ComboFix 07-12-21.4 - Sylwia&Romek 2007-12-30 21:29:10.1 - NTFSx86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.282 [GMT 1:00] Running from: C:\Documents and Settings\Sylwia&Romek\Pulpit\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-30 ))))))))))))))))))))))))))))))) . 2007-12-30 21:14 . 2007-12-30 21:14 2007-12-30 21:13 . 2007-12-30 21:13 2007-12-12 20:45 . 2007-12-12 20:45 2007-12-12 20:45 . 2007-12-12 20:46 2007-12-04 07:12 . 2007-12-04 07:12 22 --a------ C:\WINDOWS\system32\ati64hlp.stb 2007-12-03 18:24 . 2007-12-03 18:24 22 --a------ C:\WINDOWS\system32\ati64hl2.stb 2007-12-03 17:06 . 2007-12-03 17:06 2007-11-28 08:21 . 2002-10-12 21:00 110,677 --------- C:\WINDOWS\system32\ati2sgag.exe 2007-11-28 08:15 . 2007-11-28 08:15 2007-11-28 08:00 . 2007-11-28 08:00 2007-11-26 09:49 . 2007-11-26 09:49 2007-11-26 09:49 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl 2007-11-26 09:48 . 2007-11-26 09:49 2007-11-26 09:48 . 2007-11-26 09:48 2007-11-26 09:47 . 2007-11-26 09:49 671 --a------ C:\WINDOWS\mozver.dat 2007-11-25 20:27 . 2007-11-25 20:27 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe 2007-11-23 16:17 . 2007-12-03 08:01 2007-11-19 08:24 . 2007-12-27 22:03 69 --a------ C:\WINDOWS\NeroDigital.ini 2007-11-19 08:16 . 2007-11-19 08:16 2007-11-19 08:10 . 2007-11-19 08:10 2007-11-19 08:10 . 2007-11-19 08:14 2007-11-19 08:10 . 2007-11-19 08:10 2007-11-14 14:58 . 2006-10-26 19:58 30,512 --a------ C:\WINDOWS\system32\mdimon.dll 2007-11-12 11:35 . 2007-11-12 11:35 10 --a------ C:\WINDOWS\WININIT.INI 2007-11-12 11:17 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-11-10 15:58 . 2007-11-10 16:21 2007-11-09 11:00 . 2007-11-09 11:00 2007-11-09 10:57 . 2007-11-09 10:57 2007-11-08 09:52 . 2007-11-08 09:52 2007-11-07 20:31 . 2007-11-07 20:31 2007-11-06 11:55 . 2007-11-06 11:55 2007-11-05 20:46 . 2007-11-21 07:07 2007-11-05 16:50 . 2007-11-05 16:50 2007-11-03 18:25 . 2007-11-03 19:44 2007-11-03 18:13 . 2007-11-03 18:14 2007-11-03 18:13 . 2007-11-03 18:14 2007-11-03 14:07 . 2007-11-03 14:07 2007-11-03 14:07 . 2007-11-03 14:08 2007-11-03 11:58 . 2007-11-03 11:58 2007-11-03 11:58 . 2007-11-19 07:53 2007-11-03 09:19 . 2007-11-03 09:19 2007-11-03 09:19 . 2007-11-03 09:19 0 --a------ C:\WINDOWS\nsreg.dat 2007-11-03 08:51 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll 2007-11-03 08:49 . 2007-11-03 08:49 2007-11-03 08:45 . 2007-11-03 08:45 2007-11-03 08:41 . 2007-11-03 08:41 2007-11-03 08:40 . 2007-11-03 08:47 2007-11-03 08:37 . 2007-11-14 15:05 2007-11-03 08:36 . 2007-11-03 08:36 2007-11-03 03:53 . 2007-05-17 12:30 549,376 -----c— C:\WINDOWS\system32\dllcache\oleaut32.dll 2007-11-03 03:51 . 2007-11-03 03:51 2007-11-03 03:51 . 2007-06-26 14:57 851,968 -----c— C:\WINDOWS\system32\dllcache\vgx.dll 2007-11-03 03:48 . 2007-11-03 03:48 2007-11-03 03:48 . 2007-11-03 03:48 2007-11-03 03:48 . 2007-06-26 07:10 1,104,896 -----c— C:\WINDOWS\system32\dllcache\msxml3.dll 2007-11-03 03:46 . 2007-06-13 14:23 1,034,752 -----c— C:\WINDOWS\system32\dllcache\explorer.exe 2007-11-03 03:39 . 2007-04-25 15:23 144,896 -----c— C:\WINDOWS\system32\dllcache\schannel.dll 2007-11-03 03:38 . 2007-04-23 11:14 364,160 -----c— C:\WINDOWS\system32\dllcache\update.sys 2007-11-03 03:37 . 2007-05-16 16:19 1,314,816 -----c— C:\WINDOWS\system32\dllcache\msoe.dll 2007-11-03 03:37 . 2007-05-16 16:19 510,976 -----c— C:\WINDOWS\system32\dllcache\wab32.dll 2007-11-03 03:37 . 2007-05-16 16:18 86,528 -----c— C:\WINDOWS\system32\dllcache\directdb.dll 2007-11-03 03:37 . 2007-05-16 16:19 85,504 -----c— C:\WINDOWS\system32\dllcache\wabimp.dll 2007-11-03 03:36 . 2007-05-16 16:18 683,520 -----c— C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-11-03 03:36 . 2007-04-16 22:45 43,352 --a------ C:\WINDOWS\system32\wups2.dll 2007-11-03 03:36 . 2007-04-16 22:45 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui 2007-11-03 03:36 . 2007-04-16 22:47 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui 2007-11-03 03:36 . 2007-04-16 22:47 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui 2007-11-03 03:36 . 2007-04-16 22:45 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui 2007-11-03 03:35 . 2007-02-09 12:10 574,464 -----c— C:\WINDOWS\system32\dllcache\ntfs.sys 2007-11-03 03:33 . 2007-03-17 14:45 293,376 -----c— C:\WINDOWS\system32\dllcache\winsrv.dll 2007-11-03 03:32 . 2007-02-05 21:19 185,856 -----c— C:\WINDOWS\system32\dllcache\upnphost.dll 2007-11-03 03:30 . 2007-04-11 07:47 1,843,840 -----c— C:\WINDOWS\system32\dllcache\win32k.sys 2007-11-03 03:30 . 