ComboFix 07-11-08.1 - Krzysiek 2007-11-11 16:05:00.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.298 [GMT 1:00] Running from: C:\Documents and Settings\Krzysiek\Pulpit\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-10-11 to 2007-11-11 ))))))))))))))))))))))))))))))) . 2007-11-07 22:27 2007-11-07 22:25 2007-11-04 14:58 2007-11-04 14:26 2007-11-03 18:49 2007-11-01 20:10 2007-10-27 22:50 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2007-10-27 22:50 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2007-10-27 21:19 2007-10-23 19:27 2007-10-23 19:26 2007-10-23 19:09 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2007-10-23 19:09 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-10-23 19:09 15,104 --a–c— C:\WINDOWS\system32\dllcache\usbscan.sys 2007-10-23 19:09 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2007-10-22 20:40 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll 2007-10-22 20:38 2007-10-22 20:35 2007-10-22 20:31 2007-10-22 20:29 2007-10-22 20:27 2007-10-13 23:03 2007-10-12 21:39 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-11 15:02 --------- d-----w C:\Program Files\PEERGuardian2 2007-11-11 14:27 --------- d-----w C:\Program Files\eMule 2007-11-11 14:18 --------- d-----w C:\Documents and Settings\Krzysiek\Dane aplikacji\Skype 2007-11-11 08:44 --------- d-----w C:\Program Files\AutoConnect 2007-11-07 21:28 --------- d-----w C:\Program Files\Lavasoft 2007-11-07 21:28 --------- d-----w C:\Documents and Settings\Krzysiek\Dane aplikacji\Lavasoft 2007-10-31 16:22 --------- d-----w C:\Program Files\Neostrada TP 2007-10-27 13:59 --------- d-----w C:\Program Files\Odkurzacz 2007-10-27 13:59 --------- d-----w C:\Documents and Settings\Krzysiek\Dane aplikacji\uTorrent 2007-10-24 12:48 --------- d-----w C:\Program Files\Mozilla Thunderbird 2007-10-11 19:19 25,992 ----a-w C:\WINDOWS\system32\pgdfgsvc.exe 2007-10-11 19:03 --------- d-----w C:\Program Files\CyberLink 2007-10-09 18:38 --------- d-----w C:\Documents and Settings\Krzysiek\Dane aplikacji\GanymedeNet 2007-10-09 18:08 --------- d-----w C:\Program Files\Ganymede 2007-10-05 14:59 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-10-05 06:07 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy 2007-10-05 06:04 --------- d-----w C:\Program Files\Trend Micro 2007-09-26 19:30 --------- d-----w C:\Program Files\Common Files\Adobe 2007-09-26 18:29 11,544 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err 2007-09-25 14:46 --------- d-----w C:\Program Files\Google 2007-09-23 08:36 --------- d-----w C:\Documents and Settings\Krzysiek\Dane aplikacji\DivX 2007-09-23 08:26 --------- d-----w C:\Program Files\Xvid 2007-09-23 08:24 --------- d-----w C:\Program Files\DivX 2007-09-22 19:53 --------- d-----w C:\Program Files\Ambient Design Ltd 2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll 2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll 2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll 2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll 2007-09-15 20:06 --------- d-----w C:\Program Files\Sophos 2007-09-15 19:50 --------- d-----w C:\Program Files\Gadu-Gadu 2007-09-14 14:44 --------- d-----w C:\Program Files\Microsoft Bootvis 2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2007-08-22 02:09 352,256 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll 2007-08-22 02:07 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll 2007-08-22 02:07 268,800 ----a-w C:\WINDOWS\system32\ati2dvag.dll 2007-08-22 01:59 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe 2007-08-22 01:59 143,360 ----a-w C:\WINDOWS\system32\atipdlxx.dll 2007-08-22 01:58 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll 2007-08-22 01:58 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll 2007-08-22 01:57 487,424 ----a-w C:\WINDOWS\system32\ati2evxx.exe 2007-08-22 01:56 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL 2007-08-22 01:48 8,306,688 ----a-w C:\WINDOWS\system32\atioglx2.dll 2007-08-22 01:47 3,091,392 ----a-w C:\WINDOWS\system32\ati3duag.dll 2007-08-22 01:35 1,586,816 ----a-w C:\WINDOWS\system32\ativvaxx.dll 2007-08-22 01:21 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll 2007-08-22 01:19 266,240 ----a-w C:\WINDOWS\system32\atikvmag.dll 2007-08-22 01:17 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll 2007-08-22 01:15 172,032 ----a-w C:\WINDOWS\system32\atiok3x2.dll 2007-08-22 01:11 450,560 ----a-w C:\WINDOWS\system32\ati2cqag.dll 2007-08-21 19:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll 2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll 2007-08-15 22:33 129,784 ------w C:\WINDOWS\system32\pxafs.dll 2007-08-15 22:33 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe 2007-08-15 22:33 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe 2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll 2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll 2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll 2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll 2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll 2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll 2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll 2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2004-08-25 11:52] “WooCnxMon”=“C:\PROGRA~1\NEOSTR~1\CnxMon.exe” [2003-10-16 17:07] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2003-10-16 17:07] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [2003-10-16 17:07] “nod32kui”=“C:\Program Files\Eset\nod32kui.exe” [2007-06-15 16:56] “SystemTray”=“SysTray.Exe” [2001-10-30 13:00 C:\WINDOWS\system32\systray.exe] “FmctrlTray”=“Fmctrl.EXE” [2001-08-20 20:47 C:\WINDOWS\system32\fmctrl.exe] “LXSUPMON”=“C:\WINDOWS\system32\LXSUPMON.exe” [2001-10-09 17:10] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-03 23:44] “AutoConnect”=“C:\Program Files\AutoConnect\AutoConnect.exe” [2004-08-28 19:27] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26] DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-06-15 15:49:52] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “AppInit_DLLs”=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Synchronizer.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Synchronizer.lnk backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Monitor Apache Servers.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Monitor Apache Servers.lnk backup=C:\WINDOWS\pss\Monitor Apache Servers.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] “C:\Program Files\DAEMON Tools\daemon.exe” -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser] C:\Program Files\Eraser\eraser.exe -hide [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu] “C:\Program Files\Gadu-Gadu\gg.exe” /tray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut] “C:\Program Files\CyberLink\PowerDVD\Language\Language.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] “C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] “C:\Program Files\Skype\Phone\Skype.exe” /nosplash /minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] “SpybotSD TeaTimer”=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] “Google Desktop Search”=“C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys R2 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe R3 gameport;FM801 PCI Joystick;C:\WINDOWS\system32\DRIVERS\fmjoy.sys R3 wdm_fm801;FM801 PCI Audio (WDM);C:\WINDOWS\system32\drivers\fm801.sys S3 MEMSWEEP2;MEMSWEEP2;??\C:\WINDOWS\system32\25B.tmp S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-11 16:09:55 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-11 16:12:34 . — E O F —