“Wojtek” - 2007-06-25 12:01:10 - ComboFix 07-06-23.5 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2007-05-25 to 2007-06-25 ))))))))))))))))))))))))))))))) 2007-06-25 11:56 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-25 11:41 2007-06-25 11:39 2007-06-20 19:38 2007-06-19 19:09 2007-06-19 15:05 2007-06-18 12:49 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr 2007-06-18 12:49 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-06-18 12:49 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-06-18 12:49 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-06-18 12:49 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-06-18 12:49 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-06-18 12:49 23,416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-06-18 12:49 2007-06-16 21:49 2007-06-16 20:55 2007-06-16 20:52 2007-06-16 17:30 5,888 --------- C:\WINDOWS\system32\drivers\imagedrv.sys 2007-06-16 17:30 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2007-06-16 17:30 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2007-06-16 17:30 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2007-06-16 17:30 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2007-06-16 17:30 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-06-16 17:30 127,488 --------- C:\WINDOWS\system32\drivers\imagesrv.sys 2007-06-16 17:30 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-06-16 17:30 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2007-06-16 17:30 2007-06-16 17:03 2007-06-16 14:01 2007-06-15 20:09 2007-06-15 16:49 2007-06-14 14:47 2007-06-14 14:29 2007-06-13 16:21 2007-06-13 16:20 2007-06-13 16:12 2007-06-11 22:14 2007-06-11 18:26 584,704 --a------ C:\WINDOWS\system32\Pearl-Jam Screen Saver.scr 2007-06-11 18:26 283,648 --a------ C:\WINDOWS\system32\uninstall.exe 2007-06-11 18:26 149,504 --a------ C:\WINDOWS\system32\Mpegdll.dll 2007-06-10 14:00 2007-06-10 13:02 2007-06-09 20:10 2007-06-09 20:09 2007-06-09 20:05 2007-06-09 19:48 2007-06-09 19:31 2007-06-09 18:42 2007-06-09 18:39 2007-06-09 18:38 2007-06-09 18:24 2007-06-09 18:22 2007-06-09 18:17 2,621,440 --a------ C:\DOCUME~1\Wojtek\NTUSER.DAT 2007-06-09 18:17 2007-06-09 18:17 2007-06-09 18:17 2007-06-09 18:17 2007-06-09 18:17 2007-06-09 18:17 2007-06-09 18:17 2007-06-09 16:53 2007-06-08 23:43 2007-06-08 19:49 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-06-08 19:49 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll 2007-06-08 19:49 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll 2007-06-08 19:49 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll 2007-06-08 19:49 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll 2007-06-08 19:49 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll 2007-06-08 19:49 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll 2007-06-08 19:49 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll 2007-06-08 19:49 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll 2007-06-08 19:49 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll 2007-06-08 19:49 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll 2007-06-08 19:49 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-06-08 19:49 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll 2007-06-08 19:49 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll 2007-06-08 19:49 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll 2007-06-08 19:49 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-06-08 19:49 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll 2007-06-08 19:49 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll 2007-06-08 19:48 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-06-08 18:20 2007-06-07 20:00 2007-06-04 20:33 2007-06-04 19:33 64,502 --a------ C:\WINDOWS\BricoPackUninst.cmd 2007-06-04 19:31 6,116 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd 2007-06-04 19:30 2007-06-04 15:18 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys 2007-06-04 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys 2007-06-04 15:14 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys 2007-06-02 22:10 24,816 --a------ C:\WINDOWS\system32\mdimon.dll 2007-06-02 22:08 2007-06-02 22:05 2007-06-02 22:04 2007-06-02 15:18 2007-06-02 15:15 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2007-06-02 15:14 2007-06-02 14:41 2007-06-01 17:21 90,112 --a------ C:\WINDOWS\unvise32.exe 2007-06-01 17:21 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-25 10:00:13 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-06-25 09:50:33 -------- d-----w C:\Program Files\Neostrada TP 2007-06-19 17:09:53 -------- d-----w C:\Program Files\BitComet 2007-06-19 17:09:23 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll 2007-06-09 17:56:59 -------- d-----w C:\Program Files\Opera 2007-06-09 17:36:13 -------- d-----w C:\Program Files\Tlen.pl 2007-06-09 16:39:20 -------- d-----w C:\Program Files\Common Files\Teleca Shared 2007-06-09 16:26:05 -------- d-----w C:\Program Files\Winamp 2007-06-09 14:53:40 -------- d-----w C:\Program Files\BearShare 2007-06-09 14:53:21 -------- d-----w C:\Program Files\Movie Maker 2007-06-04 17:33:44 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll 2007-06-01 12:33:03 -------- d-----w C:\Program Files\Ganymede 2007-05-31 18:03:05 -------- d-----w C:\Program Files\Gadu-Gadu 2007-05-24 17:03:27 -------- d-----w C:\Program Files\Sony Ericsson 2007-05-24 16:36:11 -------- d-----w C:\Program Files\Common Files\Nero 2007-05-22 06:15:55 -------- d-----w C:\Program Files\MSXML 4.0 2007-05-21 18:34:15 5,744 ----a-w C:\WINDOWS\system32\drivers\k750wh.sys 2007-05-21 18:34:14 94,064 ----a-w C:\WINDOWS\system32\drivers\k510mdm.sys 2007-05-21 18:34:14 85,408 ----a-w C:\WINDOWS\system32\drivers\k510mgmt.sys 2007-05-21 18:34:14 83,344 ----a-w C:\WINDOWS\system32\drivers\k510obex.sys 2007-05-21 18:34:14 5,808 ----a-w C:\WINDOWS\system32\drivers\k510whnt.sys 2007-05-21 18:34:14 5,808 ----a-w C:\WINDOWS\system32\drivers\k510wh.sys 2007-05-21 18:34:13 8,336 ----a-w C:\WINDOWS\system32\drivers\k510mdfl.sys 2007-05-21 18:34:13 6,176 ----a-w C:\WINDOWS\system32\drivers\k510cmnt.sys 2007-05-21 18:34:13 6,176 ----a-w C:\WINDOWS\system32\drivers\k510cm.sys 2007-05-21 18:34:13 6,144 ----a-w C:\WINDOWS\system32\drivers\k750cm.sys 2007-05-21 18:34:13 58,288 ----a-w C:\WINDOWS\system32\drivers\k510bus.sys 2007-05-21 18:33:56 -------- d-----w C:\Program Files\Common Files\InstallShield 2007-05-21 06:01:38 49,492 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-05-21 06:01:38 355,486 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-05-20 19:29:09 -------- d-----w C:\Program Files\Messenger 2007-05-20 18:12:01 -------- d-----w C:\Program Files\Lavasoft 2007-05-20 18:05:08 -------- d-----w C:\Program Files\Common Files\ODBC 2007-05-20 18:05:06 -------- d-----w C:\Program Files\Common Files\SpeechEngines 2007-05-20 17:53:20 -------- d-----w C:\Program Files\Skype 2007-05-20 17:53:16 -------- d-----w C:\Program Files\Common Files\Skype 2007-05-20 17:36:03 4 ----a-w C:\WINDOWS\system32\proc-220146841.bin 2007-05-20 17:18:33 -------- d-----w C:\Program Files\Last.fm 2007-05-20 17:13:13 -------- d-----w C:\Program Files\Realtek Sound Manager 2007-05-20 17:13:13 -------- d-----w C:\Program Files\AvRack 2007-05-20 17:13:12 -------- d-----w C:\Program Files\Realtek AC97 2007-05-20 17:13:07 -------- d–h--w C:\Program Files\InstallShield Installation Information 2007-05-20 16:55:41 -------- d-----w C:\Program Files\Lexmark 4300 Series 2007-05-20 16:44:15 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat 2007-05-20 16:23:17 -------- d-----w C:\Program Files\SAGEM 2007-05-20 16:23:03 -------- d-----w C:\Program Files\Java Web Start 2007-05-20 16:15:38 -------- d-----w C:\Program Files\microsoft frontpage 2007-05-20 16:15:18 0 --sha-r C:\MSDOS.SYS 2007-05-20 16:15:18 0 --sha-r C:\IO.SYS 2007-05-20 16:15:18 0 ----a-w C:\CONFIG.SYS 2007-05-20 16:15:18 0 ----a-w C:\AUTOEXEC.BAT 2007-05-20 16:14:04 -------- d–h--w C:\Program Files\WindowsUpdate 2007-05-20 16:14:00 -------- d-----w C:\Program Files\Usługi online 2007-05-20 16:13:16 -------- d-----w C:\Program Files\Common Files\MSSoap 2007-05-20 16:12:44 21,856 ----a-w C:\WINDOWS\system32\emptyregdb.dat 2007-05-20 16:11:48 -------- d-----w C:\Program Files\MSN