“Big” - 07-03-19 15:15:13 Dodatek Service Pack 2 ComboFix 07-03-15.2 - Running from: “C:\Documents and Settings\Big\Pulpit” ((((((((((((((((((((((((((((((( Files Created from 2007-02-19 to 2007-03-19 )))))))))))))))))))))))))))))))))) 2007-03-19 13:59 2007-03-18 09:44 305,664 --a------ C:\WINDOWS\IsUn0415.exe 2007-03-18 09:44 0 -rahs---- C:\MSDOS.SYS 2007-03-18 09:44 0 -rahs---- C:\IO.SYS 2007-03-17 11:13 2007-03-16 12:49 2007-03-16 11:01 2007-03-14 13:37 2007-03-14 12:27 2007-03-11 20:14 2007-03-10 12:17 2007-03-09 13:27 2007-03-08 18:26 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll 2007-03-08 18:26 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-03-08 18:26 2007-03-08 18:25 298,496 --a------ C:\WINDOWS\unin0415.exe 2007-03-08 18:25 2007-03-08 17:55 2007-03-07 20:26 2007-03-07 16:50 2007-03-07 10:59 2007-03-06 11:17 2007-03-06 10:19 2007-03-06 09:25 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-03-06 09:25 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-03-05 14:42 2007-03-04 12:23 2007-03-03 01:44 2007-03-02 11:32 2007-03-02 10:26 2007-03-02 09:28 2007-03-01 23:03 2007-03-01 14:10 2007-03-01 10:57 990 --a------ C:\WINDOWS\system32\winpoa06.sys 2007-02-28 21:06 2007-02-28 21:06 2007-02-28 16:55 2007-02-27 22:57 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-02-27 11:42 2007-02-27 11:39 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll 2007-02-27 11:39 2007-02-27 11:39 2007-02-27 11:35 2007-02-27 11:34 2007-02-26 20:49 2007-02-26 18:14 2007-02-26 17:26 2007-02-25 20:48 237,568 --a------ C:\WINDOWS\system32\OggDS.dll 2007-02-25 20:47 921,600 --a------ C:\WINDOWS\system32\vorbisenc.dll 2007-02-25 20:47 45,056 --a------ C:\WINDOWS\system32\ogg.dll 2007-02-25 20:47 188,416 --a------ C:\WINDOWS\system32\vorbis.dll 2007-02-25 20:47 1,415,680 --a------ C:\WINDOWS\system32\WMV9VCM.dll 2007-02-25 20:46 9,216 --a------ C:\WINDOWS\system32\cpuinf32.dll 2007-02-25 20:46 245,760 --a------ C:\WINDOWS\system32\mplvpx.dll 2007-02-25 20:45 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-02-25 19:50 2007-02-25 14:01 2007-02-24 23:35 2007-02-24 15:20 2007-02-24 01:04 4,673 --a------ C:\WINDOWS\mozver.dat 2007-02-24 01:04 4 --a------ C:\WINDOWS\system32\proc-503976190.bin 2007-02-24 01:04 2007-02-24 01:04 2007-02-24 01:04 2007-02-24 01:04 2007-02-24 00:11 2007-02-23 23:47 2007-02-23 18:59 2007-02-23 18:13 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-02-23 18:12 2007-02-23 18:11 2007-02-23 15:09 2007-02-23 11:46 2007-02-23 10:56 2007-02-23 00:22 2007-02-23 00:22 2007-02-22 20:36 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat 2007-02-22 15:43 2007-02-22 15:43 2007-02-22 14:45 2007-02-22 09:48 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-02-22 09:18 2007-02-22 00:09 2007-02-21 23:59 2,359,296 --ah----- C:\DOCUME~1\Tomek\NTUSER.DAT 2007-02-21 23:59 2007-02-21 23:59 2007-02-21 23:59 2007-02-21 23:59 2007-02-21 23:59 2007-02-21 23:59 2007-02-21 23:59 2007-02-21 23:59 2007-02-21 23:55 2007-02-21 23:48 1,835,008 --ah----- C:\DOCUME~1\Piotrek\NTUSER.DAT 2007-02-21 23:48 2007-02-21 23:48 2007-02-21 23:48 2007-02-21 