOWS\system\SHELL.DLL 2007-07-25 11:05 33,376 --a------ C:\WINDOWS\system\COMMDLG.DLL 2007-07-25 11:05 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-07-25 11:05 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL 2007-07-25 11:05 19,200 --a------ C:\WINDOWS\system\TAPI.DLL 2007-07-25 11:05 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll 2007-07-25 11:05 15,360 --a------ C:\WINDOWS\TASKMAN.EXE 2007-07-25 11:05 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-07-25 11:05 127,008 --a------ C:\WINDOWS\system\MSVIDEO.DLL 2007-07-25 11:05 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys 2007-07-25 11:05 109,488 --a------ C:\WINDOWS\system\AVIFILE.DLL 2007-07-25 11:05 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll 2007-07-25 11:05 2007-07-25 11:05 2007-07-25 11:05 2007-07-25 11:05 2007-07-25 11:05 2007-07-25 11:05 2007-07-25 11:05 2007-07-25 11:05 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-25 10:12:52 49,712 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-07-25 10:12:52 355,830 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-07-25 07:13:43 -------- d-----w C:\Program Files\Usługi online 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “mouseElf”=“C:\PROGRA~1\GENIUS~1\mouseElf.exe” [2004-06-10 17:26] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-04-30 17:42] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 14:00] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount] “C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe” /automount [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] “C:\Program Files\DAEMON Tools\daemon.exe” -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DemonStarter] C:\Program Files\PWN\Definicje\Bin\Starter.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD] C:\Program Files\Ahead\InCD\InCD.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSF_Monitor] C:\PROGRA~1\MYSECR~1\MSFMON.exe /Start [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRaidService] C:\WINDOWS\system32\nvraidservice.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] SOUNDMAN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics] “C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” /icon [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] C:\Program Files\Winamp\winampa.exe R0 speedfan;speedfan;C:\WINDOWS\system32\speedfan.sys R1 AmdK8;Sterownik procesora AMD;C:\WINDOWS\system32\DRIVERS\AmdK8.sys R2 MSF32;MSF32;??\C:\Program Files\MySecretFolder XP\MSF32.SYS R3 alcan5wn;SpeedTouch USB ADSL PPP Networking Driver (NDISWAN);C:\WINDOWS\system32\DRIVERS\alcan5wn.sys R3 alcaudsl;SpeedTouch ADSL Modem ATM Transport;C:\WINDOWS\system32\DRIVERS\alcaudsl.sys R3 genmcmnUSB;Genius USB Mouse Driver;C:\WINDOWS\system32\DRIVERS\gflmouhid.sys ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-25 19:44:15 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden registry entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-25 19:45:01 — E O F —