ComboFix 07-10-23.2 - Ela i Max 2007-10-23 17:04:57.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.660 [GMT 2:00] Running from: C:\Documents and Settings\Ela i Max\Pulpit\ComboFix.exe Command switches used :: C:\Documents and Settings\Ela i Max\Pulpit\CFScript.txt * Created a new restore point FILE:: C:\WINDOWS\system32\svshost.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\svshost.exe . ((((((((((((((((((((((((( Files Created from 2007-09-23 to 2007-10-23 ))))))))))))))))))))))))))))))) . 2007-10-23 11:31 2007-10-23 10:31 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-23 09:43 2007-10-23 09:22 2007-10-23 09:22 2007-10-22 23:58 0 --a------ C:\WINDOWS\nsreg.dat 2007-10-17 08:51 94,208 --a------ C:\WINDOWS\system32\vbpng1.dll 2007-10-17 08:51 53,248 --a------ C:\WINDOWS\system32\zlib.dll 2007-10-15 16:41 2007-10-15 15:12 2007-10-12 00:08 2007-10-12 00:08 2007-10-12 00:08 3,036,456 --a------ C:\WINDOWS\system32\BCGCBPRO860u80.dll 2007-10-12 00:08 1,757,184 --a------ C:\WINDOWS\system32\imagX7.dll 2007-10-12 00:08 802,816 --a------ C:\WINDOWS\system32\imagXRA7.dll 2007-10-12 00:08 497,296 --a------ C:\WINDOWS\system32\imagXpr7.dll 2007-10-12 00:08 368,640 --a------ C:\WINDOWS\system32\TwnLib4.dll 2007-10-12 00:08 258,048 --a------ C:\WINDOWS\system32\imagXR7.dll 2007-10-12 00:08 33,576 --a------ C:\WINDOWS\system32\BCGPOleAcc.dll 2007-10-11 16:10 2007-10-09 20:28 2007-10-09 20:28 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-10-09 20:28 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-10-09 20:28 740,442 --a------ C:\WINDOWS\system32\divx.dll 2007-10-09 20:28 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-10-09 20:28 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll 2007-10-09 20:28 73,728 --a------ C:\WINDOWS\system32\dpl100.dll 2007-10-09 20:28 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-10-09 09:20 2007-10-09 09:20 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-10-07 18:56 2007-10-01 21:02 2007-10-01 21:02 24,064 --------- C:\WINDOWS\system32\msxml3a.dll 2007-09-23 23:34 2007-09-23 23:32 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-23 12:33 --------- d-----w C:\Documents and Settings\Ela i Max\Dane aplikacji\uTorrent 2007-10-23 07:15 --------- d-----w C:\Program Files\Lavasoft 2007-10-23 07:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-10-16 19:14 --------- d-----w C:\Program Files\AlienGUIse 2007-10-16 09:58 --------- d-----w C:\Program Files\Winamp 2007-10-11 21:16 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-10-11 21:10 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-10-01 19:01 --------- d-----w C:\Program Files\CyberLink 2007-09-22 11:59 --------- d-----w C:\Program Files\Yamicsoft 2007-09-22 11:44 --------- d-----w C:\Program Files\Common Files\Ahead 2007-09-20 18:00 --------- d-----w C:\Program Files\Gadu-Gadu 2007-09-20 17:56 21,504 ----a-w C:\WINDOWS\system32\adptifav.dll 2007-09-18 11:59 --------- d-----w C:\Program Files\CoffeeCup Software 2007-09-18 09:08 21,504 ----a-w C:\WINDOWS\system32\atkctrsb.dll 2007-09-17 18:41 21,504 ----a-w C:\WINDOWS\system32\ati2dvagvva.dll 2007-09-16 17:53 21,504 ----a-w C:\WINDOWS\system32\atmfdaa.dll 2007-09-15 12:56 21,504 ----a-w C:\WINDOWS\system32\ati2dvagvv.dll 2007-09-14 18:27 --------- d-----w C:\Documents and Settings\Ela i Max\Dane aplikacji\SopCast 2007-09-14 18:11 --------- d-----w C:\Program Files\SopCast 2007-09-13 22:02 21,504 ----a-w C:\WINDOWS\system32\avwava.dll 2007-09-12 15:33 21,504 ----a-w C:\WINDOWS\system32\authza.dll 2007-09-11 13:19 21,504 ----a-w C:\WINDOWS\system32\ATIDEMGRb.dll 2007-09-10 12:35 --------- d-----w C:\Program Files\Gra w ciemno v2 2007 2007-09-10 06:00 21,504 ----a-w C:\WINDOWS\system32\acctresa.dll 2007-09-08 18:55 21,504 ----a-w C:\WINDOWS\system32\Audio3Db.dll 2007-09-08 15:12 21,504 ----a-w C:\WINDOWS\system32\adptifa.dll 