ComboFix 07-10-21.1** - Paulina 2007-10-22 16:01:30.5 - NTFSx86 Running from: E:\Programy\Nowy folder\ComboFix.exe Command switches used :: E:\Programy\Nowy folder\CFScript.txt FILE:: C:\WINDOWS\system32\hompex.dll C:\WINDOWS\system32\mmdmm.exe c:\windows\system32\vtursrp.dll C:\WINDOWS\System32\winIogon.exe C:\WINDOWS\system32\znuc.exe . ((((((((((((((((((((((((( Files Created from 2007-09-22 to 2007-10-22 ))))))))))))))))))))))))))))))) . 2007-10-22 13:42 169,984 --ahs---- C:\WINDOWS\system32\urdvxc.exe 2007-10-22 11:54 2007-10-22 11:54 2007-10-22 11:54 2007-10-22 11:54 2007-10-22 11:54 2007-10-22 11:54 2007-10-22 11:54 2007-10-22 11:54 44,495 --a------ C:\9r2h2z5l7v8.exe 2007-10-21 19:59 52,224 --------- C:\WINDOWS\system32\brinsstr.dll 2007-10-21 19:59 50 --a------ C:\WINDOWS\system32\bridf05a.dat 2007-10-21 19:58 2007-10-21 19:58 147,456 --------- C:\WINDOWS\brunin03.dll 2007-10-21 19:53 2007-10-21 19:52 2007-10-21 19:51 2007-10-21 19:35 2007-10-21 19:34 2007-10-21 19:27 97,280 -----c— C:\WINDOWS\system32\dllcache\dpcdll.dll 2007-10-21 19:26 2007-10-21 19:26 2007-10-21 19:13 755,200 --a------ C:\WINDOWS\system32\ir50_32.dll 2007-10-21 19:13 338,432 --a------ C:\WINDOWS\system32\ir41_qcx.dll 2007-10-21 19:13 200,192 --a------ C:\WINDOWS\system32\ir50_qc.dll 2007-10-21 19:13 183,808 --a------ C:\WINDOWS\system32\ir50_qcx.dll 2007-10-21 19:13 182,880 --a------ C:\WINDOWS\system32\iuengine.dll 2007-10-21 19:13 120,320 --a------ C:\WINDOWS\system32\ir41_qc.dll 2007-10-21 19:13 27,392 --a------ C:\WINDOWS\system32\drivers\viaagp.sys 2007-10-21 19:13 15,872 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-10-21 19:08 2007-10-21 17:58 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-10-21 13:31 720 --a------ C:\WINDOWS\system32\tmp.reg 2007-10-21 13:30 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe 2007-10-21 13:30 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2007-10-21 13:30 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-10-21 13:30 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2007-10-21 13:30 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe 2007-10-21 13:26 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-21 12:19 2007-10-21 12:07 2007-10-21 12:07 98,304 --a------ C:\WINDOWS\system32\nvudisp.exe 2007-10-21 11:57 36,224 --a------ C:\WINDOWS\system32\drivers\isapnp.sys 2007-10-21 11:55 2007-10-21 11:00 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr 2007-10-21 11:00 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-10-21 11:00 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-10-21 11:00 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-10-21 10:59 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll 2007-10-21 10:59 801,144 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-10-21 10:59 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll 2007-10-21 10:59 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll 2007-10-21 10:59 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-10-21 10:59 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-10-21 10:09 40,960 --a–c— C:\WINDOWS\system32\dllcache\trialoc.dll 2007-10-21 10:08 73,728 --a–c— C:\WINDOWS\system32\dllcache\icwtutor.exe 2007-10-21 10:08 65,536 --a–c— C:\WINDOWS\system32\dllcache\icwres.dll 2007-10-21 09:58 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-10-21 09:58 24,661 --a–c— C:\WINDOWS\system32\dllcache\spxcoins.dll 2007-10-21 09:58 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-10-21 09:58 13,312 --a–c— C:\WINDOWS\system32\dllcache\irclass.dll 2007-10-20 18:48 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-10-20 18:46 577,024 -rahs---- C:\WINDOWS\VTTray.exe 2007-10-20 18:45 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:44 2007-10-20 18:42 2007-10-20 18:28 5 --ahs---- C:\WINDOWS\system32\efebacff3_s.dll 2007-10-20 18:22 2007-10-20 18:19 2007-10-20 18:14 2,928 --a------ C:\WINDOWS\mozver.dat 2007-10-20 18:14 0 --a------ C:\WINDOWS\nsreg.dat 2007-10-20 18:03 2007-10-20 18:03 2007-10-20 18:03 61,440 --a------ C:\WINDOWS\system32\3Deep.dll 2007-10-20 18:02 2007-10-20 18:02 2007-10-20 18:02 2007-10-20 18:02 2007-10-20 18:02 947,884 -ra------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2007-10-20 18:02 46,592 -ra------ C:\WINDOWS\SOUNDMAN.EXE 2007-10-20 18:01 2007-10-20 18:01 2007-10-20 18:01 2007-10-20 18:01 2007-10-20 18:01 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-10-20 18:01 208,896 -ra------ C:\WINDOWS\alcupd.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-22 13:51 42,496 ----a-w C:\WINDOWS\system32\ftp.exe 2007-10-22 13:51 42,496 ----a-w C:\WINDOWS\system32\dllcache\ftp.exe 2007-10-22 13:51 16,896 ----a-w C:\WINDOWS\system32\tftp.exe 2007-10-22 11:44 169,984 ----a-w C:\WINDOWS\Web\wcxnjhhj.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\zejthvxk.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\tlrrsvlj.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\btlekkxb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\btlekkxb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\btlekkxb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\btlekkxb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\nbbrcrbb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\estewkrn.