ComboFix 07-12-15.1 - Rodzice 2007-12-14 17:45:12.4 - FAT32x86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.174 [GMT 1:00] Running from: D:\Documents and Settings\Rodzice\Pulpit\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-11-15 to 2007-12-15 ))))))))))))))))))))))))))))))) . 2007-12-14 17:06 . 2007-12-14 17:06 2007-12-14 17:06 . 2003-03-18 21:20 1,060,864 --a------ D:\WINDOWS\system32\MFC71.dll 2007-12-14 17:06 . 2007-12-04 14:04 837,496 --a------ D:\WINDOWS\system32\aswBoot.exe 2007-12-14 17:06 . 2003-03-18 20:14 499,712 --a------ D:\WINDOWS\system32\MSVCP71.dll 2007-12-14 17:06 . 2004-01-09 10:13 380,928 --a------ D:\WINDOWS\system32\actskin4.ocx 2007-12-14 17:06 . 2007-12-04 13:54 95,608 --a------ D:\WINDOWS\system32\AvastSS.scr 2007-12-14 17:06 . 2007-12-04 15:55 94,544 --a------ D:\WINDOWS\system32\drivers\aswmon2.sys 2007-12-14 17:06 . 2007-12-04 15:56 93,264 --a------ D:\WINDOWS\system32\drivers\aswmon.sys 2007-12-14 17:06 . 2007-12-04 15:51 42,912 --a------ D:\WINDOWS\system32\drivers\aswTdi.sys 2007-12-14 17:06 . 2007-12-04 15:49 26,624 --a------ D:\WINDOWS\system32\drivers\aavmker4.sys 2007-12-14 17:06 . 2007-12-04 15:53 23,152 --a------ D:\WINDOWS\system32\drivers\aswRdr.sys 2007-12-09 15:54 . 2007-12-09 15:54 2007-11-27 23:43 . 2007-11-27 23:43 2007-11-26 18:49 . 2007-11-26 18:49 2007-11-25 21:47 . 2007-11-25 21:47 2007-11-23 19:13 . 2007-11-23 19:13 2007-11-21 19:19 . 2007-11-21 19:19 2007-11-17 23:29 . 2007-11-17 23:29 2007-11-17 22:55 . 2007-11-17 22:55 2007-11-16 21:33 . 2007-11-16 21:33 2007-11-16 19:22 . 2007-11-16 19:22 2007-11-16 18:52 . 2007-11-16 18:52 2007-11-16 18:40 . 2007-11-16 18:40 2007-11-16 18:39 . 2007-11-16 18:39 2007-11-16 18:38 . 2007-11-16 18:38 685,816 --a------ D:\WINDOWS\system32\drivers\sptd.sys 2007-11-16 18:27 . 2007-11-16 18:27 2007-11-16 16:36 . 2007-11-16 16:36 2007-11-16 13:19 . 2007-11-16 13:19 2007-11-16 11:39 . 2007-11-16 11:39 2007-11-15 17:38 . 2007-11-15 17:38 2007-11-15 12:19 . 2007-11-15 12:19 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-14 07:28 450,560 ----a-w D:\WINDOWS\system32\dllcache\jscript.dll 2007-11-13 10:25 20,480 ----a-w D:\WINDOWS\system32\drivers\secdrv.sys 2007-11-10 13:38 --------- d-----w D:\Program Files\CeWe Color 2007-11-02 18:24 --------- d-----w D:\Program Files\SourceTec 2007-11-02 16:11 --------- d-----w D:\Program Files\Real Alternative 2007-11-02 14:51 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files 2007-10-30 10:19 3,079,680 ----a-w D:\WINDOWS\system32\dllcache\mshtml.dll 2007-10-29 22:44 1,291,264 ----a-w D:\WINDOWS\system32\quartz.dll 2007-10-29 22:44 1,291,264 ----a-w D:\WINDOWS\system32\dllcache\quartz.dll 2007-10-25 16:57 8,483,328 ----a-w D:\WINDOWS\system32\dllcache\shell32.dll 2007-10-20 05:01 227,328 ----a-w D:\WINDOWS\system32\wmasf.dll 2007-10-20 05:01 227,328 ----a-w D:\WINDOWS\system32\dllcache\wmasf.dll 2007-10-11 06:14 96,768 ----a-w