“Artur i Iza” - 2007-06-29 12:33:36 - ComboFix 07-06-27.7 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-29 ))))))))))))))))))))))))))))))) 2007-06-29 12:33 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-11 20:11 2007-06-11 20:11 2007-06-10 13:35 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-10-06 23:11:45 -------- d-----w C:\Program Files\Common Files\ODBC 2007-10-06 23:11:43 -------- d-----w C:\Program Files\Common Files\SpeechEngines 2007-06-29 10:32:27 22,418,451 ----a-w C:\WINDOWS\system32\dfl1z32.dll 2007-05-28 18:59:00 -------- d-----w C:\DOCUME~1\ARTURI~1\DANEAP~1\HP 2007-05-28 18:58:45 -------- d-----w C:\DOCUME~1\ARTURI~1\DANEAP~1\Image Zone Express 2007-05-27 06:50:58 145,408 ----a-w C:\WINDOWS\system32\rundll32.exe 2007-05-22 20:14:00 -------- d-----w C:\Program Files\Winamp 2007-05-22 17:08:18 397,824 ----a-w C:\WINDOWS\winhlp32.exe 2007-05-22 17:08:16 2,260,992 ----a-w C:\WINDOWS\UNNMP.exe 2007-05-22 17:08:15 2,400,256 ----a-w C:\WINDOWS\UNNeroVision.exe 2007-05-22 17:08:15 137,728 ----a-w C:\WINDOWS\twunk_32.exe 2007-05-22 17:08:12 127,488 ----a-w C:\WINDOWS\TASKMAN.EXE 2007-05-22 17:08:11 142,848 ----a-w C:\WINDOWS\system32\xcopy.exe 2007-05-22 17:08:09 229,376 ----a-w C:\WINDOWS\system32\wscript.exe 2007-05-22 17:08:09 117,760 ----a-w C:\WINDOWS\system32\write.exe 2007-05-22 17:08:08 144,896 ----a-w C:\WINDOWS\system32\wpnpinst.exe 2007-05-22 17:08:08 144,384 ----a-w C:\WINDOWS\system32\wpabaln.exe 2007-05-22 17:08:07 117,760 ----a-w C:\WINDOWS\system32\winver.exe 2007-05-22 17:08:06 123,904 ----a-w C:\WINDOWS\system32\winmsd.exe 2007-05-22 17:08:05 147,456 ----a-w C:\WINDOWS\system32\winchat.exe 2007-05-22 17:08:05 120,320 ----a-w C:\WINDOWS\system32\winhlp32.exe 2007-05-22 17:08:04 547,840 ----a-w C:\WINDOWS\system32\wiaacmgr.exe 2007-05-22 17:08:04 178,176 ----a-w C:\WINDOWS\system32\wextract.exe 2007-05-22 17:07:56 403,968 ----a-w C:\WINDOWS\system32\vssvc.exe 2007-05-22 17:07:55 159,232 ----a-w C:\WINDOWS\system32\uwdf.exe 2007-05-22 17:07:55 145,920 ----a-w C:\WINDOWS\system32\vssadmin.exe 2007-05-22 17:07:54 196,608 ----a-w C:\WINDOWS\system32\usrmlnka.exe 2007-05-22 17:07:54 188,416 ----a-w C:\WINDOWS\system32\usrshuta.exe 2007-05-22 17:07:54 180,224 ----a-w C:\WINDOWS\system32\usrprbda.exe 2007-05-22 17:07:52 137,216 ----a-w C:\WINDOWS\system32\userinit.exe 2007-05-22 17:07:51 130,560 ----a-w C:\WINDOWS\system32\ups.exe 2007-05-22 17:07:51 129,024 ----a-w C:\WINDOWS\system32\upnpcont.exe 2007-05-22 17:07:51 116,224 ----a-w C:\WINDOWS\system32\unlodctr.exe 2007-05-22 17:07:50 148,992 ----a-w C:\WINDOWS\system32\typeperf.exe 2007-05-22 17:07:50 130,048 ----a-w C:\WINDOWS\system32\tsshutdn.exe 