“Goka” - 2007-05-31 11:13:49 - ComboFix 07-06-27.7 - Dodatek Service Pack. 1 NTFS ((((((((((((((((((((((((( Files Created from 2007-04-28 to 2007-05-31 ))))))))))))))))))))))))))))))) 2007-05-31 16:34 2007-05-30 20:39 2007-05-30 13:05 249,856 --------- C:\WINDOWS\Setup1.exe 2007-05-30 13:05 2007-05-30 13:04 73,216 --a------ C:\WINDOWS\ST6UNST.EXE 2007-05-29 22:33 2007-05-29 19:36 2007-05-29 14:39 20,640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys 2007-05-29 14:36 2007-05-28 23:30 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-05-28 23:20 2007-05-27 16:49 2007-05-25 19:04 2007-05-25 16:13 2007-05-23 20:37 2007-05-23 20:37 2007-05-20 21:53 2007-05-19 22:08 86,016 --a------ C:\WINDOWS\system32\ElbyCDIO.dll 2007-05-16 14:34 2007-05-02 19:01 2007-04-27 22:15 2007-04-27 22:12 2007-04-27 21:59 2007-04-26 21:33 4,096 --a------ C:\WINDOWS\d3dx.dat 2007-04-26 19:11 4,456,448 --a------ C:\DOCUME~1\GOKA~1\ntuser.dat 2007-04-26 18:51 307,200 --a------ C:\WINDOWS\IsUn0415.exe 2007-04-20 23:29 2007-04-20 23:23 2,560 --a------ C:\WINDOWS_MSRSTRT.EXE 2007-04-20 23:04 2007-04-20 23:03 338,432 --a------ C:\WINDOWS\system32\Ir41_qcx.dll 2007-04-20 23:03 225,280 --a------ C:\WINDOWS\system32\qtmlClient.dll 2007-04-20 23:03 120,320 --a------ C:\WINDOWS\system32\Ir41_qc.dll 2007-04-20 23:03 2007-04-20 23:03 2007-04-20 23:03 2007-04-13 19:59 659 --a------ C:\WINDOWS\mozver.dat 2007-04-10 17:39 2007-04-10 17:36 2007-04-09 19:36 959 --a------ C:\WINDOWS\eReg.dat 2007-04-09 19:36 33,792 -ra------ C:\WINDOWS\NPSExec.exe 2007-04-09 19:16 2007-04-09 18:52 639,224 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-04-08 23:01 129,024 --a------ C:\Program Files\UNWISE.EXE 2007-04-08 22:25 26,056 --a------ C:\WINDOWS\system32\drivers\hamachi.sys 2007-04-08 16:06 2007-04-08 12:52 2007-04-08 11:54 2007-04-07 09:34 831,519 --a------ C:\WINDOWS\system32\mswdat10.dll 2007-04-07 09:34 614,429 --a------ C:\WINDOWS\system32\mswstr10.dll 2007-04-07 09:34 552,989 --a------ C:\WINDOWS\system32\msrepl40.dll 2007-04-07 09:34 53,279 --a------ C:\WINDOWS\system32\msjter40.dll 2007-04-07 09:34 512,029 --a------ C:\WINDOWS\system32\msexch40.dll 2007-04-07 09:34 421,919 --a------ C:\WINDOWS\system32\msrd2x40.dll 2007-04-07 09:34 380,957 --a------ C:\WINDOWS\system32\expsrv.dll 2007-04-07 09:34 348,193 --a------ C:\WINDOWS\system32\msjetoledb40.dll 2007-04-07 09:34 348,189 --a------ C:\WINDOWS\system32\msxbde40.dll 2007-04-07 09:34 348,189 --a------ C:\WINDOWS\system32\mspbde40.dll 2007-04-07 09:34 319,517 --a------ C:\WINDOWS\system32\msexcl40.dll 2007-04-07 09:34 315,423 --a------ C:\WINDOWS\system32\msrd3x40.dll 2007-04-07 09:34 30,749 --a------ C:\WINDOWS\system32\vbajet32.dll 2007-04-07 09:34 258,077 --a------ C:\WINDOWS\system32\mstext40.dll 2007-04-07 09:34 241,693 --a------ C:\WINDOWS\system32\msjtes40.dll 2007-04-07 09:34 213,023 --a------ C:\WINDOWS\system32\msltus40.dll 2007-04-07 09:34 172,061 --a------ C:\WINDOWS\system32\msjint40.dll 2007-04-07 09:34 1,507,358 --a------ C:\WINDOWS\system32\msjet40.dll 2007-04-07 09:34 2007-04-04 21:14 442,368 -ra------ C:\WINDOWS\system32\vp6vfw.dll 2007-04-03 18:04 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-07 15:09:42 -------- d-----w C:\Program Files\Ruins of Alkor V.3.4 2007-06-07 13:29:22 -------- d-----w C:\Program Files\Asprate 2007-06-06 21:02:35 -------- d-----w C:\Program Files\VIA Technologies, INC 2007-06-06 19:49:06 -------- d-----w C:\Program Files\Realtek 2007-06-06 19:47:50 315,392 ----a-w C:\WINDOWS\HideWin.exe 2007-06-06 19:36:25 -------- d-----w C:\Program Files\Realtek AC97 2007-06-06 07:36:59 -------- d-----w C:\DOCUME~1\GOKA~1\DANEAP~1\AdobeUM 2007-06-05 20:37:27 -------- d-----w C:\DOCUME~1\GOKA~1\DANEAP~1\Ashampoo 