ComboFix 07-12-21.4 - Dawid 2007-12-27 0:26:15.7 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.48.1045.18.161 [GMT 1:00] Running from: C:\Documents and Settings\Dawid\Pulpit\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-11-26 to 2007-12-26 ))))))))))))))))))))))))))))))) . 2007-12-25 22:30 . 2007-12-25 22:30 2007-12-25 20:05 . 2007-12-25 20:05 2007-12-25 19:57 . 2007-12-25 19:57 2007-12-25 19:55 . 2002-01-05 09:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll 2007-12-25 19:52 . 2007-12-25 19:52 2007-12-25 19:52 . 2007-12-25 19:52 249,856 --------- C:\WINDOWS\Setup1.exe 2007-12-25 19:52 . 2007-12-25 19:52 73,216 --a------ C:\WINDOWS\ST6UNST.EXE 2007-12-25 10:24 . 2007-12-25 22:33 2007-12-25 03:16 . 2007-12-25 19:44 2007-12-25 02:31 . 2007-12-25 19:44 2007-12-24 00:58 . 2007-12-24 01:00 2007-12-24 00:31 . 2007-12-24 00:31 2007-12-23 22:36 . 2007-12-23 22:36 2007-12-23 00:54 . 2007-12-23 00:54 2007-12-23 00:54 . 2007-12-23 00:54 16 --a------ C:\WINDOWS\nraesg.exe 2007-12-22 19:25 . 2007-12-22 19:25 32,229 --a------ C:\122207_192531.wma 2007-12-22 19:25 . 2007-12-22 19:25 5,717 --a------ C:\122207_192528.wma 2007-12-22 15:40 . 2007-12-22 15:40 2007-12-21 20:55 . 2007-12-21 20:55 169 --a------ C:\WINDOWS\RtlRack.ini 2007-12-21 20:33 . 2007-12-21 20:33 2007-12-21 20:33 . 2007-12-21 20:33 32 --a------ C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat 2007-12-21 20:32 . 2007-12-21 20:35 2007-12-21 20:31 . 2007-12-21 20:31 2007-12-21 20:31 . 2007-12-21 20:31 2007-12-21 20:31 . 2007-12-21 20:31 2007-12-20 23:21 . 2007-12-20 23:21 2007-12-20 23:19 . 2007-12-20 23:19 2007-12-20 23:19 . 2007-12-20 23:19 2007-12-20 16:29 . 2007-12-20 16:35 2007-12-18 16:33 . 2007-12-18 16:33 2007-12-18 16:33 . 2007-12-19 13:48 2007-12-18 16:33 . 2004-06-06 22:42 45,952 --a------ C:\WINDOWS\system32\drivers\filedisk.sys 2007-12-17 16:43 . 2007-12-17 16:43 2007-12-17 16:43 . 2007-12-17 16:43 2007-12-16 13:54 . 2007-12-16 13:54 2007-12-16 13:54 . 2007-12-16 13:54 2007-12-15 22:02 . 2007-12-15 22:02 2007-12-15 22:02 . 2006-11-12 11:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx 2007-12-14 22:53 . 2007-12-14 22:53 2007-12-12 17:51 . 2007-12-25 03:07 2007-12-12 17:51 . 2007-12-12 17:59 2007-12-12 16:57 . 2007-12-12 16:57 2007-12-12 16:56 . 2007-12-12 16:56 2007-12-12 16:56 . 2007-03-07 00:45 3,086,336 --a------ C:\WINDOWS\system32\NCMedia.dll 2007-12-12 16:56 . 2007-03-07 00:45 3,086,336 --a------ C:\WINDOWS\system32\flvvideo.dll 2007-12-12 16:56 . 2007-02-25 15:36 383,238 --a------ C:\WINDOWS\system32\libmp3lame-0.dll 2007-12-12 16:20 . 2007-12-12 16:20 2007-12-10 13:52 . 2007-12-10 13:52 2007-12-10 13:48 . 2007-12-10 13:48 2007-12-10 13:47 . 2007-12-10 13:47 2007-12-10 13:24 . 2007-12-10 13:28 2007-12-10 13:23 . 2007-12-10 13:23 2007-12-09 10:49 . 2007-12-09 10:49 2007-12-09 10:48 . 2007-12-09 10:48 2007-12-09 10:48 . 2007-12-09 10:48 2007-12-09 10:47 . 2006-06-14 10:38 336,128 -ra------ C:\WINDOWS\system32\drivers\Cap7134.sys 2007-12-08 18:42 . 2007-12-08 18:42 2007-12-08 14:31 . 2007-12-08 14:31 2007-12-07 10:43 . 2007-12-23 20:53 542 --a------ C:\WINDOWS\wcx_ftp.ini 2007-12-06 19:08 . 2007-12-06 19:08 2007-12-06 19:08 . 2007-12-06 19:08 2007-12-06 19:08 . 2007-12-06 19:08 2007-12-06 19:08 . 2004-06-03 03:40 294,400 -ra------ C:\WINDOWS\system32\SET39.tmp 2007-12-06 19:08 . 2004-06-03 03:40 18,432 -ra------ C:\WINDOWS\system32\SET43.tmp 2007-12-06 19:07 . 2001-07-05 17:19 164 --------- C:\WINDOWS\avrack.ini 2007-12-06 19:02 . 2007-12-06 19:02 2007-12-06 19:02 . 2007-12-06 19:02 2007-12-06 16:43 . 2007-12-06 16:43 2007-12-06 16:37 . 2007-12-06 16:37 2007-12-06 16:37 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2007-12-06 16:33 . 2007-12-06 16:33 2007-12-02 00:33 . 2007-12-02 00:33 2007-11-30 18:25 . 2007-11-30 18:25 2007-11-30 17:59 . 2007-11-30 18:06 2007-11-30 17:57 . 2007-11-30 18:19 2007-11-29 23:00 . 2007-11-29 22:59 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe 2007-11-29 23:00 . 