ComboFix 08-02-14.1 - Łukasz 2008-02-15 8:21:36.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.371 [GMT 1:00] Running from: C:\Documents and Settings\Łukasz\Pulpit\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr0.dat C:\Documents and Settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr1.dat C:\WINDOWS.0\system32\aabae3_r.dll ----- BITS: Possible infected sites ----- hxxp://au.download.windowsupdate . ((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 ))))))))))))))))))))))))))))))) . 2008-02-14 14:40 . 2008-02-14 14:40 2008-02-14 14:40 . 2008-02-14 14:40 2008-02-14 14:39 . 2008-02-14 14:39 2008-02-14 13:31 . 2008-02-14 13:31 2008-02-14 13:17 . 2008-02-14 13:17 98,304 --a------ C:\WINDOWS.0\system32CmdLineExt.dll 2008-02-14 08:56 . 2008-02-14 08:57 1,374 --a------ C:\WINDOWS.0\imsins.BAK 2008-02-13 14:29 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS.0\system32\drivers\aswTdi.sys 2008-02-13 14:29 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS.0\system32\drivers\aavmker4.sys 2008-02-13 14:29 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS.0\system32\drivers\aswRdr.sys 2008-02-13 14:28 . 2008-02-13 14:28 2008-02-13 14:28 . 2003-03-18 21:20 1,060,864 --a------ C:\WINDOWS.0\system32\MFC71.dll 2008-02-13 14:28 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS.0\system32\aswBoot.exe 2008-02-13 14:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS.0\system32\actskin4.ocx 2008-02-13 14:28 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS.0\system32\AvastSS.scr 2008-02-13 14:28 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS.0\system32\drivers\aswmon2.sys 2008-02-13 14:28 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS.0\system32\drivers\aswmon.sys 2008-02-13 14:18 . 2008-02-13 14:18 2008-02-13 13:59 . 2008-02-13 13:59 84,418 --a------ C:\Documents and Settings\All Users\Dane aplikacji\firstlsp.reg.dat 2008-02-12 20:34 . 2008-02-12 20:34 2008-02-12 19:06 . 2008-02-12 19:19 2008-02-12 16:59 . 2008-02-12 16:59 2008-02-12 16:59 . 2005-11-23 07:25 385,024 --a------ C:\WINDOWS.0\system32\XPControls.ocx 2008-02-12 16:59 . 1998-06-24 10:57 209,192 --a------ C:\WINDOWS.0\system32\TABCTL32.OCX 2008-02-12 16:59 . 1998-06-24 10:55 140,096 --a------ C:\WINDOWS.0\system32\COMDLG32.OCX 2008-02-12 16:59 . 1998-06-24 10:56 115,016 --a------ C:\WINDOWS.0\system32\MSINET.OCX 2008-02-12 16:59 . 1999-08-29 13:15 7,716 --a------ C:\WINDOWS.0\system32\urlhist.tlb 2008-02-12 10:41 . 2008-02-12 10:41 2008-02-12 10:39 . 2008-02-13 14:33 2008-02-12 10:39 . 2008-02-12 10:39 2008-02-12 10:17 . 2008-02-12 10:17 2008-02-11 13:01 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS.0\system32\d3dx9_31.dll 2008-02-11 12:15 . 2008-02-11 12:15 2008-02-11 11:42 . 2008-02-11 11:42 1,415,680 --a------ C:\WINDOWS.0\system32\WMV9VCM.dll 2008-02-11 11:42 . 2008-02-11 11:42 921,600 --a------ C:\WINDOWS.0\system32\vorbisenc.dll 2008-02-11 11:42 . 2008-02-11 11:42 892,928 --a------ C:\WINDOWS.0\system32\iconv.dll 2008-02-11 11:42 . 2008-02-11 11:42 577,536 --a------ C:\WINDOWS.0\system32\ac3filter.ax 2008-02-11 11:42 . 2008-02-11 11:42 237,568 --a------ C:\WINDOWS.0\system32\OggDS.dll 2008-02-11 11:42 . 2008-02-11 11:42 188,416 --a------ C:\WINDOWS.0\system32\vorbis.dll 2008-02-11 11:42 . 2008-02-11 11:42 45,056 --a------ C:\WINDOWS.0\system32\ogg.dll 2008-02-11 11:41 . 2008-02-11 11:41 630,784 --a------ C:\WINDOWS.0\system32\divxdec.ax 2008-02-11 11:41 . 2008-02-11 11:41 524,288 --a------ C:\WINDOWS.0\system32\DivXsm.exe 2008-02-11 11:41 . 2008-02-11 11:41 391,168 --a------ C:\WINDOWS.0\system32\i263_32.drv 2008-02-11 11:41 . 