“Kryhu” - 2007-05-21 12:33:02 Dodatek Service Pack 2 ComboFix 07-05.21.6.V - Running from: “C:\Documents and Settings\Kryhu\Pulpit\Problem temp2.exe” (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\temp2.exe c:\autorun.inf c:\copy.exe c:\host.exe d:\autorun.inf d:\copy.exe d:\host.exe e:\autorun.inf e:\copy.exe e:\host.exe C:\WINDOWS\autorun.inf C:\WINDOWS\svchost.exe C:\WINDOWS\xcopy.exe ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-21 )))))))))))))))))))))))))))))))))) 2007-05-19 12:42 2007-05-19 09:54 60,273 --a------ C:\WINDOWS\system32\pthreadGC2.dll 2007-05-19 09:54 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-05-19 09:43 2007-05-19 09:05 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe 2007-05-19 09:05 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe 2007-05-19 09:05 2007-05-17 12:05 2007-05-16 13:40 2007-05-16 13:21 311,808 --a------ C:\WINDOWS\system32\CAMSDKR.DLL 2007-05-16 13:21 11,776 --a------ C:\WINDOWS\system32\pmsbfn32.dll 2007-05-16 13:21 2007-05-16 13:21 2007-05-15 19:05 10 --a------ C:\WINDOWS\popcinfo.dat 2007-05-13 22:40 2007-05-12 21:49 2007-05-12 20:58 2007-05-12 14:11 30,512 --a------ C:\WINDOWS\system32\mdimon.dll 2007-05-12 14:10 2007-05-12 14:10 2007-05-12 14:08 2007-05-12 14:08 2007-05-12 14:08 2007-05-12 14:02 639,224 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-05-12 13:27 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys 2007-05-12 13:27 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-05-12 13:27 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys 2007-05-12 13:27 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys 2007-05-12 13:27 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-05-12 13:27 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-05-12 13:27 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-05-12 13:27 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys 2007-05-12 13:27 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-05-12 13:27 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2007-05-12 13:27 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys 2007-05-12 13:27 4,096 --a------ C:\WINDOWS\system32\ksuser.dll 2007-05-12 13:27 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-05-12 13:27 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-05-12 13:27 21,504 --a------ C:\WINDOWS\system32\hidserv.dll 2007-05-12 13:27 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2007-05-12 13:27 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys 2007-05-12 13:27 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys 2007-05-12 13:27 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys 2007-05-12 13:27 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-05-12 13:27 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys 2007-05-12 13:27 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys 2007-05-12 13:26 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-05-12 13:26 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-05-12 13:26 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-05-12 13:26 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-05-12 13:26 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-05-12 13:26 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-05-12 13:26 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-05-12 13:26 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-05-12 13:26 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-05-12 13:26 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-05-12 13:26 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-05-12 13:26 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-05-12 13:26 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-05-12 13:26 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-05-12 13:26 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-05-12 13:26 