ComboFix 07-08-30.3 - “BoBeK” 2007-09-06 9:42:03.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.151 [GMT 2:00] ((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 ))))))))))))))))))))))))))))))) 2007-09-06 09:17 2007-09-06 09:16 2007-09-06 09:16 2007-09-06 09:16 2007-09-06 09:16 2007-09-06 09:16 2007-09-06 09:16 2007-09-06 09:16 2007-09-06 08:45 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-09-06 08:45 2007-09-05 23:12 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-09-05 21:14 2007-09-05 20:45 2007-09-05 20:10 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-09-05 20:09 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-09-05 20:09 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-09-05 20:09 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS 2007-09-05 20:09 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys 2007-09-05 20:08 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys 2007-09-05 20:08 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys 2007-09-05 20:08 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys 2007-09-05 20:08 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 20:07 2007-09-05 19:31 2007-09-05 19:30 2007-09-05 19:30 2007-09-05 19:28 2007-09-05 19:20 2007-09-05 19:16 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-09-05 19:02 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys 2007-09-05 19:01 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2007-09-05 19:01 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-09-05 19:01 2007-09-05 19:00 2007-09-05 19:00 2007-09-05 19:00 2007-09-05 18:33 2007-09-05 18:33 2007-09-05 18:33 2007-09-05 18:33 2007-09-05 18:30 488,992 -ra------ C:\WINDOWS\system32\drivers\ar5211.sys 2007-09-05 18:26 2007-09-05 18:26 2007-09-05 18:26 2007-09-05 18:26 2007-09-05 18:26 2007-09-05 18:26 2007-09-05 18:26 2007-09-05 18:22 2007-09-05 18:22 2007-09-05 18:22 2007-09-05 18:22 2007-09-05 18:18 2007-09-05 18:17 2007-09-05 18:17 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-09-05 21:24 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF 2007-09-05 21:24 8014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll --------- C:\Program Files\Usługi online ((((((((((((((((((((((((((((( snapshot_2007-09-05_231641.53 ))))))))))))))))))))))))))))))))))))))))) ----a-w 163,328 2007-09-05 09:43:25 C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE ----a-w 385,024 2007-09-06 07:17:37 C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT ----a-w 8,192 2007-09-06 07:17:37 C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat ----a-w 163,328 2007-09-05 09:43:25 C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE ----a-w 385,024 2007-09-06 07:17:32 C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT ----a-w 8,192 2007-09-06 07:17:32 C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat ----a-w 364,544 2005-11-29 14:27:06 C:\WINDOWS\SoftwareDistribution\Download\0a943bdee5944948fb2fd718a69f36f3\npdsplay.dll ----a-w 13,536 2005-06-28 07:20:24 C:\WINDOWS\SoftwareDistribution\Download\0a943bdee5944948fb2fd718a69f36f3\spmsg.dll ----a-w 216,288 2005-06-28 07:23:38 C:\WINDOWS\SoftwareDistribution\Download\0a943bdee5944948fb2fd718a69f36f3\spuninst.exe ----a-w 22,752 2005-06-28 07:21:34 C:\WINDOWS\SoftwareDistribution\Download\0a943bdee5944948fb2fd718a69f36f3\spupdsvc.exe ----a-w 723,680 2005-06-28 07:25:02 C:\WINDOWS\SoftwareDistribution\Download\0a943bdee5944948fb2fd718a69f36f3\update\update.exe ----a-w 371,424 2005-06-28 07:23:54 C:\WINDOWS\SoftwareDistribution\Download\0a943bdee5944948fb2fd718a69f36f3\update\updspapi.dll ----a-w 497,392 2005-10-07 01:43:14 C:\WINDOWS\SoftwareDistribution\Download\0c8eb5282ac47f38ba57a849cb8b2306\WindowsXP-KB905749-x86-express-PLK.exe ----a-w 16,096 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\spmsg.dll ----a-w 212,704 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\spuninst.exe ------w 118,784 2004-08-03 22:44:14 C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\backup\sp2gdr\umpnpmgr.dll ------w 118,784 2004-08-03 22:44:14 C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\backup\sp2qfe\umpnpmgr.dll ----a-w 30,720 2005-08-22 16:01:30 C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\update\arpidfix.exe ----a-w 22,240 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\update\spcustom.dll ----a-w 725,728 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\update\update.exe ----a-w 387,296 