ComboFix 07-11-08.3 - CHUDY 2007-08-21 0:56:39.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.218 [GMT 2:00] Running from: D:\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Program Files\myglobalsearch C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.JAR C:\Program Files\myglobalsearch\bar\1.bin\M9FFXTBR.MANIFEST C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.JAR C:\Program Files\myglobalsearch\bar\1.bin\M9NTSTBR.MANIFEST C:\Program Files\myglobalsearch\bar\1.bin\M9PLUGIN.DLL C:\Program Files\myglobalsearch\bar\1.bin\NPMYGLSH.DLL C:\Program Files\myglobalsearch\bar\Cache\00430960 C:\Program Files\myglobalsearch\bar\Cache\00430BE1 C:\Program Files\myglobalsearch\bar\Cache\00430D58.bin C:\Program Files\myglobalsearch\bar\Cache\00430F3C.bin C:\Program Files\myglobalsearch\bar\Cache\004310C3.bin C:\Program Files\myglobalsearch\bar\Cache\files.ini C:\Program Files\myglobalsearch\bar\History\search C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm . ((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 ))))))))))))))))))))))))))))))) . 2007-11-21 00:13 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-11-20 01:26 2007-11-20 01:26 2007-11-18 14:46 2007-11-17 01:29 1,156 --a------ C:\WINDOWS\mozver.dat 2007-11-17 01:23 2007-11-16 23:40 0 --a------ C:\WINDOWS\nsreg.dat 2007-11-16 21:14 2007-11-16 18:26 2007-11-14 16:54 2007-11-14 10:33 2007-11-14 10:25 2007-11-14 07:16 2007-11-14 02:25 2007-11-14 01:19 2007-11-13 23:09 262,144 --a------ C:\WINDOWS\system32\wrap_oal.dll 2007-11-13 23:09 86,016 --a------ C:\WINDOWS\system32\OpenAL32.dll 2007-11-13 02:50 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys 2007-11-13 02:50 14,848 --a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys 2007-11-12 19:35 2007-11-12 17:08 1,415,680 --a------ C:\WINDOWS\system32\WMV9VCM.dll 2007-11-12 17:08 892,928 --a------ C:\WINDOWS\system32\iconv.dll 2007-11-12 17:08 245,760 --a------ C:\WINDOWS\system32\mplvpx.dll 2007-11-12 17:08 9,216 --a------ C:\WINDOWS\system32\cpuinf32.dll 2007-11-12 01:44 2007-11-12 01:41 2007-11-12 01:40 2007-11-12 01:39 2007-11-12 01:38 2007-11-12 01:37 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-11-12 01:34 2007-11-12 00:24 2007-11-12 00:23 2007-11-12 00:23 2007-11-12 00:11 2007-11-12 00:11 2007-11-12 00:11 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2007-11-12 00:11 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2007-11-12 00:11 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2007-11-12 00:11 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2007-11-12 00:11 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-11-12 00:11 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys 2007-11-12 00:11 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-11-12 00:11 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys 2007-11-12 00:06 2007-11-12 00:05 2007-11-12 00:02 2007-11-12 00:01 2007-11-11 23:59 2007-11-11 23:56 2007-11-11 23:56 737,280 --a------ C:\WINDOWS\iun6002.exe 2007-11-11 23:55 2007-11-11 23:54 2007-11-11 23:39 2007-11-11 23:38 2007-11-11 23:36 2007-11-11 23:35 2007-11-11 23:32 2007-11-11 23:31 2007-11-11 23:31 1,703,936 --a------ C:\WINDOWS\system32\gdiplus.dll 2007-11-11 23:31 110,592 --a------ C:\WINDOWS\system32\ccrpbds6.dll 2007-11-11 23:27 2007-11-11 23:03 2007-11-11 23:02 2007-11-11 23:01 2007-11-11 23:01 43,352 --a------ C:\WINDOWS\system32\wups2.dll 2007-10-20 01:56 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-10-20 01:56 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll 2007-10-20 01:56 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe 2007-10-20 01:56 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll 2007-10-20 01:54 