D:\WINDOWS\system32\dllcache\inseng.dll 2007-10-11 06:14 662,016 ----a-w D:\WINDOWS\system32\dllcache\wininet.dll 2007-10-11 06:14 616,448 ----a-w D:\WINDOWS\system32\dllcache\urlmon.dll 2007-10-11 06:14 55,808 ----a-w D:\WINDOWS\system32\dllcache\extmgr.dll 2007-10-11 06:14 532,480 ----a-w D:\WINDOWS\system32\dllcache\mstime.dll 2007-10-11 06:14 474,112 ----a-w D:\WINDOWS\system32\dllcache\shlwapi.dll 2007-10-11 06:14 449,024 ----a-w D:\WINDOWS\system32\dllcache\mshtmled.dll 2007-10-11 06:14 39,424 ----a-w D:\WINDOWS\system32\dllcache\pngfilt.dll 2007-10-11 06:14 357,888 ----a-w D:\WINDOWS\system32\dllcache\dxtmsft.dll 2007-10-11 06:14 251,392 ----a-w D:\WINDOWS\system32\dllcache\iepeers.dll 2007-10-11 06:14 205,312 ----a-w D:\WINDOWS\system32\dllcache\dxtrans.dll 2007-10-11 06:14 16,384 ----a-w D:\WINDOWS\system32\dllcache\jsproxy.dll 2007-10-11 06:14 151,552 ----a-w D:\WINDOWS\system32\dllcache\cdfview.dll 2007-10-11 06:14 146,432 ----a-w D:\WINDOWS\system32\dllcache\msrating.dll 2007-10-11 06:14 1,494,528 ----a-w D:\WINDOWS\system32\dllcache\shdocvw.dll 2007-10-11 06:14 1,055,744 ----a-w D:\WINDOWS\system32\dllcache\danim.dll 2007-10-11 06:14 1,023,488 ----a-w D:\WINDOWS\system32\dllcache\browseui.dll 2007-10-10 11:16 18,432 ----a-w D:\WINDOWS\system32\dllcache\iedw.exe 2007-09-21 18:24 451,072 ----a-w D:\WINDOWS\Radeon Omega Drivers v3.8.360 Uninstall.exe 2007-09-21 14:25 57,344 ------w D:\WINDOWS\system32\MultiSZ.dll 2007-09-21 14:25 561,152 ------w D:\WINDOWS\UNNERO.exe 2007-09-21 14:25 532,480 ------w D:\WINDOWS\system32\imagx5.dll 2007-09-21 14:25 507,904 ------w D:\WINDOWS\system32\imagr5.dll 2007-09-21 14:25 35,328 ------w D:\WINDOWS\system32\picn20.dll 2007-09-21 14:25 275,312 ------w D:\WINDOWS\system32\ImagXpr5.dll . ((((((((((((((((((((((((((((( snapshot_2007-10-31_20.24.29,85 ))))))))))))))))))))))))))))))))))))))))) . + 2007-10-25 16:44:12 8,488,960 ------w D:\WINDOWS$hf_mig$\KB943460\SP2QFE\shell32.dll + 2007-10-29 15:07:28 368,640 ------w D:\WINDOWS$hf_mig$\KB943460\SP2QFE\spru0415.dll + 2007-03-06 03:28:34 16,096 ------w D:\WINDOWS$hf_mig$\KB943460\spmsg.dll + 2007-03-06 03:28:40 216,288 ------w D:\WINDOWS$hf_mig$\KB943460\spuninst.exe + 2007-03-06 03:28:32 22,752 ------w D:\WINDOWS$hf_mig$\KB943460\update\spcustom.dll + 2007-03-06 03:28:58 723,680 ------w D:\WINDOWS$hf_mig$\KB943460\update\update.exe + 2007-03-06 03:29:50 386,784 ------w D:\WINDOWS$hf_mig$\KB943460\update\updspapi.dll + 2006-12-19 22:51:04 8,482,304 ------w D:\WINDOWS$NtUninstallKB943460$\shell32.dll + 2007-03-06 03:28:40 216,288 ------w D:\WINDOWS$NtUninstallKB943460$\spuninst\spuninst.exe + 2007-03-06 03:29:50 386,784 ------w D:\WINDOWS$NtUninstallKB943460$\spuninst\updspapi.dll + 2007-08-21 11:53:34 122,368 ------w D:\WINDOWS$NtUninstallKB943460$\xpsp3res.dll - 2007-08-22 14:19:16 1,022,976 ----a-w D:\WINDOWS\system32\browseui.dll + 2007-10-11 06:14:30 1,023,488 ----a-w