“Administrator” - 07-03-23 19:58:11 Dodatek Service Pack 2 ComboFix 07-03-22.2 - Running from: “C:\Documents and Settings\Administrator\Pulpit” ((((((((((((((((((((((((((((((( Files Created from 2007-02-23 to 2007-03-23 )))))))))))))))))))))))))))))))))) 2007-03-23 19:58 2007-03-22 12:50 2007-03-20 20:41 2007-03-19 11:00 610,304 --a------ C:\WINDOWS\system32\eraser.dll 2007-03-19 11:00 282,624 --a------ C:\WINDOWS\system32\erasext.dll 2007-03-19 11:00 233,472 --a------ C:\WINDOWS\system32\eraserl.exe 2007-03-19 11:00 2007-03-19 10:36 2007-03-19 09:24 2007-03-19 09:24 2007-03-19 09:23 2007-03-18 20:57 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll 2007-03-18 20:57 2007-03-18 20:31 2007-03-18 20:27 2007-03-18 20:11 271,360 --a------ C:\WINDOWS\system32\drivers\atksgt.sys 2007-03-18 20:11 18,048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys 2007-03-18 20:10 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-03-18 20:10 2007-03-18 20:06 2007-03-18 20:06 2007-03-18 19:42 2007-03-18 19:41 2007-03-18 19:41 2007-03-18 19:41 2007-03-18 19:39 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-03-18 19:38 2007-03-18 19:35 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll 2007-03-18 19:35 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll 2007-03-18 19:35 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-03-18 19:35 2007-03-18 19:31 2007-03-17 15:42 2007-03-17 15:41 2007-03-17 15:41 2007-03-17 15:37 30,976 -ra------ C:\WINDOWS\system32\drivers\cx88tune.sys 2007-03-17 15:36 9,728 -ra------ C:\WINDOWS\system32\drivers\cxavxbar.sys 2007-03-17 15:30 796,672 --a------ C:\WINDOWS\GPInstall.exe 2007-03-17 15:30 2007-03-17 15:25 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys 2007-03-17 15:25 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll 2007-03-17 15:25 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys 2007-03-17 15:25 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS 2007-03-17 15:25 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys 2007-03-17 15:25 163,584 -ra------ C:\WINDOWS\system32\drivers\cx88vid.sys 2007-03-17 15:25 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys 2007-03-17 15:25 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys 2007-03-17 15:25 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys 2007-03-16 19:39 2007-03-16 13:28 2007-03-16 11:56 2007-03-15 20:56 2007-03-15 20:56 2007-03-15 20:55 2007-03-15 20:50 2007-03-15 18:33 2007-03-15 18:32 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-03-15 18:30 2007-03-15 18:30 2007-03-15 18:30 2007-03-15 18:29 82,380 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS 2007-03-15 18:29 2007-03-15 13:44 2007-03-14 12:32 2007-03-13 16:55 2007-03-13 16:55 2007-03-13 12:59 2007-03-13 12:59 2007-03-13 12:57 21,504 --a------ C:\WINDOWS\system32\hidserv.dll 2007-03-13 12:57 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys 2007-03-12 17:05 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-03-12 17:05 2007-03-12 17:05 2007-03-12 16:42 9,728 -ra------ C:\WINDOWS\system32\sysinfoX64.sys 2007-03-12 16:42 8,192 -ra------ C:\WINDOWS\system32\sysinfo.sys 2007-03-12 16:42 69,632 -ra------ C:\WINDOWS\system32\sw24.exe 2007-03-12 16:42 53,248 -ra------ C:\WINDOWS\system32\Nvgpio.dll 2007-03-12 16:42 200,704 -ra------ C:\WINDOWS\system32\sw20.exe 2007-03-12 16:42 114,688 -ra------ C:\WINDOWS\system32\sysinfo.dll 2007-03-12 16:42 1,409,024 -ra------ C:\WINDOWS\system32\msicpl.dll 2007-03-12 14:18 2007-03-12 14:14 2007-03-12 13:26 2007-03-12 12:55 2007-03-12 12:54 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-03-12 12:54 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2007-03-12 12:53 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2007-03-12 12:53 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-03-12 12:53 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys 2007-03-12 12:53 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-03-12 12:52 2007-03-12 12:52 2007-03-12 12:51 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-03-12 12:51 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-03-12 12:51 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-03-12 12:51 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-03-12 12:51 8,704 --a------ C:\WINDOWS\system32\batt.dll 2007-03-12 12:51 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-03-12 12:51 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-03-12 12:51 70,144 --a------ C:\WINDOWS\NOTEPAD.EXE 2007-03-12 12:51 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-03-12 12:51 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-03-12 12:51 69,552 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-03-12 12:51 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-03-12 12:51 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-03-12 12:51 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-03-12 12:51 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-03-12 12:51 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-03-12 12:51 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-03-12 