ComboFix 07-11-19.3 - Popielarz 2007-11-23 18:05:22.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.200 [GMT 1:00] Running from: C:\Documents and Settings\Popielarz\Pulpit\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 ))))))))))))))))))))))))))))))) . 2007-11-23 17:45 2007-11-23 16:35 2007-11-23 16:34 2007-11-23 16:34 2007-11-23 16:34 2007-11-23 16:34 2007-11-23 16:34 2007-11-23 16:34 2007-11-23 16:34 2007-11-23 14:25 2007-11-23 14:25 2007-11-23 14:23 2007-11-23 14:21 2,855,080 --a------ C:\aawsepersonal(dobreprogramy.pl).exe 2007-11-23 14:20 7,467,056 --a------ C:\spybotsd15.exe 2007-11-23 14:10 2007-11-22 21:31 221,611 --a------ C:\WINDOWS\system32\UGapcsHo.exe 2007-11-22 21:30 69,632 --a------ C:\WINDOWS\system32\gate.exe 2007-11-22 21:29 71,595 --a------ C:\WINDOWS\system32\QrJsvJsx.exe 2007-11-22 20:38 8 --a------ C:\WINDOWS\system32\1.htm 2007-11-22 18:21 26,496 --a–c— C:\WINDOWS\system32\dllcache\usbstor.sys 2007-11-22 17:27 2007-11-22 15:23 2007-11-22 15:21 2007-11-22 15:14 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe 2007-11-22 14:49 129,254 --a------ C:\WINDOWS\system32\TZLog.log 2007-11-22 14:27 97,280 --a------ C:\WINDOWS\system32\dpcdll.dll.wga 2007-11-22 14:27 29,338 --a------ C:\WINDOWS\system32\EULA.TXT.wga 2007-11-22 14:27 24,064 --a------ C:\WINDOWS\system32\pidgen.dll.wga 2007-11-22 14:27 13,588 --a------ C:\WINDOWS\system32\wpa.bak 2007-11-22 13:50 2007-11-22 13:44 2007-11-22 13:44 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-11-22 13:34 2007-11-22 13:33 2007-11-22 13:33 2007-11-22 13:33 2007-11-22 13:33 2007-11-22 13:30 2007-11-22 13:29 2007-11-22 13:28 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-11-22 13:28 389,120 --a------ C:\WINDOWS\system32\lameACM.acm 2007-11-22 13:28 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-11-22 13:28 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll 2007-11-22 13:28 164,352 --a------ C:\WINDOWS\system32\unrar.dll 2007-11-22 13:28 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm 2007-11-22 13:28 414 --a------ C:\WINDOWS\system32\lame_acm.xml 2007-11-22 13:27 2007-11-22 13:27 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-11-22 13:27 739,840 --a------ C:\WINDOWS\system32\divx.dll 2007-11-22 13:27 81,920 --a------ C:\WINDOWS\system32\dpl100.dll 2007-11-22 13:27 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-11-22 13:27 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest 2007-11-22 13:25 2007-11-22 13:23 2007-11-22 13:23 2007-11-22 13:17 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-11-22 13:14 2007-11-22 13:14 2007-11-22 13:07 2007-11-22 13:02 2007-11-22 12:58 2007-11-22 12:51 1,114,674 -ra------ C:\WINDOWS\system32\drivers\ativcaxx.cpa 2007-11-22 12:51 520,192 --------- C:\WINDOWS\system32\ati2sgag.exe 2007-11-22 12:51 307,200 -ra------ C:\WINDOWS\system32\atiiiexx.dll 2007-11-22 12:51 133,246 -ra------ C:\WINDOWS\system32\atiicdxx.dat 2007-11-22 12:51 58,560 -ra------ C:\WINDOWS\system32\drivers\ativckxx.vp 2007-11-22 12:51 31,696 -ra------ C:\WINDOWS\system32\drivers\ativvpxx.vp 2007-11-22 12:51 6,126 -ra------ C:\WINDOWS\system32\atifglpf.xml 2007-11-22 12:51 929 -ra------ C:\WINDOWS\system32\drivers\ativcaxx.vp 2007-11-22 12:50 2007-11-22 12:34 2007-11-22 12:34 2007-11-22 12:34 129,784 --------- C:\WINDOWS\system32\pxafs.dll 2007-11-22 12:34 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys 2007-11-22 12:34 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys 2007-11-22 12:24 2007-11-22 12:23 2007-11-22 12:23 2007-11-22 11:59 2007-11-22 11:59 2007-11-22 11:58 2007-11-22 11:54 2007-11-22 11:54 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll 2007-11-22 11:54 801,144 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-11-22 11:54 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll 2007-11-22 11:54 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx 2007-11-22 11:54 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll 2007-11-22 11:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr 2007-11-22 11:54 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-11-22 11:54 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-11-22 11:54 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-11-22 11:54 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-11-22 11:54 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-11-22 11:49 2007-11-22 11:49 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav 2007-11-22 11:49 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav 2007-11-22 11:47 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys 2007-11-22 11:47 142,464 --a–c— C:\WINDOWS\system32\dllcache\aec.sys 2007-11-22 11:47 130,048 --a------ C:\WINDOWS\system32\ksproxy.ax 2007-11-22 11:47 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-22 10:45 315,392 ----a-w C:\WINDOWS\HideWin.exe 2007-11-22 10:37 14,656 ----a-w C:\WINDOWS\gdrv.sys 2007-11-22 00:22 --------- d-----w C:\Program Files\microsoft frontpage 2007-11-22 00:19 --------- d-----w C:\Program Files\Usługi online . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-03 23:44] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-07-09 08:39] “SpybotSD TeaTimer”=“C:\SpybotSearchDestroy\TeaTimer.exe” [2007-08-31 16:46] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 12:06] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe” [2006-05-10 11:12] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-03 23:44] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] ALCMTR.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] 2005-10-28 16:25 94208 --a------ C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu] C:\Program Files\Gadu-Gadu\gg.exe /tray [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Network Services Controller] C:\WINDOWS\system32\mmsvc32.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2001-07-09 10:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] RTHDCPL.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spools Service Controller] C:\WINDOWS\system32\spools.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2007-10-10 06:28 36352 --a------ C:\Program Files\Winamp\winampa.exe S3 gdrv;gdrv;??\C:\WINDOWS\gdrv.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{636bb9f8-991f-11dc-a7d5-001a4d83227d}] \Shell\AutoRun\command - G:\ \Shell\open\Command - G:.\autorun.exe explore *Newly Created Service* - CATCHME *Newly Created Service* - HTTPFILTER . ************************************************************************** catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-23 18:06:46 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … C:\WINDOWS\erdnt scan completed successfully hidden files: 1 ************************************************************************** . Completion time: 2007-11-23 18:07:29 . — E O F —