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll 2007-10-20 01:54 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll 2007-10-20 01:54 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll 2007-10-20 01:54 739,840 --a------ C:\WINDOWS\system32\DivX.dll 2007-10-20 01:54 196,608 --a------ C:\WINDOWS\system32\dtu100.dll 2007-10-20 01:54 81,920 --a------ C:\WINDOWS\system32\dpl100.dll 2007-10-18 10:06 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2007-10-18 10:03 593,920 --a------ C:\WINDOWS\system32\dpuGUI11.dll 2007-10-18 10:03 344,064 --a------ C:\WINDOWS\system32\dpus11.dll 2007-10-18 10:03 294,912 --a------ C:\WINDOWS\system32\dpu11.dll 2007-10-18 10:03 294,912 --a------ C:\WINDOWS\system32\dpu10.dll 2007-10-18 10:03 57,344 --a------ C:\WINDOWS\system32\dpv11.dll 2007-10-18 10:03 53,248 --a------ C:\WINDOWS\system32\dpuGUI10.dll 2007-10-18 10:02 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-12 16:08 1,559,040 ----a-w C:\WINDOWS\system32\xvidcore.dll 2007-11-11 22:32 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-11-11 22:20 --------- d–h--w C:\Program Files\Java 2007-11-11 21:34 --------- d-----w C:\Program Files\ZTE ZXDSL 852 2007-11-11 21:32 --------- d-----w C:\Program Files\Winamp 2007-11-11 21:32 --------- d-----w C:\Documents and Settings\CHUDY\Dane aplikacji\Winamp 2007-11-11 21:23 --------- d–h--w C:\Program Files\Intel 2007-11-11 21:21 --------- d–h--w C:\Program Files\Sierra Wireless 2007-11-11 21:21 --------- d-----w C:\Program Files\Common Files\Java 2007-11-11 21:20 --------- d–h--w C:\Program Files\Broadcom 2007-11-11 21:18 --------- d–h--w C:\Program Files\Synaptics 2007-11-11 21:18 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-11-11 21:10 --------- d–h--w C:\Program Files\Analog Devices 2007-11-11 21:08 --------- d–h--w C:\Program Files\HPQ 2007-11-11 20:54 --------- d–h--w C:\Program Files\Alwil Software 2007-11-11 20:46 --------- d–h--w C:\Program Files\microsoft frontpage 2007-11-11 20:45 --------- d–h--w C:\Program Files\Usługi online 2007-11-07 23:58 --------- d-----w C:\Program Files\neostrada tp 2007-09-06 11:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-09-06 11:00 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 12:06] “SoundMAXPnP”=“C:\Program Files\Analog Devices\Core\smax4pnp.exe” [2005-05-20 09:11] “SoundMAX”=“C:\Program Files\Analog Devices\SoundMAX\Smax4.exe” [2005-05-06 14:06] “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2006-03-03 17:46] “igfxtray”=“C:\WINDOWS\system32\igfxtray.exe” [2006-03-23 13:17] “igfxhkcmd”=“C:\WINDOWS\system32\hkcmd.exe” [2006-03-23 13:13] “igfxpers”=“C:\WINDOWS\system32\igfxpers.exe” [2006-03-23 13:17] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11] “AdslTaskBar”=“stmctrl.dll” [2006-06-02 10:01 C:\WINDOWS\system32\stmctrl.dll] “WOOWATCH”=“C:\PROGRA~1\NEOSTR~1\Watch.exe” [2004-08-23 14:49] “NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 10:50] “TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2007-11-12 00:23] “BluetoothAuthenticationAgent”=“bthprops.cpl” [2006-03-02 13:00 C:\WINDOWS\system32\bthprops.cpl] “Windows Defender”=“C:\Program Files\Windows Defender\MSASCui.exe” [2006-11-03 19:20] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 13:00] “RocketDock”=“C:\Program Files\RocketDock\RocketDock.exe” [2007-09-02 13:58] R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys . Contents of the ‘Scheduled Tasks’ folder “2007-11-12 01:07:14 C:\WINDOWS\Tasks\Critical Battery Alarm Program.job” “2007-11-20 23:10:11 C:\WINDOWS\Tasks\MP Scheduled Scan.job” - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-08 00:58:51 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-08 0:59:26 - machine was rebooted . — E O F —