ComboFix 07-12-19.2 - michal 2007-12-19 20:37:59.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.48.1045.18.1603 [GMT 1:00] Running from: C:\Documents and Settings\michal\Pulpit\ComboFix.exe Command switches used :: C:\Documents and Settings\michal\Pulpit\CFScript.txt * Created a new restore point FILE C:\Documents and Settings\WOJTEK\Dane aplikacji\Anti-Virus-Pro.com C:\WINDOWS\system32\drivers\pe3ajquc.sys C:\WINDOWS\system32\drivers\ps6ajquc.sys C:\WINDOWS\system32\pr2ajquc.exe C:\WINDOWS\system32\tvtpwp.dll C:\WINDOWS\windivx.dll . ((((((((((((((((((((((((( Files Created from 2007-11-19 to 2007-12-19 ))))))))))))))))))))))))))))))) . 2007-12-18 17:52 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll 2007-12-18 17:51 . 2007-12-18 17:51 2007-12-18 17:51 . 2007-12-18 17:51 2007-12-18 17:47 . 2007-12-18 17:51 2007-12-18 17:47 . 2007-12-18 17:47 2007-12-18 17:47 . 2007-12-18 17:52 2007-12-17 14:56 . 2007-12-17 14:56 2007-12-17 14:55 . 2000-07-31 13:28 286,208 --a------ C:\WINDOWS\system32\binkw32.dll 2007-12-17 14:46 . 2007-12-17 14:46 2007-12-17 14:46 . 2007-12-17 14:46 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-12-17 13:09 . 2007-09-14 05:21 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-12-17 13:08 . 2007-12-17 13:08 2007-12-17 06:26 . 2007-12-17 06:26 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll 2007-12-17 06:25 . 2007-12-17 06:25 2007-12-16 00:07 . 2007-12-16 00:10 223,232 --a------ C:\WINDOWS\pmspl.dll 2007-12-15 20:26 . 2007-12-15 20:26 0 --a------ C:\WINDOWS\MOTO.INI 2007-12-15 15:48 . 2007-12-15 15:48 2007-12-15 15:48 . 2007-12-15 15:48 1 --a------ C:\WINDOWS\system32\SI.bin 2007-12-15 15:47 . 2007-12-15 15:47 2007-12-11 20:42 . 2007-12-11 20:42 2007-12-11 20:42 . 2007-12-11 20:42 2007-12-10 17:37 . 2003-06-25 16:09 45,056 --a------ C:\WINDOWS\system32\vcSUBFORMCTL.ocx 2007-12-09 18:02 . 2007-12-09 18:02 2007-12-09 18:01 . 2007-12-09 18:20 2007-12-09 17:09 . 2007-12-09 17:10 2007-12-09 17:08 . 2007-12-09 17:08 2007-12-09 17:08 . 2007-12-09 17:09 32 --a------ C:\WINDOWS\0 2007-12-09 17:08 . 2007-12-09 17:08 0 --a------ C:\WINDOWS\system32\0 2007-12-09 16:45 . 2004-08-04 00:44 153,088 --a------ C:\WINDOWS\system32\irftp.exe 2007-12-09 16:45 . 2004-08-04 00:44 153,088 --a–c— C:\WINDOWS\system32\dllcache\irftp.exe 2007-12-09 16:45 . 2004-08-03 23:00 87,424 --a------ C:\WINDOWS\system32\drivers\irda.sys 2007-12-09 16:45 . 2004-08-03 23:00 87,424 --a–c— C:\WINDOWS\system32\dllcache\irda.sys 2007-12-09 16:45 . 2004-08-04 00:44 27,648 --a------ C:\WINDOWS\system32\irmon.dll 2007-12-09 16:45 . 2004-08-04 00:44 27,648 --a–c— C:\WINDOWS\system32\dllcache\irmon.dll 2007-12-09 16:45 . 2001-08-17 21:51 19,584 --a------ C:\WINDOWS\system32\drivers\rasirda.sys 2007-12-09 16:45 . 2001-08-17 21:51 19,584 --a–c— C:\WINDOWS\system32\dllcache\rasirda.sys 2007-12-09 16:45 . 2004-08-04 00:44 8,192 --a------ C:\WINDOWS\system32\wshirda.dll 2007-12-09 16:45 . 2004-08-04 00:44 8,192 --a–c— C:\WINDOWS\system32\dllcache\wshirda.dll 2007-12-09 16:44 . 2001-08-17 21:49 26,624 --a------ C:\WINDOWS\system32\drivers\irstusb.sys 2007-12-09 16:44 . 2001-08-17 21:49 26,624 --a–c— C:\WINDOWS\system32\dllcache\irstusb.sys 2007-12-08 02:23 . 2007-12-08 02:23 577,536 --a------ C:\WINDOWS\system32\ac3filter.ax 2007-12-08 02:23 . 2006-10-18 20:05 232,448 --a------ C:\WINDOWS\system32\l3codecp.acm 2007-12-08 02:22 . 2007-12-08 02:22 892,928 --a------ C:\WINDOWS\system32\iconv.dll 2007-12-08 02:21 . 2007-12-08 02:21 237,568 --a------ C:\WINDOWS\system32\OggDS.dll 2007-12-08 02:20 . 