“mateo” - 2007-07-05 8:57:28 - ComboFix 07-07-04.4 - Dodatek Service Pack 2 ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\DOCUME~1\ALLUSE~1\DANEAP~1.\TEMP ((((((((((((((((((((((((( Files Created from 2007-06-05 to 2007-07-05 ))))))))))))))))))))))))))))))) 2007-07-05 08:50 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-07-05 08:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2007-07-05 08:50 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2007-07-05 00:30 42,743 --a------ C:\WINDOWS\mssadv.dll 2007-07-01 15:52 450 --a------ C:\WINDOWS\system32\tmp.reg 2007-06-20 21:01 2007-06-18 21:53 2007-06-18 21:52 2007-06-18 21:52 2007-06-18 15:20 2007-06-18 15:19 2007-06-18 15:19 2007-06-17 13:27 2007-06-17 13:27 2007-06-17 13:26 2007-06-17 13:26 2007-06-17 13:26 2007-06-17 13:26 2007-06-17 13:25 6,144 --a------ C:\WINDOWS\system32\drivers\k750cm.sys 2007-06-17 13:25 5,744 --a------ C:\WINDOWS\system32\drivers\k750wh.sys 2007-06-17 13:25 2007-06-17 13:25 2007-06-15 14:54 2007-06-14 23:20 2007-06-14 23:17 569,344 -ra------ C:\WINDOWS\system32\imagr5.dll 2007-06-14 23:17 544,768 -ra------ C:\WINDOWS\system32\imagx5.dll 2007-06-14 23:17 38,912 -ra------ C:\WINDOWS\system32\picn20.dll 2007-06-14 23:17 283,920 -ra------ C:\WINDOWS\system32\ImagXpr5.dll 2007-06-14 23:17 155,648 -ra------ C:\WINDOWS\system32\NeroCheck.exe 2007-06-14 23:17 2007-06-14 23:17 2007-06-13 18:46 2007-06-12 22:18 2007-06-12 22:18 2007-06-12 18:32 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-06-12 18:32 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-06-12 18:32 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-06-12 18:31 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-06-12 18:31 524,567 --a------ C:\WINDOWS\system32\ati3d1ag.dll 2007-06-12 18:31 516,768 --a------ C:\WINDOWS\system32\ativvaxx.dll 2007-06-12 18:31 385,152 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys 2007-06-12 18:31 229,376 --a------ C:\WINDOWS\system32\ati2cqag.dll 2007-06-12 18:31 215,040 --a------ C:\WINDOWS\system32\ati2dvag.dll 2007-06-12 18:31 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys 2007-06-12 18:31 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll 2007-06-12 18:29 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-06-12 18:29 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-06-12 18:29 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-06-12 18:29 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-06-12 18:29 8,704 --a------ C:\WINDOWS\system32\batt.dll 2007-06-12 18:29 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-06-12 18:29 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-06-12 18:29 70,144 --a------ C:\WINDOWS\NOTEPAD.EXE 2007-06-12 18:29 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-06-12 18:29 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-06-12 18:29 69,552 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-06-12 18:29 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-06-12 18:29 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-06-12 18:29 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll 2007-06-12 18:29 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-06-12 18:29 5,632 --a------ C:\WINDOWS\system32\kbdro.dll 2007-06-12 18:29 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll 2007-06-12 18:29 5,120 --a------ C:\WINDOWS\system\SHELL.DLL 2007-06-12 18:29 33,376 --a------ C:\WINDOWS\system\COMMDLG.DLL 2007-06-12 18:29 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-06-12 18:29 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL 2007-06-12 18:29 19,200 --a------ C:\WINDOWS\system\TAPI.DLL 2007-06-12 18:29 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll 2007-06-12 18:29 15,360 --a------ C:\WINDOWS\TASKMAN.EXE 2007-06-12 18:29 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-06-12 18:29 127,008 --a------ C:\WINDOWS\system\MSVIDEO.DLL 2007-06-12 18:29 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys 2007-06-12 18:29 109,488 --a------ C:\WINDOWS\system\AVIFILE.DLL 2007-06-12 18:29 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 2007-06-12 18:29 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-12 14:47:19 49,492 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-12 14:47:19 355,486 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-12 14:40:30 -------- d-----w C:\Program Files\Usługi online ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-14 18:54] “mssadv.exe”="?" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-05-10 16:36] “mssadv.exe”="" [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2007-05-30 14:29] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg!AVG Anti-Spyware] “C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” /minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiPTA] atiptaxx.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare] “C:\Program Files\BearShare\BearShare.exe” /pause [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydarVisionDesktopManager] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] “C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” /startoptions ************************************************************************** catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-05 08:58:16 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-05 8:58:44 — E O F —