23:48 2007-02-21 23:48 2007-02-21 23:48 2007-02-21 23:48 2007-02-21 23:42 2007-02-21 23:38 2,359,296 --ah----- C:\DOCUME~1\Majka\NTUSER.DAT 2007-02-21 23:38 2007-02-21 23:38 2007-02-21 23:38 2007-02-21 23:38 2007-02-21 23:38 2007-02-21 23:38 2007-02-21 23:38 2007-02-21 23:32 2007-02-21 23:29 2007-02-21 23:20 1,835,008 --ah----- C:\DOCUME~1\Sawciu\NTUSER.DAT 2007-02-21 23:20 2007-02-21 23:20 2007-02-21 23:20 2007-02-21 23:20 2007-02-21 23:20 2007-02-21 23:20 2007-02-21 23:20 2007-02-21 22:22 2007-02-21 22:19 2007-02-21 22:19 2007-02-21 22:12 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll 2007-02-21 22:11 2007-02-21 22:11 2007-02-21 22:11 2007-02-21 22:04 2007-02-21 21:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-02-21 21:56 2007-02-21 21:55 2007-02-21 21:55 2007-02-21 21:55 2007-02-21 21:55 2007-02-21 21:55 2007-02-21 21:55 2007-02-21 21:54 69,120 --a------ C:\WINDOWS\system32\wlanapi.dll 2007-02-21 21:54 62,336 --a------ C:\WINDOWS\system32\drivers\rspndr.sys 2007-02-21 21:54 10,752 --a------ C:\WINDOWS\system32\rspndr.exe 2007-02-21 21:54 2007-02-21 21:53 2007-02-21 21:53 2007-02-21 21:52 2,111,096 --a------ C:\WINDOWS\system32\NPSWF32.dll 2007-02-21 21:52 190,072 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe 2007-02-21 21:52 2007-02-21 21:50 6,144 --a------ C:\WINDOWS\system32\kbdpash.dll 2007-02-21 21:50 6,144 --a------ C:\WINDOWS\system32\kbdnepr.dll 2007-02-21 21:50 6,144 --a------ C:\WINDOWS\system32\kbdiultn.dll 2007-02-21 21:50 6,144 --a------ C:\WINDOWS\system32\kbdbhc.dll 2007-02-21 21:50 18,200 --a------ C:\WINDOWS\system32\wups2.dll 2007-02-21 21:50 2007-02-21 21:50 2007-02-21 21:48 2007-02-21 21:36 2007-02-21 21:35 2007-02-21 21:34 737,280 --a------ C:\WINDOWS\iun6002.exe 2007-02-21 21:25 2007-02-21 21:24 2007-02-21 21:23 2007-02-21 21:12 2007-02-21 21:10 2007-02-21 21:04 2007-02-21 21:04 2007-02-21 21:01 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys 2007-02-21 21:01 298,104 --a------ C:\WINDOWS\system32\imon.dll 2007-02-21 21:01 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys 2007-02-21 19:50 6,272 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-02-21 19:50 577,536 -ra------ C:\WINDOWS\soundman.exe 2007-02-21 19:50 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-02-21 19:50 49,152 -ra------ C:\WINDOWS\system32\ChCfg.exe 2007-02-21 19:50 4,096 --a------ C:\WINDOWS\system32\ksuser.dll 2007-02-21 19:50 4,017,536 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys 2007-02-21 19:50 315,392 -ra------ C:\WINDOWS\alcupd.exe 2007-02-21 19:50 217,088 -ra------ C:\WINDOWS\Alcrmv.exe 2007-02-21 19:50 143,360 -ra------ C:\WINDOWS\system32\RtlCPAPI.dll 2007-02-21 19:50 10,528,768 -ra------ C:\WINDOWS\system32\RTLCPL.exe 2007-02-21 19:50 2007-02-21 19:50 2007-02-21 19:50 2007-02-21 19:50 2007-02-21 19:49 93,568 -ra------ C:\WINDOWS\system32\drivers\nvata.sys 2007-02-21 19:49 33,280 -ra------ C:\WINDOWS\system32\NVCOI.DLL 2007-02-21 19:49 289,792 -ra------ C:\WINDOWS\system32\idecoins.dll 2007-02-21 19:49 289,792 -ra------ C:\WINDOWS\system32\idecoi.dll 2007-02-21 19:49 176,128 --a------ C:\WINDOWS\system32\nvuide.exe 