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\0fffd07eaf930cc2973bc1444b13a2dd\update\updspapi.dll ----a-w 16,096 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\2f591c6de1d57e751071795880d0c1d2\spmsg.dll ----a-w 212,704 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\2f591c6de1d57e751071795880d0c1d2\spuninst.exe ------w 77,312 2004-08-03 22:44:28 C:\WINDOWS\SoftwareDistribution\Download\2f591c6de1d57e751071795880d0c1d2\backup\sp2gdr\telnet.exe ------w 77,312 2004-08-03 22:44:28 C:\WINDOWS\SoftwareDistribution\Download\2f591c6de1d57e751071795880d0c1d2\backup\sp2qfe\telnet.exe ----a-w 22,240 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\2f591c6de1d57e751071795880d0c1d2\update\spcustom.dll ----a-w 725,728 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\2f591c6de1d57e751071795880d0c1d2\update\update.exe ----a-w 387,296 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\2f591c6de1d57e751071795880d0c1d2\update\updspapi.dll ----a-w 16,096 2005-10-12 23:21:28 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\spmsg.dll ----a-w 216,288 2005-10-12 23:21:30 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\spuninst.exe ----a-w 42,496 2006-10-12 14:05:18 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\SP2GDR\agentdp2.dll ----a-w 57,344 2006-10-12 14:05:18 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\SP2GDR\agentdpv.dll ----a-w 256,512 2006-10-12 11:09:53 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\SP2GDR\agentsvr.exe ----a-w 122,368 2006-10-16 01:41:06 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\SP2GDR\spru0415.dll ----a-w 42,496 2006-10-12 13:56:14 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\SP2QFE\agentdp2.dll ----a-w 57,344 2006-10-12 13:56:14 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\SP2QFE\agentdpv.dll ----a-w 256,512 2006-10-12 11:54:07 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\SP2QFE\agentsvr.exe ----a-w 265,216 2006-10-16 02:19:24 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\SP2QFE\spru0415.dll ----a-w 22,752 2005-10-12 23:21:27 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\update\spcustom.dll ----a-w 723,680 2005-10-12 23:21:34 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\update\update.exe ----a-w 386,784 2005-10-12 23:21:41 C:\WINDOWS\SoftwareDistribution\Download\451957319b67021a35ca2a8ddf7799fa\update\updspapi.dll ----a-w 16,096 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\spmsg.dll ----a-w 212,704 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\spuninst.exe ------w 18,944 2004-08-03 22:44:02 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\backup\sp2gdr\linkinfo.dll ------w 8,412,672 2004-08-03 22:44:10 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\backup\sp2gdr\shell32.dll ------w 473,600 2004-08-03 22:44:12 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\backup\sp2gdr\shlwapi.dll ------w 291,328 2004-08-03 22:44:16 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\backup\sp2gdr\winsrv.dll ------w 18,944 2004-08-03 22:44:02 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\backup\sp2qfe\linkinfo.dll ------w 8,412,672 2004-08-03 22:44:10 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\backup\sp2qfe\shell32.dll ------w 473,600 2004-08-03 22:44:12 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\backup\sp2qfe\shlwapi.dll ------w 291,328 2004-08-03 22:44:16 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\backup\sp2qfe\winsrv.dll ----a-w 925,184 2005-08-31 17:32:08 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\sp1qfe\asms\60\msft\windows\common\controls\comctl32.dll ----a-w 30,720 2005-09-26 15:36:24 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\update\arpidfix.exe ----a-w 22,240 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\update\spcustom.dll ----a-w 725,728 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\update\update.exe ----a-w 387,296 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\4c41adde360d8087c4b4dd4e2d835dec\update\updspapi.dll ----a-w 9,216 2004-10-14 08:35:44 C:\WINDOWS\SoftwareDistribution\Download\5c9fd830c61df8040995447f1d8e61b0\spmsg.dll ----a-w 171,520 2004-10-14 08:36:26 C:\WINDOWS\SoftwareDistribution\Download\5c9fd830c61df8040995447f1d8e61b0\spuninst.exe ------w 349,696 2004-08-03 22:44:00 C:\WINDOWS\SoftwareDistribution\Download\5c9fd830c61df8040995447f1d8e61b0\backup\sp2gdr\hypertrm.dll ------w 349,696 2004-08-03 22:44:00 