2007-09-07 13:31 21,504 ----a-w C:\WINDOWS\system32\ati2dvagv.dll 2007-09-06 08:53 21,504 ----a-w C:\WINDOWS\system32\blackboxav.dll 2007-09-05 08:24 21,504 ----a-w C:\WINDOWS\system32\adsndss.dll 2007-09-04 07:48 21,504 ----a-w C:\WINDOWS\system32\advpacksv.dll 2007-09-03 07:17 21,504 ----a-w C:\WINDOWS\system32\acluiv.dll 2007-09-01 13:19 --------- d-----w C:\Program Files\Ortalion Entertainment 2007-09-01 06:48 21,504 ----a-w C:\WINDOWS\system32\bidisplvs.dll 2007-08-31 22:47 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys 2007-08-31 05:15 21,504 ----a-w C:\WINDOWS\system32\adsldpcs.dll 2007-08-29 22:35 21,504 ----a-w C:\WINDOWS\system32\appmgmtsv.dll 2007-08-29 18:50 --------- d-----w C:\Program Files\Avery Dennison 2007-08-28 21:29 21,504 ----a-w C:\WINDOWS\system32\aaaamons.dll 2007-08-28 21:25 --------- d-----w C:\Program Files\ESTsoft 2007-08-28 14:51 21,504 ----a-w C:\WINDOWS\system32\actxprxya.dll 2007-08-27 08:16 21,504 ----a-w C:\WINDOWS\system32\bootvidb.dll 2007-08-26 08:15 21,504 ----a-w C:\WINDOWS\system32\ati2evxxs.dll 2007-08-24 20:32 21,504 ----a-w C:\WINDOWS\system32\ati2cqagb.dll 2007-08-23 20:30 21,504 ----a-w C:\WINDOWS\system32\capicoma.dll 2007-08-22 19:43 21,504 ----a-w C:\WINDOWS\system32\adsldpcb.dll 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-20 08:54 21,504 ----a-w C:\WINDOWS\system32\amstreamb.dll 2007-08-19 08:48 21,504 ----a-w C:\WINDOWS\system32\catsrva.dll 2007-08-18 08:31 21,504 ----a-w C:\WINDOWS\system32\adsnta.dll 2007-08-16 18:56 21,504 ----a-w C:\WINDOWS\system32\advpacks.dll 2007-08-15 11:54 21,504 ----a-w C:\WINDOWS\system32\autodiscv.dll 2007-08-14 11:08 21,504 ----a-w C:\WINDOWS\system32\aaaamonb.dll 2007-08-13 07:07 21,504 ----a-w C:\WINDOWS\system32\ativcoxxv.dll 2007-08-11 16:38 21,504 ----a-w C:\WINDOWS\system32\ccfgnta.dll 2007-08-10 13:56 21,504 ----a-w C:\WINDOWS\system32\advapi32s.dll 2007-08-07 21:40 21,504 ----a-w C:\WINDOWS\system32\bidisplb.dll 2007-08-06 19:37 21,504 ----a-w C:\WINDOWS\system32\browsewma.dll 2007-08-05 16:03 21,504 ----a-w C:\WINDOWS\system32\blackboxa.dll 2007-08-02 20:07 21,504 ----a-w C:\WINDOWS\system32\advapi32a.dll 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll . ((((((((((((((((((((((((((((((((((((((((((((( AWF )))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ----a-w 15,360 2004-08-03 22:44:20 C:\WINDOWS\system32\bak\ctfmon.exe ----a-w 15,360 2004-08-03 22:44:20 C:\WINDOWS\system32\ctfmon.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2004-08-25 15:25] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2004-08-25 13:52] “RemoteControl”=“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [2005-12-07 22:57] “LanguageShortcut”=“C:\Program Files\CyberLink\PowerDVD\Language\Language.exe” [2006-05-18 11:29] “C-Media Mixer”=“Mixer.exe” [2002-10-15 20:00 C:\WINDOWS\mixer.exe] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NCLaunch”=“C:\WINDOWS\NCLAUNCH.EXe” [2007-02-28 15:47] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce] “megauploadtoolbar”=C:\DOCUME~1\ELAIMA~1\USTAWI~1\Temp\tbuninstall.exe -df “C:\Program Files\MegauploadToolbar” [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” runtime [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB] C:\Program Files\AlienGUIse\fastload.dll 2001-12-20 23:34 24576 C:\Program Files\AlienGUIse\fastload.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “appinit_dlls”= ,wbsys.dll S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys S3 HWACCESS;HWACCESS;??\C:\WINDOWS\SYSTEM32\HWACCESS.SYS S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS . ************************************************************************** catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-23 17:06:10 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-23 17:06:52 C:\ComboFix2.txt … 2007-10-23 10:36 . — E O F —