12:51 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-03-12 12:51 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-03-12 12:51 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-03-12 12:51 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-03-12 12:51 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-03-12 12:51 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-03-12 12:51 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-03-12 12:51 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-03-12 12:51 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-03-12 12:51 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-03-12 12:51 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-03-12 12:51 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-03-12 12:51 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-03-12 12:51 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-03-12 12:51 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-03-12 12:51 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-03-12 12:51 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll 2007-03-12 12:51 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-03-12 12:51 5,632 --a------ C:\WINDOWS\system32\kbdro.dll 2007-03-12 12:51 5,632 --a------ C:\WINDOWS\system32\kbdhu1.dll 2007-03-12 12:51 5,120 --a------ C:\WINDOWS\system\SHELL.DLL 2007-03-12 12:51 33,376 --a------ C:\WINDOWS\system\COMMDLG.DLL 2007-03-12 12:51 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll 2007-03-12 12:51 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL 2007-03-12 12:51 19,200 --a------ C:\WINDOWS\system\TAPI.DLL 2007-03-12 12:51 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll 2007-03-12 12:51 15,360 --a------ C:\WINDOWS\TASKMAN.EXE 2007-03-12 12:51 13,312 --a------ C:\WINDOWS\system32\irclass.dll 2007-03-12 12:51 127,008 --a------ C:\WINDOWS\system\MSVIDEO.DLL 2007-03-12 12:51 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys 2007-03-12 12:51 109,488 --a------ C:\WINDOWS\system\AVIFILE.DLL 2007-03-12 12:51 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:51 2007-03-12 12:50 2007-03-12 12:50 2007-03-12 12:48 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:44 2007-03-12 12:42 1,423 --a------ C:\WINDOWS\mozver.dat 2007-03-12 12:29 0 --a------ C:\WINDOWS\nsreg.dat 2007-03-12 12:29 2007-03-12 12:28 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll 2007-03-12 12:28 8,192 --a------ C:\WINDOWS\system32\kbdkor.dll 2007-03-12 12:28 6,144 --a------ C:\WINDOWS\system32\kbd106.dll 2007-03-12 12:28 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll 2007-03-12 12:28 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll 2007-03-12 12:28 5,632 --a------ C:\WINDOWS\system32\kbd103.dll 2007-03-12 12:23 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys 2007-03-12 12:23 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys 2007-03-12 12:23 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys 2007-03-12 12:23 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-03-12 12:23 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys 2007-03-12 12:23 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys 2007-03-12 12:23 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys 2007-03-12 12:23 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys 2007-03-12 12:23 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2007-03-12 12:23 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys 2007-03-12 12:23 4,096 --a------ C:\WINDOWS\system32\ksuser.dll 2007-03-12 12:23 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-03-12 12:23 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys 2007-03-12 12:23 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys 2007-03-12 12:23 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-03-12 12:23 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys 2007-03-12 12:19 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-03-12 12:19 2007-03-12 12:19 2007-03-12 12:19 2007-03-12 12:19 2007-03-12 12:19 2007-03-12 12:18 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2007-03-12 12:18 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2007-03-12 12:18 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2007-03-12 12:18 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-03-12 12:18 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-03-12 12:18 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2007-03-12 12:18 2007-03-12 12:17 40,960 --a------ C:\Program Files\Uninstall_CDS.exe 2007-03-12 12:17 2007-03-12 12:17 2007-03-12 12:15 102,912 --------- C:\WINDOWS\system32\Vb6stkit.dll 2007-03-12 12:15 102,160 --------- C:\WINDOWS\system32\VB6KO.DLL 2007-03-12 12:15 2007-03-12 12:13 92,800 -ra------ C:\WINDOWS\system32\drivers\nvata.sys 2007-03-12 12:13 300,032 -ra------ C:\WINDOWS\system32\idecoi.dll 2007-03-12 12:12 36,352 -ra------ C:\WINDOWS\system32\drivers\AmdK8.sys 2007-03-12 12:12 2007-03-12 12:10 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2007-03-12 12:10 