2007-03-08 16:38 579,072 -----c— C:\WINDOWS\system32\dllcache\user32.dll 2007-11-03 03:30 . 2007-02-19 11:34 343,040 -----c— C:\WINDOWS\system32\dllcache\msvcrt.dll 2007-11-03 03:30 . 2007-06-19 14:32 282,112 -----c— C:\WINDOWS\system32\dllcache\gdi32.dll 2007-11-03 03:30 . 2007-03-08 16:38 40,960 -----c— C:\WINDOWS\system32\dllcache\mf3216.dll 2007-11-03 03:29 . 2007-11-03 03:29 2007-11-03 03:28 . 2006-12-21 14:16 288,768 --------- C:\WINDOWS\system32\rhttpaa.dll 2007-11-03 03:28 . 2006-10-16 17:16 123,392 -----c— C:\WINDOWS\system32\dllcache\oledlg.dll 2007-11-03 03:28 . 2006-12-21 14:16 116,736 --------- C:\WINDOWS\system32\aaclient.dll 2007-11-03 03:28 . 2006-12-21 14:16 36,352 --------- C:\WINDOWS\system32\tsgqec.dll 2007-11-03 03:27 . 2006-12-14 14:45 981,760 -----c— C:\WINDOWS\system32\dllcache\mfc42u.dll 2007-11-03 03:27 . 2006-11-01 20:19 927,504 -----c— C:\WINDOWS\system32\dllcache\mfc40u.dll 2007-11-03 03:26 . 2006-11-27 15:55 539,136 -----c— C:\WINDOWS\system32\dllcache\msftedit.dll 2007-11-03 03:26 . 2006-12-26 14:09 536,576 -----c— C:\WINDOWS\system32\dllcache\msado15.dll 2007-11-03 03:26 . 2006-11-27 15:55 433,152 -----c— C:\WINDOWS\system32\dllcache\riched20.dll 2007-11-03 03:26 . 2006-12-26 14:09 200,704 -----c— C:\WINDOWS\system32\dllcache\msadox.dll 2007-11-03 03:26 . 2006-12-26 14:09 180,224 -----c— C:\WINDOWS\system32\dllcache\msadomd.dll 2007-11-03 03:26 . 2006-12-26 14:09 102,400 -----c— C:\WINDOWS\system32\dllcache\msjro.dll 2007-11-03 03:25 . 2006-12-19 22:51 8,482,304 -----c— C:\WINDOWS\system32\dllcache\shell32.dll 2007-11-03 03:25 . 2007-04-02 06:59 546,304 -----c— C:\WINDOWS\system32\dllcache\hhctrl.ocx 2007-11-03 03:25 . 2006-12-19 22:51 135,168 -----c— C:\WINDOWS\system32\dllcache\shsvcs.dll 2007-11-03 03:24 . 2006-12-19 19:18 334,336 -----c— C:\WINDOWS\system32\dllcache\wiaservc.dll 2007-11-03 03:23 . 2006-10-31 11:26 36,864 -----c— C:\WINDOWS\system32\dllcache\hidclass.sys 2007-11-03 03:22 . 2007-02-28 17:04 2,181,632 -----c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe 2007-11-03 03:22 . 2007-02-28 17:04 2,137,600 -----c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe 2007-11-03 03:22 . 2007-02-28 17:04 2,058,880 -----c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe 2007-11-03 03:22 . 2007-02-28 17:04 2,017,280 -----c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe 2007-11-03 03:21 . 2007-11-03 03:21 2007-11-03 03:20 . 2007-11-03 03:20 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-12-03 13:05 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-12-03 13:05 --------- d-----w C:\Program Files\ATI Technologies 2007-11-02 23:28 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-11-02 23:12 --------- d-----w C:\Program Files\Usługi online 2007-09-28 17:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2007-09-28 17:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2007-09-28 17:05 739,840 ----a-w C:\WINDOWS\system32\divx.dll 2007-09-20 08:59 972,072 ----a-w C:\WINDOWS\UNRecode.exe 2007-09-20 08:55 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe 2007-09-20 08:55 95,600 ----a-w C:\WINDOWS\system32\NeroCo.dll 2007-09-04 17:56 164,352 ----a-w C:\WINDOWS\system32\unrar.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:44] “SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe” [2007-08-31 16:46] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2002-10-12 21:00] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-04 00:44] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] 2007-09-20 15:35 202024 --a------ C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2006-10-27 00:47 31016 --a------ C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan] 2007-09-20 09:51 1836328 --a------ C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2007-03-01 15:57 153136 --a------ C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2007-09-25 01:11 132496 --a------ C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2007-10-10 06:28 36352 --a------ C:\Program Files\Winamp\winampa.exe S2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 09:51] S3 FA312;Sterownik karty NETGEAR FA330/FA312/FA311 Fast Ethernet;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 21:12] S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08] . ************************************************************************** catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-12-30 21:31:05 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-12-30 21:32:00