C:\WINDOWS\SoftwareDistribution\Download\5c9fd830c61df8040995447f1d8e61b0\backup\sp2qfe\hypertrm.dll ----a-w 21,504 2004-10-14 08:36:24 C:\WINDOWS\SoftwareDistribution\Download\5c9fd830c61df8040995447f1d8e61b0\update\spcustom.dll ----a-w 662,016 2004-10-14 08:35:44 C:\WINDOWS\SoftwareDistribution\Download\5c9fd830c61df8040995447f1d8e61b0\update\update.exe ----a-w 16,096 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\spmsg.dll ----a-w 212,704 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\spuninst.exe ------w 1,281,024 2004-08-03 22:44:08 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\backup\sp2gdr\ole32.dll ------w 69,120 2001-10-26 15:29:40 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\backup\sp2gdr\olecli32.dll ------w 34,304 2001-10-26 15:29:40 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\backup\sp2gdr\olecnv32.dll ------w 395,776 2004-08-03 22:44:10 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\backup\sp2gdr\rpcss.dll ------w 1,281,024 2004-08-03 22:44:08 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\backup\sp2qfe\ole32.dll ------w 69,120 2001-10-26 15:29:40 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\backup\sp2qfe\olecli32.dll ------w 34,304 2001-10-26 15:29:40 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\backup\sp2qfe\olecnv32.dll ------w 395,776 2004-08-03 22:44:10 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\backup\sp2qfe\rpcss.dll ----a-w 22,240 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\update\spcustom.dll ----a-w 725,728 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\update\update.exe ----a-w 387,296 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\6d09d0f1482adb9cdbb79b3d45a002d6\update\updspapi.dll ----a-w 902,896 2005-10-07 01:15:36 C:\WINDOWS\SoftwareDistribution\Download\7b74e73149ffe739753ba8a20e6d733d\WindowsXP-KB900725-x86-express-PLK.exe ----a-w 484,592 2005-06-11 01:37:35 C:\WINDOWS\SoftwareDistribution\Download\97972e9c433b106fa0183ec27fe1e300\WindowsXP-KB896428-x86-express-PLK.exe ----a-w 16,096 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\spmsg.dll ----a-w 212,704 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\spuninst.exe ------w 229,888 2004-08-03 22:43:54 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\catsrv.dll ------w 628,224 2004-08-03 22:43:54 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\catsrvut.dll ------w 110,080 2004-08-03 22:43:54 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\clbcatex.dll ------w 501,248 2004-08-03 22:43:54 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\clbcatq.dll ------w 62,464 2004-08-03 22:43:56 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\colbact.dll ------w 195,584 2004-08-03 22:43:56 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\comadmin.dll ------w 82,432 2001-10-26 15:29:26 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\comrepl.dll ------w 1,251,840 2004-08-03 22:43:56 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\comsvcs.dll ------w 540,160 2004-08-03 22:43:56 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\comuid.dll ------w 243,200 2004-08-03 22:43:58 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\es.dll ------w 7,680 2004-08-03 22:44:22 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\migregdb.exe ------w 425,472 2004-08-03 22:44:04 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\msdtcprx.dll ------w 949,248 2004-08-03 22:44:04 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\msdtctm.dll ------w 161,280 2004-08-03 22:44:04 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\msdtcuiu.dll ------w 66,560 2004-08-03 22:44:06 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\mtxclu.dll ------w 90,112 2004-08-03 22:44:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\mtxoci.dll ------w 1,281,024 2004-08-03 22:44:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\ole32.dll ------w 69,120 2001-10-26 15:29:40 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\olecli32.dll ------w 34,304 2001-10-26 15:29:40 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\olecnv32.dll ------w 395,776 2004-08-03 22:44:10 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\rpcss.dll ------w 101,376 2004-08-03 22:44:14 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\txflog.dll ------w 11,776 2004-08-03 22:44:18 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2gdr\xolehlp.dll ------w 229,888 2004-08-03 22:43:54 