2007-02-21 19:48 9,728 -ra------ C:\WINDOWS\system32\bdco1ins.dll 2007-02-21 19:48 9,728 -ra------ C:\WINDOWS\system32\bdco1.dll 2007-02-21 19:48 36,352 -ra------ C:\WINDOWS\system32\drivers\AmdK8.sys 2007-02-21 19:48 33,536 -ra------ C:\WINDOWS\system32\drivers\NVENETFD.sys 2007-02-21 19:48 32,256 -ra------ C:\WINDOWS\system32\nvconrm.dll 2007-02-21 19:48 261,888 -ra------ C:\WINDOWS\system32\drivers\nvnrm.sys 2007-02-21 19:48 208,256 -ra------ C:\WINDOWS\system32\drivers\nvsnpu.sys 2007-02-21 19:48 201,728 -ra------ C:\WINDOWS\system32\fdco1ins.dll 2007-02-21 19:48 201,728 -ra------ C:\WINDOWS\system32\fdco1.dll 2007-02-21 19:48 176,128 --a------ C:\WINDOWS\system32\nvusmb.exe 2007-02-21 19:48 176,128 --a------ C:\WINDOWS\system32\nvunrm.exe 2007-02-21 19:48 12,928 -ra------ C:\WINDOWS\system32\drivers\nvnetbus.sys 2007-02-21 19:48 2007-02-21 19:46 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe 2007-02-21 19:46 2007-02-21 19:45 5,306 --a------ C:\WINDOWS\system32\drivers\TBPanel.sys 2007-02-21 19:45 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2007-02-21 19:45 2007-02-21 19:45 2007-02-21 18:27 3,407,872 --ah----- C:\DOCUME~1\Big\NTUSER.DAT 2007-02-21 18:27 2007-02-21 18:27 2007-02-21 18:27 2007-02-21 18:27 2007-02-21 18:27 2007-02-21 18:27 2007-02-21 18:27 2007-02-21 18:25 233,472 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT 2007-02-21 18:25 2007-02-21 18:25 2007-02-21 18:25 2007-02-21 18:14 233,472 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT 2007-02-21 18:14 2007-02-21 18:14 2007-02-21 18:13 262,144 —h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT 2007-02-21 18:13 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-02-21 18:13 2007-02-21 18:12 112,128 --a------ C:\WINDOWS\system32\mapi32.dll 2007-02-21 18:12 2007-02-21 18:11 67,584 --a------ C:\WINDOWS\system32\acctres.dll 2007-02-21 18:11 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll 2007-02-21 18:11 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll 2007-02-21 18:11 11,264 --a------ C:\WINDOWS\system32\atrace.dll 2007-02-21 18:11 2007-02-21 18:11 2007-02-21 18:11 2007-02-21 18:11 2007-02-21 18:11 2007-02-21 18:11 2007-02-21 18:11 2007-02-21 18:11 2007-02-21 18:11 2007-02-21 18:10 86,016 --a------ C:\WINDOWS\system32\isign32.dll 2007-02-21 18:10 81,920 --a------ C:\WINDOWS\system32\ils.dll 2007-02-21 18:10 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll 2007-02-21 18:10 73,728 --a------ C:\WINDOWS\system32\icwdial.dll 2007-02-21 18:10 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys 2007-02-21 18:10 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll 2007-02-21 18:10 69,632 --a------ C:\WINDOWS\system32\msconf.dll 2007-02-21 18:10 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-02-21 18:10 67,584 --a------ C:\WINDOWS\system32\srclient.dll 2007-02-21 18:10 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll 2007-02-21 18:10 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll 2007-02-21 18:10 49,664 --a------ C:\WINDOWS\system32\inetres.dll 2007-02-21 18:10 466,200 --a------ C:\WINDOWS\system32\wuapi.dll 