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-05-12 13:26 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-05-12 13:26 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-05-12 13:26 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-05-12 13:26 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-05-12 13:26 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-05-12 13:26 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-05-12 13:26 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-05-12 13:26 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-05-12 13:26 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-05-12 13:26 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-05-12 13:26 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-05-12 13:26 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-05-12 13:26 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-05-12 13:26 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll 2007-05-12 13:26 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-05-12 13:26 5,632 --a------ C:\WINDOWS\system32\kbdro.dll 2007-05-12 13:26 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll 2007-05-12 13:26 5,120 --a------ C:\WINDOWS\system\SHELL.DLL 2007-05-12 13:26 33,376 --a------ C:\WINDOWS\system\COMMDLG.DLL 2007-05-12 13:26 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-05-12 13:26 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL 2007-05-12 13:26 19,200 --a------ C:\WINDOWS\system\TAPI.DLL 2007-05-12 13:26 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll 2007-05-12 13:26 15,360 --a------ C:\WINDOWS\TASKMAN.EXE 2007-05-12 13:26 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-05-12 13:26 127,008 --a------ C:\WINDOWS\system\MSVIDEO.DLL 2007-05-12 13:26 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys 2007-05-12 13:26 109,488 --a------ C:\WINDOWS\system\AVIFILE.DLL 2007-05-12 13:26 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll 2007-05-12 13:26 2007-05-12 13:26 2007-05-12 13:26 2007-05-12 13:26 2007-05-12 13:25 8,704 --a------ C:\WINDOWS\system32\batt.dll 2007-05-12 13:25 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-05-12 13:25 70,144 --a------ C:\WINDOWS\notepad.exe 2007-05-12 13:25 69,552 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:25 2007-05-12 13:24 2007-05-12 13:24 2007-05-12 13:24 2007-05-12 13:24 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:20 2007-05-12 13:14 2007-05-12 13:13 2007-05-12 13:13 2007-05-12 13:10 2007-05-12 13:10 2007-05-12 13:10 2007-05-12 13:09 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll 2007-05-12 13:09 831,048 --a------ C:\WINDOWS\system32\WudfUpdate_01005.dll 2007-05-12 13:09 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys 2007-05-12 13:09 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll 2007-05-12 13:09 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys 2007-05-12 13:09 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys 2007-05-12 13:09 2007-05-12 13:07 2007-05-12 13:00 2007-05-12 13:00 2007-05-12 13:00 2007-05-12 13:00 2007-05-12 12:44 2007-05-12 12:30 2007-05-12 12:29 2007-05-12 12:28 2007-05-12 12:25 47,251 --a------ C:\WINDOWS\BricoPackUninst.cmd 2007-05-12 12:24 2,096 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd 2007-05-12 12:24 2007-05-12 12:21 2007-05-12 12:20 2007-05-12 12:16 2007-05-12 12:15 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-05-12 12:12 2007-05-12 12:07 2007-05-12 12:07 2007-05-12 12:07 2007-05-12 12:03 60,416 --a------ C:\WINDOWS\ALCFDRTM.EXE 2007-05-12 12:03 2007-05-12 11:59 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-05-12 11:59 2007-05-12 11:59 2007-05-12 11:59 2007-05-12 11:59 2007-05-12 11:58 2007-05-12 11:57 2007-05-12 11:57 2007-05-12 11:56 51,120 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys 2007-05-12 11:56 37,376 --a------ C:\WINDOWS\system32\hpz3l3xu.dll 2007-05-12 11:56 