2007-11-29 23:00 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys 2007-11-29 22:59 . 2007-11-29 22:59 2007-11-29 22:59 . 2007-11-29 22:59 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-26 23:22 --------- d-----w C:\Program Files\Eraser 2007-12-26 21:48 --------- d-----w C:\Program Files\SpeedFan 2007-12-26 18:26 --------- d-----w C:\Documents and Settings\Dawid\Dane aplikacji\uTorrent 2007-12-25 00:47 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-12-17 19:34 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\HPSSUPPLY 2007-12-13 20:14 --------- d-----w C:\Program Files\NAPI-PROJEKT 2007-12-12 18:28 --------- d-----w C:\Documents and Settings\Dawid\Dane aplikacji\Vso 2007-12-07 17:19 --------- d-----w C:\Program Files\Total Video Converter 2007-12-06 18:07 --------- d-----w C:\Program Files\AvRack 2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr 2007-11-25 08:33 --------- d-----w C:\Program Files\WapSter 2007-11-24 13:24 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll 2007-11-23 17:44 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Test Drive Unlimited 2007-11-23 15:55 --------- d-----w C:\Program Files\Alcohol Soft 2007-11-18 08:37 --------- d-----w C:\Program Files\DVDFab Platinum 3 2007-11-18 08:33 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys 2007-11-18 08:33 47,360 ----a-w C:\Documents and Settings\Dawid\Dane aplikacji\pcouffin.sys 2007-11-15 18:36 --------- d-----w C:\Program Files\Kwyshell 2007-11-15 18:33 --------- d-----w C:\Program Files\Sjboy Emulator 2007-11-13 20:03 --------- d-----w C:\Program Files\Softick 2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-11-12 18:53 --------- d-----w C:\Program Files\Common Files\Adobe 2007-11-11 18:28 --------- d-----w C:\Program Files\MSXML 4.0 2007-11-10 13:46 --------- d-----w C:\Documents and Settings\Dawid\Dane aplikacji\Media Player Classic 2007-11-10 12:18 --------- d-----w C:\Program Files\Real Alternative 2007-11-10 12:18 --------- d-----w C:\Program Files\K-Lite Codec Pack 2007-11-10 12:09 --------- d-----w C:\Program Files\Microsoft.NET 2007-11-10 12:09 --------- d-----w C:\Program Files\Microsoft Works 2007-11-10 11:12 --------- d-----w C:\Program Files\WIDCOMM 2007-11-10 11:10 --------- d-----w C:\Program Files\IRIS Desktop Search 2007-11-10 11:09 --------- d-----w C:\Program Files\Readiris Pro 11 HP 2007-11-10 11:06 --------- d-----w C:\Documents and Settings\Dawid\Dane aplikacji\HP 2007-11-10 11:06 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Hewlett-Packard 2007-11-10 11:01 --------- d-----w C:\Program Files\HP 2007-11-10 11:01 --------- d-----w C:\Program Files\Common Files\HP 2007-11-10 11:01 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\HP 2007-11-10 11:00 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\zvprt50 2007-11-10 10:57 --------- d-----w C:\Program Files\Hewlett-Packard 2007-11-10 10:57 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard 2007-11-10 10:41 --------- d-----w C:\Program Files\Alwil Software 2007-11-10 10:31 --------- d-----w C:\Program Files\Winamp 2007-11-10 10:30 --------- d-----w C:\Documents and Settings\Dawid\Dane aplikacji\Lavasoft 2007-11-10 10:29 --------- d-----w C:\Program Files\Sygate 2007-11-10 10:29 --------- d-----w C:\Program Files\Lavasoft 2007-11-10 10:29 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-11-10 10:28 --------- d-----w C:\Program Files\Gadu-Gadu 2007-11-10 10:28 --------- d-----w C:\Documents and Settings\Dawid\Dane aplikacji\Gadu-Gadu 2007-11-10 10:24 --------- d-----w C:\Program Files\PowerISO 2007-11-10 10:20 --------- d-----w C:\Documents and Settings\Dawid\Dane aplikacji\InterTrust 2007-11-10 10:18 --------- d-----w C:\Program Files\Common Files\Ahead 2007-11-10 10:18 --------- d-----w C:\Program Files\Ahead 2007-11-10 10:17 --------- d-----w C:\Program Files\CyberLink DVD Solution 2007-11-10 10:17 --------- d-----w C:\Program Files\CyberLink 2007-11-10 10:17 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\CyberLink 2007-11-10 10:14 --------- d-----w C:\Documents and