Gaming Zone 2007-05-20 16:11:41 -------- d-----w C:\Program Files\Windows NT 2007-05-16 15:18:58 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-19 12:14:14 208,896 ----a-w C:\WINDOWS\system32\nvudisp.exe 2007-04-19 11:26:00 888,832 ----a-w C:\WINDOWS\system32\nvmobls.dll 2007-04-19 11:26:00 86,016 ----a-w C:\WINDOWS\system32\nvmctray.dll 2007-04-19 11:26:00 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll 2007-04-19 11:26:00 794,624 ----a-w C:\WINDOWS\system32\nvcplui.exe 2007-04-19 11:26:00 7,700,480 ----a-w C:\WINDOWS\system32\nvcpl.dll 2007-04-19 11:26:00 581,632 ----a-w C:\WINDOWS\system32\nvhwvid.dll 2007-04-19 11:26:00 5,644,288 ----a-w C:\WINDOWS\system32\nvoglnt.dll 2007-04-19 11:26:00 5,619,712 ----a-w C:\WINDOWS\system32\nvdisps.dll 2007-04-19 11:26:00 5,255,168 ----a-w C:\WINDOWS\system32\nvdispsr.dll 2007-04-19 11:26:00 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll 2007-04-19 11:26:00 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll 2007-04-19 11:26:00 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll 2007-04-19 11:26:00 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe 2007-04-19 11:26:00 425,984 ----a-w C:\WINDOWS\system32\keystone.exe 2007-04-19 11:26:00 4,543,616 ----a-w C:\WINDOWS\system32\nv4_disp.dll 2007-04-19 11:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcodins.dll 2007-04-19 11:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcod.dll 2007-04-19 11:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll 2007-04-19 11:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll 2007-04-19 11:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll 2007-04-19 11:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrshe.dll 2007-04-19 11:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrsar.dll 2007-04-19 11:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll 2007-04-19 11:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll 2007-04-19 11:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll 2007-04-19 11:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll 2007-04-19 11:26:00 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll 2007-04-19 11:26:00 311,296 ----a-w C:\WINDOWS\system32\nvexpbar.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll 2007-04-19 11:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll 2007-04-19 11:26:00 3,203,072 ----a-w C:\WINDOWS\system32\nvgamesr.dll 2007-04-19 11:26:00 3,035,136 ----a-w C:\WINDOWS\system32\nvgames.dll 2007-04-19 11:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll 2007-04-19 11:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll 2007-04-19 11:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll 2007-04-19 11:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {22BF413B-C6D2-4d91-82A9-A0F997BA588C}=C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2007-05-10 16:09] {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll [2007-06-14 15:07] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “WooCnxMon”=“C:\PROGRA~1\NEOSTR~1\CnxMon.exe” [2003-10-16 18:07] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2003-10-16 18:07] “WOOTASKBARICON”=“C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe” [2003-10-16 18:07] “nwiz”=“nwiz.exe” [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe] “lxcemon.exe”=“C:\Program Files\Lexmark 4300 Series\lxcemon.exe” [2005-08-02 19:47] “EzPrint”=“C:\Program Files\Lexmark 4300 Series\ezprint.exe” [2005-07-26 14:17] “SoundMan”=“SOUNDMAN.EXE” [2005-08-17 18:39 C:\WINDOWS\soundman.exe] “QuickTime Task”=“D:\Program Files\QuickTime\qttask.exe” [2007-04-27 09:41] “@”="" [] “Sony Ericsson PC Suite”=“D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2005-10-26 16:17] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-04-30 17:42] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 14:00] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice] Contents of the ‘Scheduled Tasks’ folder 2007-06-15 15:15:00 C:\WINDOWS\tasks\1-Click Maintenance.job ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-25 12:03:08 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-25 12:04:00 — E O F —