2008-02-11 11:41 352,401 --a------ C:\WINDOWS.0\system32\DivXMedia.ax 2008-02-11 11:41 . 2008-02-11 11:41 245,760 --a------ C:\WINDOWS.0\system32\mplvpx.dll 2008-02-11 11:41 . 2008-02-11 11:41 106,496 --a------ C:\WINDOWS.0\system32\lmpgspl.ax 2008-02-11 11:41 . 2008-02-11 11:41 94,208 --a------ C:\WINDOWS.0\system32\lmpgvd.ax 2008-02-11 11:41 . 2008-02-11 11:41 86,528 --a------ C:\WINDOWS.0\system32\DVDVideo.ax 2008-02-11 11:41 . 2008-02-11 11:41 9,216 --a------ C:\WINDOWS.0\system32\cpuinf32.dll 2008-02-11 11:40 . 2008-02-11 11:40 1,559,040 --a------ C:\WINDOWS.0\system32\xvidcore.dll 2008-02-11 11:40 . 2008-02-11 11:40 77,824 --a------ C:\WINDOWS.0\system32\xvid.ax 2008-02-11 11:39 . 2008-02-11 11:39 2008-02-11 11:33 . 2008-02-11 11:33 2008-02-11 09:48 . 2008-02-11 09:51 2008-02-10 10:17 . 2008-02-14 11:05 2008-02-09 19:55 . 2008-02-09 19:55 2008-02-09 14:05 . 2008-02-10 08:17 2008-02-08 13:28 . 2008-02-08 13:28 2008-02-05 16:23 . 2008-02-05 16:23 2008-02-05 16:19 . 2006-10-22 15:06 208,896 --a------ C:\WINDOWS.0\system32\NVUNINST.EXE 2008-02-05 16:19 . 2006-10-22 12:22 208,896 --a------ C:\WINDOWS.0\system32\nvudisp.exe 2008-02-05 16:19 . 2008-02-15 08:00 88,566 --a------ C:\WINDOWS.0\system32\nvapps.xml 2008-02-05 16:19 . 2006-10-22 12:22 17,056 --a------ C:\WINDOWS.0\system32\nvdisp.nvu 2008-02-05 16:18 . 2008-02-05 16:18 2008-02-05 15:24 . 2008-02-05 17:19 799 --a------ C:\WINDOWS.0\CoDUO.INI 2008-02-05 15:04 . 2008-02-11 18:10 746 --a------ C:\WINDOWS.0\CoD.INI 2008-02-01 16:31 . 2008-02-01 16:31 2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ C:\WINDOWS.0\system32\QuickTimeVR.qtx 2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ C:\WINDOWS.0\system32\QuickTime.qts 2008-01-30 19:19 . 2008-01-30 19:19 2008-01-28 19:02 . 2008-01-28 19:02 2008-01-28 19:01 . 2008-01-28 19:01 2008-01-28 19:01 . 2008-01-28 19:01 2008-01-28 19:01 . 2008-01-28 19:02 372 --a------ C:\WINDOWS.0\SIERRA.INI 2008-01-26 21:15 . 2008-01-27 15:29 43,520 --a------ C:\WINDOWS.0\system32\CmdLineExt03.dll 2008-01-26 21:02 . 2008-01-27 15:40 21,840 --a----t- C:\WINDOWS.0\system32\SIntfNT.dll 2008-01-26 21:02 . 2008-01-27 15:40 17,212 --a----t- C:\WINDOWS.0\system32\SIntf32.dll 2008-01-26 21:02 . 2008-01-27 15:40 12,067 --a----t- C:\WINDOWS.0\system32\SIntf16.dll 2008-01-24 19:12 . 2008-01-30 17:07 2008-01-23 19:19 . 2008-01-23 19:19 2008-01-23 19:19 . 2008-01-23 19:19 2008-01-23 19:19 . 2008-01-23 19:19 2008-01-22 20:58 . 2008-01-22 20:58 2008-01-22 20:57 . 2008-01-22 20:58 2008-01-22 20:34 . 2008-01-22 20:34 2008-01-22 15:23 . 2008-01-22 15:23 2008-01-22 15:23 . 2008-01-22 15:24 2008-01-20 13:37 . 2004-08-04 07:08 26,496 --a–c— C:\WINDOWS.0\system32\dllcache\usbstor.sys 2008-01-20 12:16 . 2008-01-20 12:16 2008-01-20 12:06 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS.0\system32\mucltui.dll 2008-01-20 12:06 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS.0\system32\muweb.dll 2008-01-20 12:06 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS.0\system32\mucltui.dll.mui 2008-01-20 11:56 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS.0\system32\msonpmon.dll 2008-01-20 11:51 . 2008-01-20 11:51 2008-01-20 11:51 . 2008-01-20 11:52 2008-01-20 11:39 . 2008-02-14 08:58 2008-01-20 11:32 . 2008-01-20 11:32 2008-01-20 10:24 . 2008-01-20 10:24 2008-01-19 19:26 . 2008-01-19 19:26 406 --a------ C:\WINDOWS.0\system32\ioloBootDefrag.cfg 2008-01-19 18:34 . 2008-01-19 18:34 2008-01-19 17:30 . 