D:\WINDOWS\system32\browseui.dll - 2007-08-22 14:19:16 151,552 ----a-w D:\WINDOWS\system32\cdfview.dll + 2007-10-11 06:14:30 151,552 ----a-w D:\WINDOWS\system32\cdfview.dll - 2007-09-18 20:51:18 16,384 ----a-w D:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2007-11-20 08:11:22 16,384 ----a-w D:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - 2007-09-18 20:51:18 32,768 ----a-w D:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat + 2007-11-20 08:11:22 32,768 ----a-w D:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat - 2007-09-18 20:51:18 32,768 ----a-w D:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat + 2007-11-20 08:11:22 32,768 ----a-w D:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat - 2007-08-22 14:19:16 1,055,744 ----a-w D:\WINDOWS\system32\danim.dll + 2007-10-11 06:14:30 1,055,744 ----a-w D:\WINDOWS\system32\danim.dll - 2004-08-03 19:58:22 72,960 ----a-w D:\WINDOWS\system32\dllcache\mqac.sys + 2007-07-06 10:05:48 72,960 ----a-w D:\WINDOWS\system32\dllcache\mqac.sys - 2004-08-03 21:44:04 138,240 ----a-w D:\WINDOWS\system32\dllcache\mqad.dll + 2007-07-06 12:51:40 138,240 ----a-w D:\WINDOWS\system32\dllcache\mqad.dll - 2004-08-03 21:44:04 47,104 ----a-w D:\WINDOWS\system32\dllcache\mqdscli.dll + 2007-07-06 12:51:40 47,104 ----a-w D:\WINDOWS\system32\dllcache\mqdscli.dll - 2004-08-03 21:44:04 16,896 ----a-w D:\WINDOWS\system32\dllcache\mqise.dll + 2007-07-06 12:51:40 16,896 ----a-w D:\WINDOWS\system32\dllcache\mqise.dll - 2004-08-03 21:44:04 660,992 ----a-w D:\WINDOWS\system32\dllcache\mqqm.dll + 2007-07-06 12:51:40 660,992 ----a-w D:\WINDOWS\system32\dllcache\mqqm.dll - 2004-08-03 21:44:04 177,152 ----a-w D:\WINDOWS\system32\dllcache\mqrt.dll + 2007-07-06 12:51:40 177,152 ----a-w D:\WINDOWS\system32\dllcache\mqrt.dll - 2004-08-03 23:44:04 95,744 ----a-w D:\WINDOWS\system32\dllcache\mqsec.dll + 2007-07-06 12:51:40 95,744 ----a-w D:\WINDOWS\system32\dllcache\mqsec.dll - 2004-08-03 21:44:04 48,640 ----a-w D:\WINDOWS\system32\dllcache\mqupgrd.dll + 2007-07-06 12:51:40 48,640 ----a-w D:\WINDOWS\system32\dllcache\mqupgrd.dll - 2004-08-03 23:44:04 512,000 ----a-w D:\WINDOWS\system32\dllcache\mqutil.dll + 2007-07-06 12:51:40 512,000 ----a-w D:\WINDOWS\system32\dllcache\mqutil.dll - 2004-08-03 19:58:22 72,960 ----a-w D:\WINDOWS\system32\drivers\mqac.sys + 2007-07-06 10:05:48 72,960 ----a-w D:\WINDOWS\system32\drivers\mqac.sys - 2007-08-22 14:19:18 357,888 ----a-w D:\WINDOWS\system32\dxtmsft.dll + 2007-10-11 06:14:30 357,888 ----a-w D:\WINDOWS\system32\dxtmsft.dll - 2007-08-22 14:19:18 205,312 ----a-w D:\WINDOWS\system32\dxtrans.dll + 2007-10-11 06:14:30 205,312 ----a-w D:\WINDOWS\system32\dxtrans.dll - 2007-08-22 14:19:18 55,808 ----a-w D:\WINDOWS\system32\extmgr.dll + 2007-10-11 06:14:30 55,808 ----a-w D:\WINDOWS\system32\extmgr.dll - 2007-08-22 14:19:18 251,392 ----a-w D:\WINDOWS\system32\iepeers.dll + 2007-10-11 06:14:30 251,392 ----a-w D:\WINDOWS\system32\iepeers.dll - 2007-08-22 14:19:18 96,768 ----a-w D:\WINDOWS\system32\inseng.dll + 2007-10-11 06:14:30 96,768 ----a-w D:\WINDOWS\system32\inseng.dll - 2006-05-18 06:43:42 450,560 ----a-w D:\WINDOWS\system32\jscript.dll + 2007-11-14 07:28:56 450,560 ----a-w D:\WINDOWS\system32\jscript.dll - 2007-08-22 14:19:18 16,384 ----a-w D:\WINDOWS\system32\jsproxy.dll + 2007-10-11 06:14:30 16,384 ----a-w D:\WINDOWS\system32\jsproxy.dll - 2004-08-03 21:44:04 138,240 ----a-w D:\WINDOWS\system32\mqad.dll + 2007-07-06 12:51:40 138,240 ----a-w D:\WINDOWS\system32\mqad.dll - 2004-08-03 21:44:04 47,104 ----a-w D:\WINDOWS\system32\mqdscli.dll + 2007-07-06 12:51:40 47,104 ----a-w D:\WINDOWS\system32\mqdscli.dll - 2004-08-03 21:44:04 16,896 ----a-w D:\WINDOWS\system32\mqise.dll + 2007-07-06 12:51:40 16,896 ----a-w D:\WINDOWS\system32\mqise.dll - 2004-08-03 21:44:04 660,992 ----a-w D:\WINDOWS\system32\mqqm.dll + 2007-07-06 12:51:40 660,992 ----a-w D:\WINDOWS\system32\mqqm.dll - 2004-08-03 21:44:04 177,152 ----a-w D:\WINDOWS\system32\mqrt.dll + 2007-07-06 12:51:40 177,152 ----a-w D:\WINDOWS\system32\mqrt.dll - 2004-08-03 21:44:04 95,744 ----a-w D:\WINDOWS\system32\mqsec.dll + 2007-07-06 12:51:40 95,744 ----a-w D:\WINDOWS\system32\mqsec.dll - 2004-08-03 21:44:04 48,640 ----a-w D:\WINDOWS\system32\mqupgrd.dll + 2007-07-06 12:51:40 48,640 ----a-w D:\WINDOWS\system32\mqupgrd.dll - 2004-08-03 21:44:04 512,000 ----a-w D:\WINDOWS\system32\mqutil.dll + 2007-07-06 12:51:40 512,000 ----a-w D:\WINDOWS\system32\mqutil.dll - 2007-09-27 21:19:40 18,089,592 ----a-w D:\WINDOWS\system32\MRT.exe + 2007-12-02 23:00:06 18,684,536 ----a-w D:\WINDOWS\system32\MRT.exe - 2007-08-22 14:19:18 3,079,168 ----a-w D:\WINDOWS\system32\mshtml.dll + 2007-10-30 10:19:06 3,079,680 ----a-w D:\WINDOWS\system32\mshtml.dll - 2007-08-22 14:19:18 449,024 ----a-w D:\WINDOWS\system32\mshtmled.dll + 2007-10-11 06:14:32 449,024 ----a-w D:\WINDOWS\system32\mshtmled.dll - 2007-08-22 14:19:18 146,432 ----a-w D:\WINDOWS\system32\msrating.dll + 2007-10-11 06:14:32 146,432 ----a-w D:\WINDOWS\system32\msrating.dll - 2007-08-22 14:19:20 532,480 ----a-w D:\WINDOWS\system32\mstime.dll + 2007-10-11 06:14:32 532,480 ----a-w D:\WINDOWS\system32\mstime.dll + 2001-06-23 00:31:20 278,528 ----a-w D:\WINDOWS\system32\pncrt.dll + 1998-03-26 03:57:34 6,656 ----a-w D:\WINDOWS\system32\pndx5016.dll + 1998-05-12 19:36:44 5,632 ----a-w D:\WINDOWS\system32\pndx5032.dll - 2007-08-22 14:19:20 39,424 ----a-w D:\WINDOWS\system32\pngfilt.dll + 2007-10-11 06:14:32 39,424 ----a-w D:\WINDOWS\system32\pngfilt.dll + 2006-10-07 04:18:32 185,952 ----a-w D:\WINDOWS\system32\rmoc3260.dll - 2007-08-22 14:19:20 1,494,528 ----a-w D:\WINDOWS\system32\shdocvw.dll + 2007-10-11 06:14:32 1,494,528 ----a-w D:\WINDOWS\system32\shdocvw.dll - 2006-12-19 22:51:04 8,482,304 ----a-w D:\WINDOWS\system32\shell32.dll + 2007-10-25 16:57:22 8,483,328 ----a-w