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\necxlsbh.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\hsxenjvk.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\hnshlbtv.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\ewznktww.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\ecrvhvjh.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\trvnbvzr.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\tehbbexs.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\selznkbn.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\qnkstrhn.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\kenjxzsk.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\hzenbhql.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cszbbkjb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cjrhtnee.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\sljktqsl.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\lenvstcw.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\lbncltew.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\vhzlshll.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\heclkcje.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\ejjtwclz.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\brbjhjhb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\bbcrvske.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\xxrlrrck.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\slkweqkr.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\jjtkbtsb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\rlkctexe.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\resrzjkr.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\kcqrjjel.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\jllrjejn.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\hlnbkbjt.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\cqlwbrtn.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\vtxbneqq.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\jzrjzkke.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\jqnsbclx.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\rc\rjzhtwer.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\zeektjlr.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\tjsnlncx.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\NetDiag\stleqtrb.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\NetDiag\bnkrcrqq.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\errors\xnejeese.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\ErrMsg\nvsbqtlx.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\DVDUpgrd\kvzexhbs.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\zwjcbxql.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\jlskvkjt.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\hhktjkel.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\tcjqbtst.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\nrbhslcz.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\eqlrejrl.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\brvhkxjh.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\Help\tsbjbtvn.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\Help\Tours\WindowsMediaPlayer\Cnt\tjnbzhbh.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\Help\Tours\WindowsMediaPlayer\Audio\lllknblj.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\Help\jjlenkbt.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\Help\jbnshhqj.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\Help\hwexrtne.exe 2007-10-22 11:43 169,984 ----a-w C:\WINDOWS\Help\bzehxvnz.exe 2007-10-21 08:15 133,120 ----a-w C:\WINDOWS\system32\sfc_os.dll 2007-10-21 08:07 --------- d-----w C:\Program Files\Usługi online 2007-10-20 15:54 --------- d-----w C:\Program Files\microsoft frontpage . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE~\Browser Helper Objects{31257c63-f81d-4d8d-badc-5ca2969e70c2}] C:\WINDOWS\system32\hompex.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [2002-11-19 13:24 C:\WINDOWS\SOUNDMAN.EXE] “avast!”=“C:\Avast4\ashDisp.exe” [2007-09-06 12:06] “NvCplDaemon”=“C:\WINDOWS\System32\NvCpl.dll” [2003-10-06 15:16] “nwiz”=“nwiz.exe” [2003-10-06 15:16 C:\WINDOWS\system32\nwiz.exe] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\System32\ctfmon.exe” [2001-10-26 19:29] “NvMediaCenter”=“C:\WINDOWS\System32\NVMCTRAY.DLL” [2003-10-06 15:16] “AlcoholAutomount”=“E:\Programy\Alcohol\axcmd.exe” [2007-07-02 12:22] “MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2001-08-02 07:14] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ E-Color.lnk - C:\Program Files\E-Color\Common\IconMgr.exe [2007-10-20 18:03:18] [HKEY_USERS.default\software\microsoft\windows\currentversion\policies\system] “DisableTaskMgr”=0 (0x0) “DisableRegistryTools”=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoRecentDocsMenu”=1 (0x1) “DisallowRun”=1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun] “1”=9r2h2z5l7v8.exe . ************************************************************************** catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-22 16:02:07 Windows 5.1.2600 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-22 16:02:39 C:\ComboFix2.txt … 2007-10-21 15:43 . — E O F —