2007-02-21 18:10 45,568 --a------ C:\WINDOWS\system32\safrslv.dll 2007-02-21 18:10 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll 2007-02-21 18:10 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll 2007-02-21 18:10 41,240 --a------ C:\WINDOWS\system32\wups.dll 2007-02-21 18:10 382,464 --a------ C:\WINDOWS\system32\qmgr.dll 2007-02-21 18:10 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll 2007-02-21 18:10 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe 2007-02-21 18:10 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll 2007-02-21 18:10 29,696 --a------ C:\WINDOWS\system32\safrdm.dll 2007-02-21 18:10 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll 2007-02-21 18:10 278,528 --a------ C:\WINDOWS\system32\mstask.dll 2007-02-21 18:10 278,528 --a------ C:\WINDOWS\system32\inetcfg.dll 2007-02-21 18:10 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll 2007-02-21 18:10 240,128 --a------ C:\WINDOWS\system32\srrstr.dll 2007-02-21 18:10 23,640 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-02-21 18:10 23,040 --a------ C:\WINDOWS\system32\fltMc.exe 2007-02-21 18:10 195,352 --a------ C:\WINDOWS\system32\wuaueng1.dll 2007-02-21 18:10 192,000 --a------ C:\WINDOWS\system32\schedsvc.dll 2007-02-21 18:10 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll 2007-02-21 18:10 175,384 --a------ C:\WINDOWS\system32\wuauclt1.exe 2007-02-21 18:10 173,536 --a------ C:\WINDOWS\system32\wuweb.dll 2007-02-21 18:10 171,008 --a------ C:\WINDOWS\system32\srsvc.dll 2007-02-21 18:10 16,896 --a------ C:\WINDOWS\system32\fltlib.dll 2007-02-21 18:10 128,768 --a------ C:\WINDOWS\system32\drivers\fltMgr.sys 2007-02-21 18:10 128,280 --a------ C:\WINDOWS\system32\wucltui.dll 2007-02-21 18:10 125,208 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-02-21 18:10 12,288 --a------ C:\WINDOWS\system32\mstinit.exe 2007-02-21 18:10 105,984 --a------ C:\WINDOWS\system32\msoert2.dll 2007-02-21 18:10 1,343,768 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-02-21 18:10 2007-02-21 18:10 2007-02-21 18:09 97,792 --a------ C:\WINDOWS\system32\comrepl.dll 2007-02-21 18:09 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll 2007-02-21 18:09 94,720 --a------ C:\WINDOWS\system32\tscfgwmi.dll 2007-02-21 18:09 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll 2007-02-21 18:09 9,728 --a------ C:\WINDOWS\system32\reset.exe 2007-02-21 18:09 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll 2007-02-21 18:09 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll 2007-02-21 18:09 80,896 --a------ C:\WINDOWS\system32\charmap.exe 2007-02-21 18:09 73,216 --a------ C:\WINDOWS\system32\avwav.dll 2007-02-21 18:09 67,072 --a------ C:\WINDOWS\system32\rdshost.exe 2007-02-21 18:09 655,360 --a------ C:\WINDOWS\system32\mstscax.dll 2007-02-21 18:09 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll 2007-02-21 18:09 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe 2007-02-21 18:09 605,696 --a------ C:\WINDOWS\system32\getuname.dll 2007-02-21 18:09 60,928 --a------ C:\WINDOWS\system32\remotepg.dll 2007-02-21 18:09 60,416 --a------ C:\WINDOWS\system32\colbact.dll 