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\catsrv.dll ------w 628,224 2004-08-03 22:43:54 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\catsrvut.dll ------w 110,080 2004-08-03 22:43:54 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\clbcatex.dll ------w 501,248 2004-08-03 22:43:54 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\clbcatq.dll ------w 62,464 2004-08-03 22:43:56 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\colbact.dll ------w 195,584 2004-08-03 22:43:56 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\comadmin.dll ------w 82,432 2001-10-26 15:29:26 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\comrepl.dll ------w 1,251,840 2004-08-03 22:43:56 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\comsvcs.dll ------w 540,160 2004-08-03 22:43:56 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\comuid.dll ------w 243,200 2004-08-03 22:43:58 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\es.dll ------w 7,680 2004-08-03 22:44:22 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\migregdb.exe ------w 425,472 2004-08-03 22:44:04 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\msdtcprx.dll ------w 949,248 2004-08-03 22:44:04 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\msdtctm.dll ------w 161,280 2004-08-03 22:44:04 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\msdtcuiu.dll ------w 66,560 2004-08-03 22:44:06 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\mtxclu.dll ------w 90,112 2004-08-03 22:44:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\mtxoci.dll ------w 1,281,024 2004-08-03 22:44:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\ole32.dll ------w 69,120 2001-10-26 15:29:40 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\olecli32.dll ------w 34,304 2001-10-26 15:29:40 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\olecnv32.dll ------w 395,776 2004-08-03 22:44:10 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\rpcss.dll ------w 101,376 2004-08-03 22:44:14 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\txflog.dll ------w 11,776 2004-08-03 22:44:18 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\backup\sp2qfe\xolehlp.dll ----a-w 30,720 2005-07-25 17:21:18 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\update\arpidfix.exe ----a-w 22,240 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\update\spcustom.dll ----a-w 725,728 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\update\update.exe ----a-w 387,296 2005-02-24 18:36:08 C:\WINDOWS\SoftwareDistribution\Download\9ec74fb7ec17ab7a6f098ff95504d6d2\update\updspapi.dll ----a-w 522,480 2005-10-06 23:02:16 C:\WINDOWS\SoftwareDistribution\Download\9fc7d8bfae6d0ca56892095376bfd2e3\WindowsXP-KB902400-x86-express-PLK.exe ----a-w 9,216 2004-11-30 12:47:26 C:\WINDOWS\SoftwareDistribution\Download\a89ca315c00b53f4d6175cb0b4571131\spmsg.dll ----a-w 171,520 2004-11-30 18:22:46 C:\WINDOWS\SoftwareDistribution\Download\a89ca315c00b53f4d6175cb0b4571131\spuninst.exe ----a-w 21,504 2004-11-30 18:22:46 C:\WINDOWS\SoftwareDistribution\Download\a89ca315c00b53f4d6175cb0b4571131\update\spcustom.dll ----a-w 662,016 2004-11-30 12:47:26 C:\WINDOWS\SoftwareDistribution\Download\a89ca315c00b53f4d6175cb0b4571131\update\update.exe ----a-w 16,096 2005-02-25 03:36:06 C:\WINDOWS\SoftwareDistribution\Download\b6686f23b231330eed046158efe568a4\spmsg.dll ----a-w 212,704 2005-02-25 03:36:06 C:\WINDOWS\SoftwareDistribution\Download\b6686f23b231330eed046158efe568a4\spuninst.exe ----a-w 22,752 2005-02-25 03:36:06 C:\WINDOWS\SoftwareDistribution\Download\b6686f23b231330eed046158efe568a4\spupdsvc.exe ----a-w 22,240 2005-02-25 03:36:06 C:\WINDOWS\SoftwareDistribution\Download\b6686f23b231330eed046158efe568a4\update\spcustom.dll ----a-w 725,728 2005-02-25 03:36:06 C:\WINDOWS\SoftwareDistribution\Download\b6686f23b231330eed046158efe568a4\update\update.exe ----a-w 387,296 2005-02-25 03:36:07 C:\WINDOWS\SoftwareDistribution\Download\b6686f23b231330eed046158efe568a4\update\updspapi.dll ----a-w 16,096 2005-10-12 23:21:28 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\spmsg.dll ----a-w 216,288 2005-10-12 23:21:30 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\spuninst.exe ----a-w 140,288 2006-06-26 17:49:06 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\SP1QFE\dnsapi.dll ----a-w 6,144 2006-06-26 17:49:06 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\SP1QFE\rasadhlp.dll ----a-w 148,480 2006-06-26 17:45:40 