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys 2007-05-12 11:54 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll 2007-05-12 11:54 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe 2007-05-12 11:54 61,440 --a------ C:\WINDOWS\system32\HPZinw12.exe 2007-05-12 11:54 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll 2007-05-12 11:54 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-05-12 11:54 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll 2007-05-12 11:54 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll 2007-05-12 11:50 79,909 --a------ C:\WINDOWS\hpfins05.dat 2007-05-12 11:50 1,547 --------- C:\WINDOWS\hpfmdl05.dat 2007-05-12 11:50 2007-05-12 11:49 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll 2007-05-12 11:49 49,152 -ra------ C:\WINDOWS\AutoSet.dll 2007-05-12 11:49 45,056 -ra------ C:\WINDOWS\system32\micdrv.dll 2007-05-12 11:49 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-05-12 11:47 2007-05-12 11:44 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe 2007-05-12 11:44 2007-05-12 11:41 9,319,936 --a------ C:\WINDOWS\system32\RTLCPL.EXE 2007-05-12 11:41 77,824 --a------ C:\WINDOWS\SOUNDMAN.EXE 2007-05-12 11:41 40,960 --------- C:\WINDOWS\system32\ChCfg.exe 2007-05-12 11:41 208,896 --------- C:\WINDOWS\alcupd.exe 2007-05-12 11:41 2,297,664 --a------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2007-05-12 11:41 156,672 --a------ C:\WINDOWS\system32\RTLCPAPI.dll 2007-05-12 11:41 139,264 --------- C:\WINDOWS\alcrmv.exe 2007-05-12 11:41 2007-05-12 11:41 2007-05-12 11:41 2007-05-12 11:40 9,728 -ra------ C:\WINDOWS\system32\bdco1ins.dll 2007-05-12 11:40 9,728 -ra------ C:\WINDOWS\system32\bdco1.dll 2007-05-12 11:40 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS 2007-05-12 11:40 5,810 -ra------ C:\WINDOWS\system32\drivers\ASACPI.sys 2007-05-12 11:40 405,504 --a------ C:\WINDOWS\system32\CapabilityTable.exe 2007-05-12 11:40 33,408 -ra------ C:\WINDOWS\system32\drivers\NVENETFD.sys 2007-05-12 11:40 32,256 -ra------ C:\WINDOWS\system32\nvconrm.dll 2007-05-12 11:40 260,736 -ra------ C:\WINDOWS\system32\drivers\nvnrm.sys 2007-05-12 11:40 208,896 --a------ C:\WINDOWS\system32\nvusmb.exe 2007-05-12 11:40 208,896 --a------ C:\WINDOWS\system32\nvunrm.exe 2007-05-12 11:40 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2007-05-12 11:40 208,896 --a------ C:\WINDOWS\system32\nvuide.exe 2007-05-12 11:40 208,256 -ra------ C:\WINDOWS\system32\drivers\nvsnpu.sys 2007-05-12 11:40 200,192 -ra------ C:\WINDOWS\system32\fdco1ins.dll 2007-05-12 11:40 200,192 -ra------ C:\WINDOWS\system32\fdco1.dll 2007-05-12 11:40 12,928 -ra------ C:\WINDOWS\system32\drivers\nvnetbus.sys 2007-05-12 11:40 2007-05-12 11:40 2007-05-12 11:38 2007-05-12 11:37 2,359,296 --ah----- C:\DOCUME~1\Kryhu\NTUSER.DAT 2007-05-12 11:37 2007-05-12 11:37 2007-05-12 11:37 2007-05-12 11:37 2007-05-12 11:37 2007-05-12 11:37 2007-05-12 11:35 229,376 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT 2007-05-12 11:35 2007-05-12 11:35 2007-05-12 11:35 2007-05-12 11:35 2007-05-12 11:34 229,376 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT 2007-05-12 11:34 2007-05-12 11:34 2007-05-12 11:32 229,376 —h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT 2007-05-12 11:32 0 -rahs---- C:\MSDOS.SYS 2007-05-12 11:32 0 -rahs---- C:\IO.SYS 2007-05-12 11:32 0 --a------ C:\CONFIG.SYS 2007-05-12 11:32 0 --a------ C:\AUTOEXEC.BAT 2007-05-12 11:32 2007-05-12 11:32 2007-05-12 11:31 112,128 --a------ C:\WINDOWS\system32\mapi32.dll 2007-05-12 11:31 2007-05-12 11:31 2007-05-12 11:31 2007-05-12 11:31 2007-05-12 11:31 2007-05-12 11:31 2007-05-12 11:30 86,016 --a------ C:\WINDOWS\system32\isign32.dll 2007-05-12 11:30 81,920 --a------ C:\WINDOWS\system32\ils.dll 2007-05-12 11:30 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll 2007-05-12 11:30 73,728 --a------ C:\WINDOWS\system32\icwdial.dll 2007-05-12 11:30 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys 2007-05-12 11:30 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll 2007-05-12 11:30 69,632 --a------ C:\WINDOWS\system32\msconf.dll 2007-05-12 11:30 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-05-12 11:30 67,584 --a------ C:\WINDOWS\system32\srclient.dll 2007-05-12 11:30 67,584 --a------ C:\WINDOWS\system32\acctres.dll 2007-05-12 11:30 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll 2007-05-12 11:30 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll 2007-05-12 11:30 49,664 --a------ C:\WINDOWS\system32\inetres.dll 2007-05-12 11:30 466,200 --a------ C:\WINDOWS\system32\wuapi.dll 2007-05-12 11:30 45,568 --a------ C:\WINDOWS\system32\safrslv.dll 2007-05-12 11:30 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll 2007-05-12 11:30 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll 2007-05-12 11:30 41,240 --a------ C:\WINDOWS\system32\wups.dll 2007-05-12 11:30 382,464 --a------ C:\WINDOWS\system32\qmgr.dll 2007-05-12 11:30 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll 2007-05-12 11:30 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe 2007-05-12 11:30 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll 2007-05-12 11:30 29,696 --a------ C:\WINDOWS\system32\safrdm.dll 2007-05-12 11:30 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll 2007-05-12 11:30 278,528 --a------ C:\WINDOWS\system32\mstask.dll 2007-05-12 11:30 278,528 --a------ C:\WINDOWS\system32\inetcfg.dll 2007-05-12 11:30 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll 2007-05-12 11:30 240,128 --a------ C:\WINDOWS\system32\srrstr.dll 2007-05-12 11:30 23,040 --a------ C:\WINDOWS\system32\fltmc.exe 2007-05-12 11:30 195,352 --a------ C:\WINDOWS\system32\wuaueng1.dll 2007-05-12 11:30 192,000 --a------ C:\WINDOWS\system32\schedsvc.dll 2007-05-12 11:30 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll 2007-05-12 11:30 175,384 --a------ C:\WINDOWS\system32\wuauclt1.exe 2007-05-12 11:30 173,536 --a------ C:\WINDOWS\system32\wuweb.dll 2007-05-12 11:30 171,008 --a------ C:\WINDOWS\system32\srsvc.dll 2007-05-12 11:30 16,896 --a------ C:\WINDOWS\system32\fltlib.dll 2007-05-12 11:30 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll 2007-05-12 11:30 128,896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys 2007-05-12 11:30 128,280 --a------ C:\WINDOWS\system32\wucltui.dll 2007-05-12 11:30 125,208 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-05-12 11:30 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll 2007-05-12 11:30 12,288 --a------ C:\WINDOWS\system32\mstinit.exe 2007-05-12 11:30 11,264 --a------ C:\WINDOWS\system32\atrace.dll 2007-05-12 11:30 105,984 --a------ C:\WINDOWS\system32\msoert2.dll 2007-05-12 11:30 1,343,768 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-05-12 11:30 2007-05-12 11:30 2007-05-12 11:30 2007-05-12 11:30 2007-05-12 11:30 2007-05-12 11:30 2007-05-12 11:29 97,792 --a------ C:\WINDOWS\system32\comrepl.dll 2007-05-12 11:29 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll 2007-05-12 11:29 94,720 --a------ C:\WINDOWS\system32\tscfgwmi.dll 2007-05-12 11:29 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll 2007-05-12 11:29 9,728 --a------ C:\WINDOWS\system32\reset.exe 2007-05-12 11:29 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll 2007-05-12 11:29 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll 2007-05-12 11:29 80,896 --a------ C:\WINDOWS\system32\charmap.exe 2007-05-12 11:29 73,216 --a------ C:\WINDOWS\system32\avwav.dll 2007-05-12 11:29 67,072 --a------ C:\WINDOWS\system32\rdshost.exe 2007-05-12 11:29 655,360 --a------ C:\WINDOWS\system32\mstscax.dll 2007-05-12 11:29 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll 2007-05-12 11:29 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe 2007-05-12 11:29 605,696 --a------ C:\WINDOWS\system32\getuname.dll 2007-05-12 11:29 60,928 --a------ C:\WINDOWS\system32\remotepg.dll 