2007-06-05 20:36:43 -------- d-----w C:\Program Files\Ashampoo 2007-06-05 20:25:17 -------- d-----w C:\Program Files\SlySoft 2007-06-03 14:53:52 -------- d-----w C:\Program Files\MagiKnights 2007-06-01 19:41:39 -------- d-----w C:\Program Files\Xentare 2007-05-30 19:24:35 1,632 ----a-w C:\WINDOWS\system32\d3d8caps.dat 2007-05-30 15:06:18 1,744 ----a-w C:\WINDOWS\system32\d3d9caps.dat 2007-05-30 09:54:59 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-05-29 10:43:33 -------- d-----w C:\Program Files\Tibia 2007-05-28 21:36:59 50,952 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-05-28 21:36:59 359,032 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-05-28 18:47:48 42,496 ----a-w C:\WINDOWS\system32\ftp.exe 2007-05-28 18:47:48 16,896 ----a-w C:\WINDOWS\system32\tftp.exe 2007-05-28 18:08:23 -------- d-----w C:\Program Files\AskTBar 2007-05-28 17:41:20 -------- d-----w C:\Program Files\C-Media Audio 2007-05-28 17:41:02 -------- d-----w C:\Program Files\Elaborate Bytes 2007-05-26 10:52:16 -------- d-----w C:\Program Files\Kazaa Lite Rewolucja 2007-05-19 18:52:22 65,536 ----a-w C:\WINDOWS\IFinst27.exe 2007-05-16 10:22:53 -------- d-----w C:\Program Files\TibiaBot NG 2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr 2007-04-27 20:15:06 133,632 ----a-w C:\WINDOWS\system32\sfc_os.dll 2007-04-25 14:20:48 4,030,144 ----a-w C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2007-04-07 07:31:21 -------- d-----w C:\Program Files\Common Files\InstallShield 2007-04-06 07:48:39 -------- d-----w C:\Program Files\Gadu-Gadu 2007-03-29 13:24:02 -------- d–h--w C:\Program Files\WindowsUpdate 2007-03-27 14:43:31 0 -c–a-w C:\WINDOWS\nsreg.dat 2007-03-26 17:43:30 1,249 -c–a-w C:\WINDOWS\unins000.dat 2007-03-26 15:34:28 0 --sha-r C:\MSDOS.SYS 2007-03-26 15:34:28 0 --sha-r C:\IO.SYS 2007-03-26 15:34:28 0 ----a-w C:\CONFIG.SYS 2007-03-26 15:34:28 0 ----a-w C:\AUTOEXEC.BAT 2007-03-26 15:28:53 21,856 -c–a-w C:\WINDOWS\system32\emptyregdb.dat ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-05-12 00:47] {2F364306-AA45-47B5-9F9D-39A8B94E7EF7}=C:\Program Files\FlashGet\jccatch.dll [2007-06-11 11:55] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] {F156768E-81EF-470C-9057-481BA8380DBA}=C:\Program Files\FlashGet\getflash.dll [2007-05-16 07:05] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-04-30 17:42] “BearShare”=“C:\Program Files\BearShare\BearShare.exe” [2006-08-01 17:04] “Cmaudio”=“cmicnfg.cpl” [] “AT-Watch”="" [] “Anti-Trojan-Watch”=“C:\Program Files\Anti-Trojan-55\ATWatch.exe” [] “CloneCDTray”=“C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe” [2006-09-28 21:21] “SoundMan”=“SOUNDMAN.EXE” [2006-07-21 16:14 C:\WINDOWS\SoundMan.exe] “Flashget”=“C:\Program Files\FlashGet\FlashGet.exe” [2007-06-19 10:49] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2006-03-10 02:58] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “MsnMsgr”=“C:\Program Files\MSN Messenger\MsnMsgr.exe” [] “Shareaza”=“C:\Program Files\K-litePro\K-litePro.exe” [] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-01-30 16:58] “CTFMON.EXE”=“C:\WINDOWS\System32\ctfmon.exe” [2002-09-29 00:00] [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\system] “DisableRegistryTools”=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoLowDiscSpaceChecks”=000000000000f03f ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-31 11:15:49 Windows 5.1.2600 Dodatek Service Pack. 1 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … ************************************************************************** Completion time: 2007-05-31 11:16:49 C:\ComboFix-quarantined-files.txt … 2007-05-31 11:16 C:\ComboFix2.txt … 2007-05-29 22:01 C:\ComboFix3.txt … 2007-05-28 23:37 — E O F —