2008-01-19 17:31 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-14 12:34 --------- d–h--w C:\Program Files\InstallShield Installation Information 2008-02-10 09:19 360,064 ----a-w C:\WINDOWS.0\system32\drivers\tcpip.sys 2008-02-06 18:56 --------- d-----w C:\Program Files\Common Files\Adobe 2008-01-17 20:11 692,929 ----a-w C:\WINDOWS.0\system32\unins000.exe 2008-01-17 00:58 --------- d-----w C:\Program Files\Usługi online 2008-01-12 13:32 524,800 ----a-w C:\WINDOWS.0\system32\ff_x264.dll 2008-01-08 18:12 3,108,864 ----a-w C:\WINDOWS.0\system32\libavcodec.dll 2008-01-08 18:03 405,504 ----a-w C:\WINDOWS.0\system32\libmplayer.dll 2007-12-28 22:02 118,784 ----a-w C:\WINDOWS.0\system32\ff_realaac.dll 2007-12-28 22:01 135,168 ----a-w C:\WINDOWS.0\system32\ff_samplerate.dll 2007-12-28 22:01 122,880 ----a-w C:\WINDOWS.0\system32\libmpeg2_ff.dll 2007-12-24 12:49 7,680 ----a-w C:\WINDOWS.0\system32\ff_vfw.dll 2007-12-18 09:51 179,584 ----a-w C:\WINDOWS.0\system32\drivers\mrxdav.sys 2007-12-14 10:32 12,632 ----a-w C:\WINDOWS.0\system32\lsdelete.exe 2007-12-07 02:14 824,832 ----a-w C:\WINDOWS.0\system32\wininet.dll 2007-12-04 18:42 550,912 ----a-w C:\WINDOWS.0\system32\oleaut32.dll 2007-12-03 15:09 188,416 ----a-w C:\WINDOWS.0\system32\ff_theora.dll 2007-12-03 15:08 56,320 ----a-w C:\WINDOWS.0\system32\ff_unrar.dll 2007-12-03 15:08 54,784 ----a-w C:\WINDOWS.0\system32\ff_liba52.dll 2007-12-03 15:08 397,312 ----a-w C:\WINDOWS.0\system32\ff_libfaad2.dll 2007-12-03 15:08 167,936 ----a-w C:\WINDOWS.0\system32\ff_libdts.dll 2007-12-03 15:08 143,360 ----a-w C:\WINDOWS.0\system32\ff_libmad.dll 2007-12-03 15:08 102,912 ----a-w C:\WINDOWS.0\system32\ff_tremor.dll 2007-12-03 14:01 26,624 ----a-w C:\WINDOWS.0\system32\ff_wmv9.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS.0\system32\ctfmon.exe” [2004-08-04 08:44 15360] “DAEMON Tools Lite”=“C:\Program Files\DAEMON Tools Lite\daemon.exe” [2008-01-17 17:51 486856] “ares”=“C:\Program Files\Ares\Ares.exe” [2007-12-31 15:29 962560] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“soundman.exe” [2001-12-20 02:37 124416 C:\WINDOWS.0\soundman.exe] “DeviceDiscovery”=“C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe” [2003-05-21 18:37 229437] “WooCnxMon”=“C:\PROGRA~1\NEOSTR~1\CnxMon.exe” [2003-10-16 19:07 24576] “SpeedTouch USB Diagnostics”=“C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe” [2004-01-26 11:38 866816] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [2003-10-16 19:07 53248] “NvCplDaemon”=“C:\WINDOWS.0\system32\NvCpl.dll” [2006-10-22 12:22 7700480] “nwiz”=“nwiz.exe” [2006-10-22 12:22 1622016 C:\WINDOWS.0\system32\nwiz.exe] “NvMediaCenter”=“C:\WINDOWS.0\system32\NvMcTray.dll” [2006-10-22 12:22 86016] “HPDJ Taskbar Utility”=“C:\WINDOWS.0\system32\spool\drivers\w32x86\3\hpztsb09.exe” [2003-07-28 14:43 188416] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00 79224] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS.0\System32\CTFMON.EXE” [2004-08-04 08:44 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] “QuickTime Task”=“C:\Program Files\QuickTime\QTTask.exe” -atboottime “PWRISOVM.EXE”=C:\Program Files\PowerISO\PWRISOVM.EXE “GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” “Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” R1 VIAPFD;VIAPFD;C:\WINDOWS.0\system32\Drivers\VIAPFD.SYS [2001-12-18 14:45] . Contents of the ‘Scheduled Tasks’ folder “2008-01-18 09:54:45 C:\WINDOWS.0\Tasks\AppleSoftwareUpdate.job” - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-15 08:23:32 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-02-15 8:24:14 ComboFix-quarantined-files.txt 2008-02-15 07:23:52 . 2008-02-14 07:59:37 — E O F —