2007-05-12 11:29 60,416 --a------ C:\WINDOWS\system32\colbact.dll 2007-05-12 11:29 6,144 --a------ C:\WINDOWS\system32\msdtc.exe 2007-05-12 11:29 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll 2007-05-12 11:29 58,880 --a------ C:\WINDOWS\system32\licwmi.dll 2007-05-12 11:29 57,344 --a------ C:\WINDOWS\system32\sol.exe 2007-05-12 11:29 56,320 --a------ C:\WINDOWS\system32\servdeps.dll 2007-05-12 11:29 55,808 --a------ C:\WINDOWS\system32\freecell.exe 2007-05-12 11:29 540,160 --a------ C:\WINDOWS\system32\comuid.dll 2007-05-12 11:29 54,272 --a------ C:\WINDOWS\system32\stclient.dll 2007-05-12 11:29 539,136 --a------ C:\WINDOWS\system32\spider.exe 2007-05-12 11:29 5,632 --a------ C:\WINDOWS\system32\write.exe 2007-05-12 11:29 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe 2007-05-12 11:29 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll 2007-05-12 11:29 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe 2007-05-12 11:29 44,544 --a------ C:\WINDOWS\system32\hticons.dll 2007-05-12 11:29 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll 2007-05-12 11:29 408,576 --a------ C:\WINDOWS\system32\mstsc.exe 2007-05-12 11:29 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys 2007-05-12 11:29 4,608 --a------ C:\WINDOWS\system32\rdpcfgex.dll 2007-05-12 11:29 4,096 --a------ C:\WINDOWS\system32\mtxex.dll 2007-05-12 11:29 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll 2007-05-12 11:29 351,744 --a------ C:\WINDOWS\system32\hypertrm.dll 2007-05-12 11:29 35,328 --a------ C:\WINDOWS\system32\winchat.exe 2007-05-12 11:29 345,088 --a------ C:\WINDOWS\system32\mspaint.exe 2007-05-12 11:29 33,792 --a------ C:\WINDOWS\system32\regini.exe 2007-05-12 11:29 296,448 --a------ C:\WINDOWS\system32\termsrv.dll 2007-05-12 11:29 25,600 --a------ C:\WINDOWS\system32\comaddin.dll 2007-05-12 11:29 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll 2007-05-12 11:29 231,424 --a------ C:\WINDOWS\system32\avtapi.dll 2007-05-12 11:29 225,792 --a------ C:\WINDOWS\system32\catsrv.dll 2007-05-12 11:29 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe 2007-05-12 11:29 22,528 --a------ C:\WINDOWS\system32\msg.exe 2007-05-12 11:29 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys 2007-05-12 11:29 21,856 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-05-12 11:29 20,992 --a------ C:\WINDOWS\system32\qprocess.exe 2007-05-12 11:29 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll 2007-05-12 11:29 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys 2007-05-12 11:29 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll 2007-05-12 11:29 187,904 --a------ C:\WINDOWS\system32\cmprops.dll 2007-05-12 11:29 187,904 --a------ C:\WINDOWS\system32\accwiz.exe 2007-05-12 11:29 17,920 --a------ C:\WINDOWS\system32\tsshutdn.exe 2007-05-12 11:29 17,920 --a------ C:\WINDOWS\system32\mmfutil.dll 2007-05-12 11:29 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe 2007-05-12 11:29 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll 2007-05-12 11:29 16,384 --a------ C:\WINDOWS\system32\tskill.exe 2007-05-12 11:29 16,384 --a------ C:\WINDOWS\system32\rwinsta.exe 2007-05-12 11:29 16,384 --a------ C:\WINDOWS\system32\avmeter.dll 2007-05-12 11:29 15,872 --a------ C:\WINDOWS\system32\logoff.exe 2007-05-12 11:29 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll 2007-05-12 11:29 15,360 --a------ C:\WINDOWS\system32\tsdiscon.exe 2007-05-12 11:29 15,360 --a------ C:\WINDOWS\system32\tscon.exe 2007-05-12 11:29 15,360 --a------ C:\WINDOWS\system32\shadow.exe 2007-05-12 11:29 147,968 --a------ C:\WINDOWS\system32\rdchost.dll 2007-05-12 11:29 147,456 --a------ C:\WINDOWS\system32\comsnap.dll 2007-05-12 11:29 141,824 --a------ C:\WINDOWS\system32\sessmgr.exe 2007-05-12 11:29 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys 2007-05-12 11:29 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe 2007-05-12 11:29 132,608 --a------ C:\WINDOWS\system32\sndrec32.exe 2007-05-12 11:29 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe 2007-05-12 11:29 128,000 --a------ C:\WINDOWS\system32\mshearts.exe 2007-05-12 11:29 124,928 --a------ C:\WINDOWS\system32\mplay32.exe 2007-05-12 11:29 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys 2007-05-12 11:29 119,808 --a------ C:\WINDOWS\system32\winmine.exe 2007-05-12 11:29 115,200 --a------ C:\WINDOWS\system32\calc.exe 2007-05-12 11:29 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll 2007-05-12 11:29 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll 2007-05-12 11:29 11,264 --a------ C:\WINDOWS\system32\icaapi.dll 2007-05-12 11:29 103,424 --a------ C:\WINDOWS\system32\clipbrd.exe 2007-05-12 11:29 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll 2007-05-12 11:29 1,225 --a------ C:\WINDOWS\system32\usrlogon.cmd 2007-05-12 11:29 2007-05-12 11:29 2007-05-12 11:29 2007-05-12 11:29 2007-05-12 11:29 2007-05-12 11:29 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-05-12 10:25:24 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll 2007-05-12 10:21:04 67,078 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-05-12 10:21:04 435,978 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-05-12 09:31:08 -------- d-----w C:\Program Files\Usługi online 2007-04-23 00:15:25 36,624 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys 2007-03-27 01:39:14 20,480 ----a-w C:\WINDOWS\system32\ac3config.exe 2007-03-17 13:45:36 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll 2007-03-08 15:38:47 579,072 ----a-w C:\WINDOWS\system32\user32.dll 2007-03-08 15:38:47 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll 2007-03-08 15:38:47 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll 2007-03-08 15:37:33 1,843,840 ----a-w C:\WINDOWS\system32\win32k.sys 2007-02-05 20:19:48 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Programy\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 06:12] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Programy\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [] “NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-08-11 15:43] “nwiz”=“nwiz.exe” [2006-08-11 15:43 C:\WINDOWS\system32\nwiz.exe] “NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2006-08-11 15:43] “iKeyWorks”=“C:\PROGRA~1\Programy\A4Tech\Keyboard\Ikeymain.exe” [2004-08-31 07:33] “WheelMouse”=“C:\PROGRA~1\Programy\A4Tech\Mouse\Amoumain.exe” [2004-08-31 20:28] “HP Software Update”=“C:\Program Files\Programy\HP\HP Software Update\HPWuSchd2.exe” [2005-05-11 23:12] “SunJavaUpdateSched”=“C:\Program Files\Programy\Java\jre1.6.0_01\bin\jusched.exe” [2007-03-14 03:43] “PCSuiteTrayApplication”=“C:\Program Files\Programy\Nokia\Nokia PC Suite 6\LaunchApplication.exe” [2007-03-23 13:20] “NeroFilterCheck”=“C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe” [2006-01-12 15:40] “DAEMON Tools”=“C:\Program Files\Programy\DAEMON Tools\daemon.exe” [2006-11-12 12:48] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “Gadu-Gadu”=“C:\Program Files\Programy\Gadu-Gadu\gg.exe” [2007-01-30 16:58] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Nokia.PCSync”=C:\Program Files\Programy\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{d9936c12-012a-11dc-874c-0013d4541520}] AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe *Newly Created Service* -HTTPFILTER *Newly Created Service* -PROCEXP90 ~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ backup-20070521-123051-221 F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe ******************************************************************** catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-21 12:33:42 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ******************************************************************** Completion time: 2007-05-21 12:33:56 C:\ComboFix-quarantined-files.txt … 2007-05-21 12:33 — E O F —