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\SP2GDR\dnsapi.dll ----a-w 8,192 2006-06-26 17:45:40 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\SP2GDR\rasadhlp.dll ----a-w 147,456 2006-06-26 17:47:18 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\SP2QFE\dnsapi.dll ----a-w 7,680 2006-06-26 17:47:18 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\SP2QFE\rasadhlp.dll ----a-w 22,752 2005-10-12 23:21:27 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\update\spcustom.dll ----a-w 723,680 2005-10-12 23:21:34 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\update\update.exe ----a-w 386,784 2005-10-12 23:21:41 C:\WINDOWS\SoftwareDistribution\Download\c6fa644827c98b9de8999296da8b4e1b\update\updspapi.dll ----a-w 16,096 2005-10-12 23:21:28 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\spmsg.dll ----a-w 216,288 2005-10-12 23:21:30 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\spuninst.exe ----a-w 927,504 2006-11-01 19:19:04 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\SP2QFE\mfc40u.dll ----a-w 981,760 2006-12-14 13:45:53 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\SP2QFE\mfc42u.dll ----a-w 74,802 2007-01-19 12:52:03 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\SP2QFE\asms\60\msft\vcrtl\atl.dll ----a-w 995,383 2007-01-19 12:52:03 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\SP2QFE\asms\60\msft\vcrtl\mfc42.dll ----a-w 1,011,774 2007-01-19 12:52:04 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\SP2QFE\asms\60\msft\vcrtl\mfc42u.dll ----a-w 401,462 2007-01-19 12:52:04 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\SP2QFE\asms\60\msft\vcrtl\msvcp60.dll ----a-w 22,752 2005-10-12 23:21:27 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\update\spcustom.dll ----a-w 723,680 2005-10-12 23:21:34 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\update\update.exe ----a-w 386,784 2005-10-12 23:21:41 C:\WINDOWS\SoftwareDistribution\Download\d0596b1429e84382fde94c99616455ff\update\updspapi.dll ----a-w 490,736 2005-08-05 22:05:02 C:\WINDOWS\SoftwareDistribution\Download\e4230b38e4c8d51eb4611417bdb88f03\WindowsXP-KB894391-x86-express-PLK.exe ----a-w 339,176 2004-12-13 23:00:07 C:\WINDOWS\SoftwareDistribution\Download\f97c5ee1baff5417a9b063f79c897e49\WindowsXP-KB873339-x86-express-PLK.exe ----a-w 8,694 2007-09-06 07:25:45 C:\WINDOWS\SoftwareDistribution\EventCache{CAE8CD69-CC0D-47BF-89B9-C779FA3DEB27}.bin ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “VTTimer”=“VTTimer.exe” [2006-08-03 14:53 C:\WINDOWS\system32\VTTimer.exe] “S3Trayp”=“S3trayp.exe” [2006-07-11 02:33 C:\WINDOWS\system32\S3Trayp.exe] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe” [2006-10-12 03:10] “ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [2007-03-01 12:29] “Symantec PIF AlertEng”=“C:\Program Files\Common Files\Symantec Shared\PIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe” [2007-03-12 11:22] “!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 11:25] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-09-05 21:14] “MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-08-04 00:55] R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;“C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe” R3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys *Newly Created Service* - COMHOST ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-06 09:43:32 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\H a r m o n o g r a m a u t o m a t y c z n e j u s Bu g i L i v e U p d a t e] “ImagePath”="“C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe”" [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HdAudAddService] “ImagePath”=“system32\drivers\CHDAud.sys” [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HDAudBus] “ImagePath”=“system32\DRIVERS\HDAudBus.sys” [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\helpsvc] “ServiceDll”="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll" [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HidServ] “ServiceDll”="%SystemRoot%\System32\hidserv.dll" [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\hpn] [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HTTP] “ImagePath”=“System32\Drivers\HTTP.sys” [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\HTTPFilter] “ServiceDll”="%SystemRoot%\System32\w3ssl.dll" Completion time: 2007-09-06 9:44:47 C:\ComboFix-quarantined-files.txt … 2007-09-06 09:44 C:\ComboFix2.txt … 2007-09-05 23:17 — E O F —