2007-02-21 18:09 6,144 --a------ C:\WINDOWS\system32\msdtc.exe 2007-02-21 18:09 59,392 --a------ C:\WINDOWS\system32\stclient.dll 2007-02-21 18:09 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll 2007-02-21 18:09 58,880 --a------ C:\WINDOWS\system32\licwmi.dll 2007-02-21 18:09 57,344 --a------ C:\WINDOWS\system32\sol.exe 2007-02-21 18:09 56,320 --a------ C:\WINDOWS\system32\servdeps.dll 2007-02-21 18:09 55,808 --a------ C:\WINDOWS\system32\freecell.exe 2007-02-21 18:09 539,648 --a------ C:\WINDOWS\system32\comuid.dll 2007-02-21 18:09 539,136 --a------ C:\WINDOWS\system32\spider.exe 2007-02-21 18:09 5,632 --a------ C:\WINDOWS\system32\write.exe 2007-02-21 18:09 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe 2007-02-21 18:09 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll 2007-02-21 18:09 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe 2007-02-21 18:09 44,544 --a------ C:\WINDOWS\system32\hticons.dll 2007-02-21 18:09 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll 2007-02-21 18:09 408,576 --a------ C:\WINDOWS\system32\mstsc.exe 2007-02-21 18:09 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys 2007-02-21 18:09 4,608 --a------ C:\WINDOWS\system32\rdpcfgex.dll 2007-02-21 18:09 4,096 --a------ C:\WINDOWS\system32\mtxex.dll 2007-02-21 18:09 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll 2007-02-21 18:09 351,744 --a------ C:\WINDOWS\system32\hypertrm.dll 2007-02-21 18:09 35,328 --a------ C:\WINDOWS\system32\winchat.exe 2007-02-21 18:09 345,088 --a------ C:\WINDOWS\system32\mspaint.exe 2007-02-21 18:09 33,792 --a------ C:\WINDOWS\system32\regini.exe 2007-02-21 18:09 296,448 --a------ C:\WINDOWS\system32\termsrv.dll 2007-02-21 18:09 25,600 --a------ C:\WINDOWS\system32\comaddin.dll 2007-02-21 18:09 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll 2007-02-21 18:09 231,424 --a------ C:\WINDOWS\system32\avtapi.dll 2007-02-21 18:09 225,792 --a------ C:\WINDOWS\system32\catsrv.dll 2007-02-21 18:09 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe 2007-02-21 18:09 22,528 --a------ C:\WINDOWS\system32\msg.exe 2007-02-21 18:09 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys 2007-02-21 18:09 20,992 --a------ C:\WINDOWS\system32\qprocess.exe 2007-02-21 18:09 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll 2007-02-21 18:09 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys 2007-02-21 18:09 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll 2007-02-21 18:09 187,904 --a------ C:\WINDOWS\system32\cmprops.dll 2007-02-21 18:09 187,904 --a------ C:\WINDOWS\system32\accwiz.exe 2007-02-21 18:09 17,920 --a------ C:\WINDOWS\system32\tsshutdn.exe 2007-02-21 18:09 17,920 --a------ C:\WINDOWS\system32\mmfutil.dll 2007-02-21 18:09 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe 2007-02-21 18:09 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll 2007-02-21 18:09 16,384 --a------ C:\WINDOWS\system32\tskill.exe 2007-02-21 18:09 16,384 --a------ C:\WINDOWS\system32\rwinsta.exe 2007-02-21 18:09 16,384 --a------ C:\WINDOWS\system32\avmeter.dll 2007-02-21 18:09 15,872 --a------ C:\WINDOWS\system32\logoff.exe 2007-02-21 18:09 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll 2007-02-21 18:09 15,360 --a------ C:\WINDOWS\system32\tsdiscon.exe 2007-02-21 18:09 15,360 --a------ C:\WINDOWS\system32\tscon.exe 2007-02-21 18:09 15,360 --a------ C:\WINDOWS\system32\shadow.exe 2007-02-21 18:09 147,968 --a------ C:\WINDOWS\system32\rdchost.dll 2007-02-21 18:09 147,456 --a------ C:\WINDOWS\system32\comsnap.dll 2007-02-21 18:09 141,824 --a------ C:\WINDOWS\system32\sessmgr.exe 2007-02-21 18:09 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys 2007-02-21 18:09 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe 2007-02-21 18:09 132,608 --a------ C:\WINDOWS\system32\sndrec32.exe 2007-02-21 18:09 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe 2007-02-21 18:09 128,000 --a------ C:\WINDOWS\system32\mshearts.exe 2007-02-21 18:09 124,928 --a------ C:\WINDOWS\system32\mplay32.exe 2007-02-21 18:09 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys 2007-02-21 18:09 119,808 --a------ C:\WINDOWS\system32\winmine.exe 2007-02-21 18:09 115,200 --a------ C:\WINDOWS\system32\calc.exe 2007-02-21 18:09 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll 2007-02-21 18:09 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll 2007-02-21 18:09 11,264 --a------ C:\WINDOWS\system32\icaapi.dll 2007-02-21 18:09 103,424 --a------ C:\WINDOWS\system32\clipbrd.exe 2007-02-21 18:09 1,267,712 --a------ C:\WINDOWS\system32\comsvcs.dll 2007-02-21 18:09 1,225 --a------ C:\WINDOWS\system32\usrlogon.cmd 2007-02-21 18:09 2007-02-21 18:09 2007-02-21 18:09 2007-02-21 18:09 2007-02-21 18:09 2007-02-21 18:09 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-03-16 11:03 12400 --a------ C:\WINDOWS\system32\drivers\secdrv.sys 2007-03-06 11:18 88224 --a------ C:\WINDOWS\system32\perfc015.dat 2007-03-06 11:18 497524 --a------ C:\WINDOWS\system32\perfh015.dat 2007-03-02 13:16 2560 --a------ C:\WINDOWS\system32\bitcometres.dll 2007-02-21 18:11 -------- d-------- C:\Program Files\usugi online 2007-01-20 08:11 31644 --a------ C:\WINDOWS\system32\drivers\scdemu.sys 2007-01-08 19:01 17408 --a------ C:\WINDOWS\system32\corpol.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “NvCplDaemon”="“RUNDLL32.EXE” C:\WINDOWS\system32\NvCpl.dll,NvStartup" “nod32kui”="“D:\Antywir\Eset\nod32kui.exe” /WAITSERVICE" “DiskeeperSystray”="“D:\Defragmentacja\DkIcon.exe”" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] “Installed”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] “Installed”=“1” “NoChange”=“1” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] “Installed”=“1” [HKEY_USERS.default\software\microsoft\windows\currentversion\runonce] “tscuninstall”=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,6d,\ 33,32,5c,74,73,63,75,70,67,72,64,2e,65,78,65,00 “nlpo_01”=hex(2):63,6d,64,2e,65,78,65,20,2f,63,20,6d,64,20,22,25,55,53,45,52,\ 50,52,4f,46,49,4c,45,25,5c,55,73,74,61,77,69,65,6e,69,61,20,6c,6f,6b,61,6c,\ 6e,65,5c,54,65,6d,70,22,00 “nlpo_02”=hex(2):72,75,6e,64,6c,6c,33,32,20,61,64,76,70,61,63,6b,2e,64,6c,6c,\ 2c,44,65,6c,4e,6f,64,65,52,75,6e,44,4c,4c,33,32,20,22,25,53,79,73,74,65,6d,\ 