2007-12-08 02:20 921,600 --a------ C:\WINDOWS\system32\vorbisenc.dll 2007-12-08 02:19 . 2003-06-23 02:44 1,415,680 --a------ C:\WINDOWS\system32\wmv9vcm.dll 2007-12-08 02:19 . 2007-12-08 02:19 188,416 --a------ C:\WINDOWS\system32\vorbis.dll 2007-12-08 02:19 . 2007-12-08 02:19 45,056 --a------ C:\WINDOWS\system32\ogg.dll 2007-12-08 02:18 . 2007-12-08 02:18 94,208 --a------ C:\WINDOWS\system32\lmpgvd.ax 2007-12-08 02:17 . 2007-12-08 02:17 729,088 --a------ C:\WINDOWS\system32\divxdec.ax 2007-12-08 02:17 . 2007-12-08 02:17 391,168 --a------ C:\WINDOWS\system32\i263_32.drv 2007-12-08 02:17 . 2007-12-08 02:17 245,760 --a------ C:\WINDOWS\system32\mplvpx.dll 2007-12-08 02:17 . 2007-12-08 02:17 106,496 --a------ C:\WINDOWS\system32\lmpgspl.ax 2007-12-08 02:17 . 2007-12-08 02:17 86,528 --a------ C:\WINDOWS\system32\DVDVideo.ax 2007-12-08 02:17 . 2007-12-08 02:17 9,216 --a------ C:\WINDOWS\system32\cpuinf32.dll 2007-12-08 02:15 . 2007-12-08 02:15 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax 2007-12-08 02:14 . 2007-12-08 02:14 740,442 --a------ C:\WINDOWS\system32\DivX.dll 2007-12-08 02:13 . 2007-12-08 02:13 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-12-08 02:13 . 2007-12-08 02:13 77,824 --a------ C:\WINDOWS\system32\xvid.ax 2007-12-07 13:37 . 2007-12-07 13:38 2007-12-05 19:46 . 2007-12-05 19:46 2007-12-05 19:24 . 2007-12-05 19:24 2007-12-05 16:03 . 2007-12-05 16:03 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-12-05 16:01 . 2007-12-05 16:01 2007-12-05 15:56 . 2007-12-19 20:25 69 --a------ C:\WINDOWS\NeroDigital.ini 2007-12-05 15:10 . 2007-12-19 17:16 2007-12-05 03:00 . 2007-12-05 03:00 2007-12-04 18:08 . 2007-12-04 18:08 2007-12-04 18:08 . 2007-12-04 18:15 2007-12-04 17:59 . 2007-12-19 18:58 2007-12-04 17:41 . 2007-12-04 17:41 2007-12-04 17:11 . 2007-12-04 17:11 2007-12-04 17:10 . 2007-12-04 17:10 2007-12-04 17:10 . 2007-12-04 17:10 2007-12-04 17:10 . 2007-12-04 17:10 2007-12-04 15:49 . 2007-12-04 15:49 2007-12-04 15:36 . 2007-12-04 15:37 2007-12-04 15:36 . 2007-12-04 15:36 2007-12-04 15:36 . 2007-12-04 15:36 2007-12-04 15:36 . 2007-12-04 15:36 2007-12-04 15:36 . 2007-03-28 19:42 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll 2007-12-04 15:07 . 2007-12-17 19:00 13,030 --a------ C:\PDOXUSRS.NET 2007-12-04 15:03 . 2007-12-04 15:03 2007-12-04 15:03 . 2007-12-17 19:00 2007-12-04 13:22 . 2007-12-09 18:01 2007-12-04 13:22 . 2007-12-15 20:10 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe 2007-12-04 13:22 . 2007-12-04 13:22 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe 2007-12-04 13:22 . 2007-12-15 20:11 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys 2007-12-04 13:21 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-12-04 08:16 . 2007-12-04 08:16 2007-12-04 08:15 . 2007-12-04 08:15 2007-12-04 07:36 . 2007-12-04 07:36 2007-12-04 07:32 . 2007-12-04 07:32 2007-12-04 07:30 . 2007-12-16 16:03 2007-12-04 07:18 . 2007-12-04 13:05 2007-12-04 07:18 . 2007-12-04 07:18 2007-12-04 07:18 . 2007-10-04 17:14 136,260 --a------ C:\WINDOWS\system32\nvapps.nvb 2007-12-04 07:17 . 2007-12-04 07:17 2007-12-04 07:11 . 2007-12-19 20:14 2007-12-04 07:10 . 