D:\WINDOWS\system32\shell32.dll - 2007-08-22 14:19:20 474,112 ----a-w D:\WINDOWS\system32\shlwapi.dll + 2007-10-11 06:14:32 474,112 ----a-w D:\WINDOWS\system32\shlwapi.dll - 2007-07-22 17:39:28 279,552 ----a-w D:\WINDOWS\system32\swreg.exe + 2007-12-13 20:26:52 156,160 ----a-w D:\WINDOWS\system32\swreg.exe - 2007-07-18 13:42:22 60,416 ------w D:\WINDOWS\system32\tzchange.exe + 2007-11-13 11:31:12 60,416 ------w D:\WINDOWS\system32\tzchange.exe - 2007-08-22 14:19:20 616,448 ----a-w D:\WINDOWS\system32\urlmon.dll + 2007-10-11 06:14:32 616,448 ----a-w D:\WINDOWS\system32\urlmon.dll - 2007-08-22 14:19:20 661,504 ----a-w D:\WINDOWS\system32\wininet.dll + 2007-10-11 06:14:32 662,016 ----a-w D:\WINDOWS\system32\wininet.dll - 2007-08-21 11:53:34 122,368 ----a-w D:\WINDOWS\system32\xpsp3res.dll + 2007-10-29 15:35:22 122,368 ----a-w D:\WINDOWS\system32\xpsp3res.dll + 2007-12-14 16:24:02 16,384 ----a-w D:\WINDOWS\TEMP\Perflib_Perfdata_63c.dat . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“D:\WINDOWS\system32\ctfmon.exe” [2004-08-03 22:44] “MSMSGS”=“D:\Program Files\Messenger\msmsgs.exe” [2004-10-13 18:24] “BitTorrent”=“D:\Documents and Settings\Rodzice\Pulpit\bittorrent.exe” [] “Skype”=“D:\Program Files\Skype\Phone\Skype.exe” [2007-09-13 13:31] “uTorrent”=“D:\Program Files\uTorrent\uTorrent.exe” [2007-10-14 14:16] “AlcoholAutomount”=“D:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe” [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “AtiPTA”=“atiptaxx.exe” [2006-02-22 02:05 D:\WINDOWS\system32\atiptaxx.exe] “SoundMan”=“SOUNDMAN.EXE” [2006-11-17 05:42 D:\WINDOWS\soundman.exe] “SunJavaUpdateSched”=“D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe” [2007-07-12 04:00] “WinampAgent”=“D:\Program Files\Winamp\winampa.exe” [2007-05-15 00:22] “NeroFilterCheck”=“D:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50] “avast!”=“D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“D:\WINDOWS\system32\CTFMON.EXE” [2004-08-03 22:44] “Picasa Media Detector”=“D:\Program Files\Picasa2\PicasaMediaDetector.exe” [2007-09-28 03:17] D:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56] R1 VIAPFD;VIAPFD;D:\WINDOWS\system32\Drivers\VIAPFD.SYS S3 tvtool;tvtool;??\E:\instalki\tvtool\tvtool.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{36586a48-7435-11dc-9f2a-000461706ff0}] \Shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs *Newly Created Service* - AAVMKER4 *Newly Created Service* - ASWMON2 *Newly Created Service* - ASWRDR *Newly Created Service* - ASWTDI *Newly Created Service* - ASWUPDSV *Newly Created Service* - AVAST!_ANTIVIRUS *Newly Created Service* - AVAST!_MAIL_SCANNER *Newly Created Service* - AVAST!_WEB_SCANNER . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-15 17:46:06 Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-15 17:46:30 D:\ComboFix3.txt … 2007-10-31 20:24 D:\ComboFix2.txt … 2007-11-16 14:07 . 2007-12-11 23:27:47 — E O F —