2007-05-22 17:07:50 128,512 ----a-w C:\WINDOWS\system32\tskill.exe 2007-05-22 17:07:49 156,672 ----a-w C:\WINDOWS\system32\tscupgrd.exe 2007-05-22 17:07:49 127,488 ----a-w C:\WINDOWS\system32\tsdiscon.exe 2007-05-22 17:07:49 127,488 ----a-w C:\WINDOWS\system32\tscon.exe 2007-05-22 17:07:48 144,384 ----a-w C:\WINDOWS\system32\tracert6.exe 2007-05-22 17:07:48 124,928 ----a-w C:\WINDOWS\system32\tracert.exe 2007-05-22 17:07:47 372,224 ----a-w C:\WINDOWS\system32\tracerpt.exe 2007-05-22 17:07:46 192,512 ----a-w C:\WINDOWS\system32\tlntsess.exe 2007-05-22 17:07:46 187,392 ----a-w C:\WINDOWS\system32\tlntsvr.exe 2007-05-22 17:07:46 175,616 ----a-w C:\WINDOWS\system32\tlntadmn.exe 2007-05-22 17:07:45 189,440 ----a-w C:\WINDOWS\system32\telnet.exe 2007-05-22 17:07:45 131,584 ----a-w C:\WINDOWS\system32\tcpsvcs.exe 2007-05-22 17:07:45 129,024 ----a-w C:\WINDOWS\system32\tftp.exe 2007-05-22 17:07:44 251,904 ----a-w C:\WINDOWS\system32\taskmgr.exe 2007-05-22 17:07:44 127,488 ----a-w C:\WINDOWS\system32\taskman.exe 2007-05-22 17:07:44 125,440 ----a-w C:\WINDOWS\system32\tcmsetup.exe 2007-05-22 17:07:43 182,272 ----a-w C:\WINDOWS\system32\systeminfo.exe 2007-05-22 17:07:43 115,200 ----a-w C:\WINDOWS\system32\systray.exe 2007-05-22 17:07:42 219,136 ----a-w C:\WINDOWS\system32\sysocmgr.exe 2007-05-22 17:07:42 149,504 ----a-w C:\WINDOWS\system32\syskey.exe 2007-05-22 17:07:41 163,328 ----a-w C:\WINDOWS\system32\syncapp.exe 2007-05-22 17:07:40 126,976 ----a-w C:\WINDOWS\system32\stimon.exe 2007-05-22 17:07:40 121,344 ----a-w C:\WINDOWS\system32\subst.exe 2007-05-22 17:07:36 124,928 ----a-w C:\WINDOWS\system32\spiisupd.exe 2007-05-22 17:07:36 123,904 ----a-w C:\WINDOWS\system32\spnpinst.exe 2007-05-22 17:07:35 135,680 ----a-w C:\WINDOWS\system32\sort.exe 2007-05-22 17:07:34 203,264 ----a-w C:\WINDOWS\system32\smlogsvc.exe 2007-05-22 17:07:33 138,240 ----a-w C:\WINDOWS\system32\skeys.exe 2007-05-22 17:07:33 120,320 ----a-w C:\WINDOWS\system32\smbinst.exe 2007-05-22 17:07:32 190,464 ----a-w C:\WINDOWS\system32\shrpubw.exe 2007-05-22 17:07:32 154,624 ----a-w C:\WINDOWS\system32\shmgrate.exe 2007-05-22 17:07:32 132,608 ----a-w C:\WINDOWS\system32\shutdown.exe 2007-05-22 17:07:31 127,488 ----a-w C:\WINDOWS\system32\shadow.exe 2007-05-22 17:07:30 135,168 ----a-w C:\WINDOWS\system32\setup.exe 2007-05-22 17:07:30 121,856 ----a-w C:\WINDOWS\system32\sfc.exe 2007-05-22 17:07:29 144,896 ----a-w C:\WINDOWS\system32\sethc.exe 2007-05-22 17:07:28 189,952 ----a-w C:\WINDOWS\system32\sdbinst.exe 2007-05-22 17:07:28 131,072 ----a-w C:\WINDOWS\system32\secedit.exe 2007-05-22 17:07:27 240,128 ----a-w C:\WINDOWS\system32\schtasks.exe 2007-05-22 17:07:27 210,432 ----a-w C:\WINDOWS\system32\scardsvr.exe 2007-05-22 17:07:26 143,360 ----a-w C:\WINDOWS\system32\sc.exe 2007-05-22 17:07:26 128,512 ----a-w C:\WINDOWS\system32\rwinsta.exe 2007-05-22 17:07:26 125,952 ----a-w C:\WINDOWS\system32\savedump.exe 2007-05-22 17:07:25 129,024 ----a-w C:\WINDOWS\system32\runas.exe 2007-05-22 17:07:25 126,464 ----a-w C:\WINDOWS\system32\runonce.exe 2007-05-22 17:07:24 244,736 ----a-w C:\WINDOWS\system32\rsvp.exe 2007-05-22 17:07:24 189,952 ----a-w C:\WINDOWS\system32\rtcshare.exe 2007-05-22 17:07:24 175,104 ----a-w C:\WINDOWS\system32\rsopprov.exe 2007-05-22 17:07:23 219,648 ----a-w C:\WINDOWS\system32\rsnotify.exe 2007-05-22 17:07:23 161,280 ----a-w C:\WINDOWS\system32\rsmui.exe 2007-05-22 17:07:23 136,704 ----a-w C:\WINDOWS\system32\rsmsink.exe 2007-05-22 17:07:22 166,400 ----a-w C:\WINDOWS\system32\rsm.exe 2007-05-22 17:07:22 127,488 ----a-w C:\WINDOWS\system32\rsh.exe 2007-05-22 17:07:21 137,728 ----a-w C:\WINDOWS\system32\routemon.exe 2007-05-22 17:07:21 132,608 ----a-w C:\WINDOWS\system32\route.exe 2007-05-22 17:07:21 126,464 ----a-w C:\WINDOWS\system32\rexec.exe 2007-05-22 17:07:19 145,920 ----a-w C:\WINDOWS\system32\relog.exe 2007-05-22 17:07:19 124,928 ----a-w C:\WINDOWS\system32\replace.exe 2007-05-22 17:07:19 121,856 ----a-w C:\WINDOWS\system32\reset.exe 2007-05-22 17:07:16 124,416 ----a-w C:\WINDOWS\system32\regsvr32.exe 2007-05-22 17:07:16 116,736 ----a-w C:\WINDOWS\system32\regwiz.exe 2007-05-22 17:07:15 165,376 ----a-w C:\WINDOWS\system32\reg.exe 2007-05-22 17:07:15 145,920 ----a-w C:\WINDOWS\system32\regini.exe 2007-05-22 17:07:15 115,712 ----a-w C:\WINDOWS\system32\regedt32.exe 2007-05-22 17:07:14 179,200 ----a-w C:\WINDOWS\system32\rdshost.exe ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 15:21] {F6104497-54FD-4688-9162-5115CC8AB0FB}=C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll [2007-03-20 17:27] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “nwiz”=“nwiz.exe” [2007-05-22 14:19 C:\WINDOWS\system32\nwiz.exe] “SoundMan”=“SOUNDMAN.EXE” [2005-05-17 12:48 C:\WINDOWS\SOUNDMAN.EXE] “RemoteControl”=“C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe” [2003-10-31 19:42] “HP Software Update”=“C:\Program Files\HP\HP Software Update\HPWuSchd2.exe” [2007-05-22 14:12] “Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2007-05-11 03:06] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe” [2007-06-07 09:48] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 01:44] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2007-05-10 16:36] ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-29 12:34:03 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-29 12:34:22 — E O F —