2007-12-04 18:16 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-18 18:44 --------- d-----w C:\Program Files\Lx_cats 2007-12-15 14:48 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-12-15 14:48 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-12-03 20:43 14,656 ----a-w C:\WINDOWS\gdrv.sys 2007-12-03 20:43 --------- d-----w C:\Documents and Settings\michal\Dane aplikacji\FaxCtr 2007-12-03 20:41 315,392 ----a-w C:\WINDOWS\HideWin.exe 2007-12-03 20:41 --------- d-----w C:\Program Files\Realtek 2007-12-03 20:41 --------- d-----w C:\Program Files\DIFX 2007-12-03 20:26 --------- d-----w C:\Program Files\RALINK 2007-12-03 20:25 --------- d-----w C:\Program Files\Lexmark_P910 Series 2007-12-03 20:25 --------- d-----w C:\Program Files\Lexmark P910 Series 2007-12-03 20:25 --------- d-----w C:\Program Files\Lexmark Fax Solutions 2007-12-03 20:25 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\FaxCtr 2007-12-03 20:19 --------- d-----w C:\Program Files\microsoft frontpage 2007-12-03 20:18 --------- d-----w C:\Program Files\Usługi online 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-10-29 22:44 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll 2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll 2007-10-04 16:14 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll 2007-10-04 16:14 8,491,008 ----a-w C:\WINDOWS\system32\nvcpl.dll 2007-10-04 16:14 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe 2007-10-04 16:14 6,750,208 ----a-w C:\WINDOWS\system32\nvoglnt.dll 2007-10-04 16:14 6,344,704 ----a-w C:\WINDOWS\system32\nvdisps.dll 2007-10-04 16:14 5,783,424 ----a-w C:\WINDOWS\system32\nv4_disp.dll 2007-10-04 16:14 5,509,120 ----a-w C:\WINDOWS\system32\nvdispsr.dll 2007-10-04 16:14 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll 2007-10-04 16:14 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2007-10-04 16:14 364,544 ----a-w C:\WINDOWS\system32\nvapi.dll 2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcodins.dll 2007-10-04 16:14 36,864 ----a-w C:\WINDOWS\system32\nvcod.dll 2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvrshe.dll 2007-10-04 16:14 327,680 ----a-w C:\WINDOWS\system32\nvrsar.dll 2007-10-04 16:14 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll 2007-10-04 16:14 3,629,056 ----a-w C:\WINDOWS\system32\nvvitvsr.dll 2007-10-04 16:14 3,551,232 ----a-w C:\WINDOWS\system32\nvvitvs.dll 2007-10-04 16:14 3,334,144 ----a-w C:\WINDOWS\system32\nvgames.dll 2007-10-04 16:14 3,166,208 ----a-w C:\WINDOWS\system32\nvgamesr.dll 2007-10-04 16:14 290,816 ----a-w C:\WINDOWS\system32\nvwrsth.dll 2007-10-04 16:14 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll 2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrsfr.dll 2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrses.dll 2007-10-04 16:14 282,624 ----a-w C:\WINDOWS\system32\nvrsel.dll 2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvrsit.dll 2007-10-04 16:14 278,528 ----a-w C:\WINDOWS\system32\nvrsde.dll 2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrspt.dll 2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrsnl.dll 2007-10-04 16:14 274,432 ----a-w C:\WINDOWS\system32\nvrsesm.dll 2007-10-04 16:14 270,336 ----a-w C:\WINDOWS\system32\nvrsru.dll 2007-10-04 16:14 266,240 ----a-w C:\WINDOWS\system32\nvrsptb.dll 2007-10-04 16:14 266,240 ----a-w C:\WINDOWS\system32\nvrsja.dll 2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrstr.dll 2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrssl.dll 2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrssk.dll 2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll 2007-10-04 16:14 258,048 ----a-w C:\WINDOWS\system32\nvrshu.dll 2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsth.dll 2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrssv.dll 2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrspl.dll 2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsno.dll 2007-10-04 16:14 253,952 ----a-w C:\WINDOWS\system32\nvrsda.dll 2007-10-04 16:14 249,856 ----a-w C:\WINDOWS\system32\nvrsfi.dll 2007-10-04 16:14 249,856 ----a-w C:\WINDOWS\system32\nvrscs.dll 2007-10-04 16:14 245,760 ----a-w C:\WINDOWS\system32\nvrseng.dll 2007-10-04 16:14 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll 2007-10-04 16:14 225,280 ----a-w C:\WINDOWS\system32\nvrszhc.dll 2007-10-04 16:14 2,854,912 ----a-w C:\WINDOWS\system32\nvmoblsr.dll 2007-10-04 16:14 2,441,216 ----a-w C:\WINDOWS\system32\nvwssr.dll 2007-10-04 16:14 2,371,584 ----a-w C:\WINDOWS\system32\nvwss.dll 2007-10-04 16:14 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll 2007-10-04 16:14 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe 2007-10-04 16:14 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe 2007-10-04 16:14 126,976 ----a-w C:\WINDOWS\system32\nvrszht.dll 2007-10-04 16:14 1,150,976 ----a-w C:\WINDOWS\system32\nvmobls.dll 2007-10-04 16:14 1,073,152 ----a-w C:\WINDOWS\system32\nvcpluir.dll 2007-09-20 08:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe 2007-09-20 08:55 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe 2007-09-20 08:55 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE~\Browser Helper Objects{17A1DBB5-DAD8-4E78-BF7E-9BE4B965408B}] 2007-12-16 00:10 223232 --a------ C:\WINDOWS\pmspl.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 13:00] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-11-14 11:54] “BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe” [2007-09-20 15:35] “DAEMON Tools”=“C:\Program Files\DAEMON Tools\daemon.exe” [2007-08-29 16:09] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “lxbymon.exe”=“C:\Program Files\Lexmark P910 Series\lxbymon.exe” [2005-01-18 10:53] “FaxCenterServer”=“C:\Program Files\Lexmark Fax Solutions\fm3032.exe” [2004-11-22 13:29] “EzPrint”=“C:\Program Files\Lexmark P910 Series\ezprint.exe” [2004-09-17 14:24] “NvCplDaemon”=“RUNDLL32.exe” [2004-08-04 13:00 C:\WINDOWS\system32\rundll32.exe] “nwiz”=“nwiz.exe” [2007-06-28 17:43 C:\WINDOWS\system32\nwiz.exe] “RTHDCPL”=“RTHDCPL.EXE” [2007-01-30 11:54 C:\WINDOWS\RTHDCPL.exe] “SkyTel”=“SkyTel.EXE” [2006-05-16 11:04 C:\WINDOWS\SkyTel.exe] “Flashget”=“C:\Program Files\FlashGet\FlashGet.exe” [2007-09-25 09:10] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 12:06] “LXBYCATS”=“C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll” [2004-11-02 16:13] “NvMediaCenter”=“RUNDLL32.exe” [2004-08-04 13:00 C:\WINDOWS\system32\rundll32.exe] “NeroFilterCheck”=“C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe” [2007-03-01 15:57] “NBKeyScan”=“C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe” [2007-09-20 09:51] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2007-10-10 06:28] “GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-27 00:47] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 13:00] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26] RaConfig.lnk - C:\WINDOWS\system32\RaConfig.exe [2007-12-03 21:26:13] R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 09:51] R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs [] R3 RT2400;RT2400 Wireless Driver;C:\WINDOWS\system32\DRIVERS\RT2400.sys [2004-03-01 18:31] S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2007-12-03 21:43] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the ‘Scheduled Tasks’ folder “2007-12-14 16:15:36 C:\WINDOWS\Tasks\1-Click Maintenance.job” - C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-19 20:38:55 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run LXBYCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll,_RunDLLEntry@16??? scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-19 20:39:09 . 2007-12-13 02:01:37 — E O F —