oto log z ComboFix
ComboFix 07-11-08.3 - banan213 2007-11-19 19:32:06.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.432 [GMT 1:00]
Running from: C:\Opera dowlands\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 )))))))))))))))))))))))))))))))
.
2007-11-18 21:18
2007-11-18 20:34
2007-11-18 18:58 6,820 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-11-18 18:58 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-11-18 18:42
2007-11-18 18:41
2007-11-18 18:31
2007-11-18 12:30
2007-11-18 12:29
2007-11-18 12:28 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-11-18 11:37 0 --a------ C:\WINDOWS\ativpsrm.bin
2007-11-17 23:06
2007-11-16 12:18 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-15 23:54
2007-11-15 23:54
2007-11-15 23:54
2007-11-15 23:54
2007-11-15 23:54
2007-11-15 23:54
2007-11-15 23:54
2007-11-14 23:09
2007-11-14 23:09
2007-11-14 23:09
2007-11-14 23:09 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-11-14 23:09 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-14 23:09 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-14 23:09 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-14 23:09 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-10-30 16:49
2007-10-30 16:16
2007-10-30 16:13 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-10-29 16:43 531,248 --a------ C:\WINDOWS\system32\es.scr
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-18 19:32 --------- d–h--w C:\Program Files\InstallShield Installation Information
2007-11-18 11:35 --------- d-----w C:\Program Files\MSBuild
2007-11-18 10:33 --------- d-----w C:\Program Files\ATI Technologies
2007-11-13 23:36 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help
2007-10-30 15:49 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-10-30 15:21 --------- d-----w C:\Program Files\Yahoo!
2007-10-22 21:43 --------- d-----w C:\Program Files\Opera
2007-10-13 17:25 --------- d-----w C:\Documents and Settings\banan213\Dane aplikacji\SopCast
2007-10-13 17:09 --------- d-----w C:\Program Files\SopCast
2007-10-11 18:08 --------- d-----w C:\Program Files\BearShare Applications
2007-10-09 16:27 --------- d-----w C:\Program Files\Java
2007-09-29 05:46 47,376 ----a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-09-29 03:21 9,854,976 ----a-w C:\WINDOWS\system32\atioglx2.dll
2007-09-29 03:07 356,352 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-09-29 03:06 268,800 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2007-09-29 03:05 2,456,064 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-09-29 02:58 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2007-09-29 02:58 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-09-29 02:58 143,360 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2007-09-29 02:58 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2007-09-29 02:57 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2007-09-29 02:56 483,328 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2007-09-29 02:55 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-09-29 02:49 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2007-09-29 02:47 3,130,720 ----a-w C:\WINDOWS\system32\ati3duag.dll
2007-09-29 02:47 172,032 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2007-09-29 02:36 1,593,600 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2007-09-29 02:23 5,435,392 ----a-w C:\WINDOWS\system32\atioglxx.dll
2007-09-29 02:22 376,832 ----a-w C:\WINDOWS\system32\atikvmag.dll
2007-09-29 02:20 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2007-09-29 02:19 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-09-29 02:14 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2007-09-28 20:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-09-03 15:06 676,224 ----a-w C:\WINDOWS\system32\OGACheckControl.dll
2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2001-11-23 04:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Cmaudio”=“cmicnfg.cpl” []
“ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-05-03 20:05]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 11:06]
“AGRSMMSG”=“AGRSMMSG.exe” [2004-06-29 08:06 C:\WINDOWS\AGRSMMSG.exe]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 00:11]
“OM_Monitor”=“C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe” [2005-11-29 18:19]
“GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-26 23:47]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 09:50]
“SDTray”=“C:\Program Files\Spyware Doctor\SDTrayApp.exe” [2007-11-02 17:24]
“StartCCC”=“C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe” [2006-11-10 12:35]
“CatalystRegistration”=“C:\Program Files\ATI\CatalystRegistration\dolce.exe” [2007-07-27 12:04]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-07-09 08:39]
“MSMSGS”=“C:\Program Files\Messenger\MSMSGS.exe” [2004-10-13 17:24]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 08:44]
“OM_Monitor”=“C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe” [2005-11-29 18:19]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe” []
“AlcoholAutomount”=“C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe” [2007-07-02 11:27]
“eMuleAutoStart”=“C:\Program Files\eMule\emule.exe” []
“Steam”=“c:\program files\steam\steam.exe” [2007-11-18 18:45]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-19 19:34:22
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-19 19:35:23
.
— E O F —