52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,32,5c,64,6c,6c,63,61,63,68,65,22,00 “nlpo_03”=hex(2):63,6d,64,2e,65,78,65,20,2f,63,20,6d,64,20,22,25,53,79,73,74,\ 65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,32,5c,64,6c,6c,63,61,63,68,65,\ 22,00 “nlpo_04”=hex(2):63,6d,64,2e,65,78,65,20,2f,43,20,6d,6f,76,65,20,2f,59,20,22,\ 25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,32,5c,73,79,73,\ 73,65,74,75,62,2e,64,6c,6c,22,20,22,25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,\ 53,79,73,74,65,6d,33,32,5c,73,79,73,73,65,74,75,70,2e,64,6c,6c,22,00 “nlpo_05”=hex(2):72,75,6e,64,6c,6c,33,32,20,61,64,76,70,61,63,6b,2e,64,6c,6c,\ 2c,4c,61,75,6e,63,68,49,4e,46,53,65,63,74,69,6f,6e,20,6e,6c,69,74,65,2e,69,\ 6e,66,2c,6e,4c,69,74,65,52,65,67,00 “nlpo_06”=hex(2):72,75,6e,64,6c,6c,33,32,20,61,64,76,70,61,63,6b,2e,64,6c,6c,\ 2c,4c,61,75,6e,63,68,49,4e,46,53,65,63,74,69,6f,6e,20,6e,6c,69,74,65,2e,69,\ 6e,66,2c,53,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] “WPDShServiceObj”="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “HideClock”=dword:00000000 “NoManageMyComputerVerb”=dword:00000000 “NoLowDiskSpaceChecks”=dword:00000000 “NoCDBurning”=dword:00000000 “NoStartMenuPinnedList”=dword:00000000 “NoStartMenuMFUprogramsList”=dword:00000000 “NoUserNameInStartMenu”=dword:00000000 “StartmenuLogoff”=dword:00000000 “NoStartMenuSubFolders”=dword:00000000 “NoCommonGroups”=dword:00000000 “NoRecentDocsMenu”=dword:00000000 “ClearRecentDocsOnExit”=dword:00000000 “NoPrinterTabs”=dword:00000000 “NoDeletePrinter”=dword:00000000 “NoAddPrinter”=dword:00000000 “NoPrinters”=dword:00000000 “NoNetworkConnections”=dword:00000000 “NoFavoritesMenu”=dword:00000000 “NoRun”=dword:00000000 “NoFind”=dword:00000000 “NoClose”=dword:00000000 “NoSetFolders”=dword:00000000 “NoSMHelp”=dword:00000000 “NoChangeStartMenu”=dword:00000000 “NoViewContextMenu”=dword:00000000 “NoFileMenu”=dword:00000000 “NoShellSearchButton”=dword:00000000 “NoToolbarCustomize”=dword:00000000 “NoRecentDocsNetHood”=dword:00000000 “NoChangeAnimation”=dword:00000000 “NoChangeKeyboardNavigationIndicators”=dword:00000000 “NoThemesTab”=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 ******************************************************************** catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files … C:\Program Files\Microsoft Office\Office12\1045\WINWORD.DEV.HXS 6828032 bytes C:\Program Files\Microsoft Office\Office12\1045\WINWORD.DEV_COL.HXC 4096 bytes C:\Program Files\Microsoft Office\Office12\1045\WINWORD.DEV_COL.HXT 216 bytes C:\Program Files\Microsoft Office\Office12\1045\WINWORD.DEV_F_COL.HXK 120 bytes C:\Program Files\Microsoft Office\Office12\1045\WINWORD.DEV_K_COL.HXK 120 bytes C:\Program Files\Microsoft Office\Office12\1045\WINWORD_COL.HXC 4096 bytes C:\Program Files\Microsoft Office\Office12\1045\WINWORD_COL.HXT 208 bytes C:\Program Files\Microsoft Office\Office12\1045\WINWORD_F_COL.HXK 120 bytes scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 8 ******************************************************************** Completion time: 07-03-19 15:16:04