Settings\Dawid\Dane aplikacji\ATI 2007-11-10 10:08 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-11-10 10:08 --------- d-----w C:\Program Files\ATI Technologies 2007-11-10 10:02 --------- d-----w C:\Program Files\AMD 2007-11-10 10:01 --------- d-----w C:\Program Files\Realtek Sound Manager 2007-11-10 09:49 --------- d-----w C:\Program Files\microsoft frontpage 2007-11-10 09:48 --------- d-----w C:\Program Files\Usługi online 2007-10-29 22:44 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll 2007-10-25 09:00 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll 2007-10-22 02:39 267,272 ----a-w C:\WINDOWS\system32\xactengine2_10.dll 2007-10-22 02:37 17,928 ----a-w C:\WINDOWS\system32\X3DAudio1_2.dll 2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll 2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll 2007-10-12 14:14 3,734,536 ----a-w C:\WINDOWS\system32\d3dx9_36.dll 2007-10-12 14:14 1,374,232 ----a-w C:\WINDOWS\system32\D3DCompiler_36.dll 2007-10-02 08:56 444,776 ----a-w C:\WINDOWS\system32\d3dx10_36.dll 2005-03-31 21:17 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe . ((((((((((((((((((((((((((((( snapshot@2007-12-24_12.38.23.48 ))))))))))))))))))))))))))))))))))))))))) . - 2005-03-18 16:19:58 2,337,488 ----a-w C:\WINDOWS\system32\d3dx9_25.dll + 2005-03-19 00:19:58 2,337,488 ----a-w C:\WINDOWS\system32\d3dx9_25.dll - 2007-11-15 08:06:23 181,040 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT + 2007-12-26 23:23:49 181,832 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT - 2004-08-04 12:00:00 1,392,671 ----a-w C:\WINDOWS\system32\msvbvm60.dll + 2005-04-05 13:28:54 1,386,496 ----a-w C:\WINDOWS\system32\MSVBVM60.DLL - 2007-12-01 07:30:18 2,467,600 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat + 2007-12-25 18:44:31 438,916 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat + 2000-07-14 23:00:00 101,888 ----a-w C:\WINDOWS\system32\VB6STKIT.DLL + 2007-12-26 23:23:57 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_658.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 13:00] “I.R.I.S. Desktop Search”=“C:\PROGRA~1\IRISDE~1\IRISDE~1.exe” [2006-01-11 14:37] “MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 17:24] “PowerBar”="" [] “Eraser”=“C:\Program Files\Eraser\eraser.exe” [2003-07-25 11:15] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NVRaidService”=“C:\WINDOWS\system32\nvraidservice.exe” [2004-01-13 05:36] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-02-22 21:05] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2005-02-22 22:21] “RemoteControl”=“C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe” [2003-12-08 17:35] “InCD”=“C:\Program Files\Ahead\InCD\InCD.exe” [2005-06-10 15:20] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 11:50] “PWRISOVM.EXE”=“C:\Program Files\PowerISO\PWRISOVM.EXE” [2007-04-09 13:23] “SmcService”=“C:\PROGRA~1\Sygate\SPF\smc.exe” [2004-10-15 19:40] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2007-05-14 23:22] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00] “ToolBoxFX”=“C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe” [2007-06-20 20:42] “HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2005-02-16 23:11] “SoftickPPP”=“C:\Program Files\Softick\PPP\Bin\PPPGate.exe” [2004-10-20 23:05] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11] “SVRemote”=“C:\Program Files\WinPVR\TVCardRemote.exe” [2006-05-30 13:45] “SoundMan”=“SOUNDMAN.EXE” [2004-12-22 10:09 C:\WINDOWS\soundman.exe] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 13:00] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2005-02-22 22:21] R3 Cap7134;OEM 7130AC Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2006-06-14 10:38] R3 PhTVTune;OEM 7130AC WDM TVTuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2006-06-14 10:38] S3 DarkSpy;DarkSpy;C:\WINDOWS\system32\DarkSpyKernel.sys [] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-27 00:28:21 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-27 0:28:51 . 2007-12-15 23:21:15 — E O F —