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe 2007-03-12 12:10 2007-03-12 12:09 2007-03-12 12:06 229,376 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT 2007-03-12 12:06 2,883,584 --ah----- C:\DOCUME~1\Meason\NTUSER.DAT 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:06 2007-03-12 12:05 229,376 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT 2007-03-12 12:05 2007-03-12 12:05 2007-03-12 12:03 229,376 —h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT 2007-03-12 12:03 112,128 --a------ C:\WINDOWS\system32\mapi32.dll 2007-03-12 12:03 0 -rahs---- C:\MSDOS.SYS 2007-03-12 12:03 0 -rahs---- C:\IO.SYS 2007-03-12 12:03 0 --a------ C:\CONFIG.SYS 2007-03-12 12:03 0 --a------ C:\AUTOEXEC.BAT 2007-03-12 12:03 2007-03-12 12:03 2007-03-12 12:02 2007-03-12 12:02 2007-03-12 12:02 2007-03-12 12:02 2007-03-12 12:02 2007-03-12 12:02 2007-03-12 12:01 86,016 --a------ C:\WINDOWS\system32\isign32.dll 2007-03-12 12:01 81,920 --a------ C:\WINDOWS\system32\ils.dll 2007-03-12 12:01 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll 2007-03-12 12:01 73,728 --a------ C:\WINDOWS\system32\icwdial.dll 2007-03-12 12:01 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys 2007-03-12 12:01 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll 2007-03-12 12:01 69,632 --a------ C:\WINDOWS\system32\msconf.dll 2007-03-12 12:01 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll 2007-03-12 12:01 67,584 --a------ C:\WINDOWS\system32\srclient.dll 2007-03-12 12:01 67,584 --a------ C:\WINDOWS\system32\acctres.dll 2007-03-12 12:01 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll 2007-03-12 12:01 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll 2007-03-12 12:01 49,664 --a------ C:\WINDOWS\system32\inetres.dll 2007-03-12 12:01 466,200 --a------ C:\WINDOWS\system32\wuapi.dll 2007-03-12 12:01 45,568 --a------ C:\WINDOWS\system32\safrslv.dll 2007-03-12 12:01 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll 2007-03-12 12:01 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll 2007-03-12 12:01 41,240 --a------ C:\WINDOWS\system32\wups.dll 2007-03-12 12:01 382,464 --a------ C:\WINDOWS\system32\qmgr.dll 2007-03-12 12:01 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll 2007-03-12 12:01 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe 2007-03-12 12:01 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll 2007-03-12 12:01 29,696 --a------ C:\WINDOWS\system32\safrdm.dll 2007-03-12 12:01 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll 2007-03-12 12:01 278,528 --a------ C:\WINDOWS\system32\mstask.dll 2007-03-12 12:01 278,528 --a------ C:\WINDOWS\system32\inetcfg.dll 2007-03-12 12:01 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll 2007-03-12 12:01 240,128 --a------ C:\WINDOWS\system32\srrstr.dll 2007-03-12 12:01 23,040 --a------ C:\WINDOWS\system32\fltmc.exe 2007-03-12 12:01 195,352 --a------ C:\WINDOWS\system32\wuaueng1.dll 2007-03-12 12:01 192,000 --a------ C:\WINDOWS\system32\schedsvc.dll 2007-03-12 12:01 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll 2007-03-12 12:01 175,384 --a------ C:\WINDOWS\system32\wuauclt1.exe 2007-03-12 12:01 173,536 --a------ C:\WINDOWS\system32\wuweb.dll 2007-03-12 12:01 171,008 --a------ C:\WINDOWS\system32\srsvc.dll 2007-03-12 12:01 16,896 --a------ C:\WINDOWS\system32\fltlib.dll 2007-03-12 12:01 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll 2007-03-12 12:01 128,896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys 2007-03-12 12:01 128,280 --a------ C:\WINDOWS\system32\wucltui.dll 2007-03-12 12:01 125,208 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-03-12 12:01 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll 2007-03-12 12:01 12,288 --a------ C:\WINDOWS\system32\mstinit.exe 2007-03-12 12:01 11,264 --a------ C:\WINDOWS\system32\atrace.dll 2007-03-12 12:01 105,984 --a------ C:\WINDOWS\system32\msoert2.dll 2007-03-12 12:01 1,343,768 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-03-12 12:01 2007-03-12 12:01 2007-03-12 12:01 2007-03-12 12:01 2007-03-12 12:01 2007-03-12 12:01 2007-03-12 12:00 5,632 --a------ C:\WINDOWS\system32\write.exe 2007-03-12 12:00 21,856 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-03-12 12:00 2007-03-12 12:00 2007-03-12 12:00 2007-03-12 11:59 97,792 --a------ C:\WINDOWS\system32\comrepl.dll 2007-03-12 11:59 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll 2007-03-12 11:59 94,720 --a------ C:\WINDOWS\system32\tscfgwmi.dll 2007-03-12 11:59 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll 2007-03-12 11:59 9,728 --a------ C:\WINDOWS\system32\reset.exe 2007-03-12 11:59 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll 2007-03-12 11:59 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll 2007-03-12 11:59 80,896 --a------ C:\WINDOWS\system32\charmap.exe 2007-03-12 11:59 73,216 --a------ C:\WINDOWS\system32\avwav.dll 2007-03-12 11:59 67,072 --a------ C:\WINDOWS\system32\rdshost.exe 2007-03-12 11:59 655,360 --a------ C:\WINDOWS\system32\mstscax.dll 2007-03-12 11:59 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll 2007-03-12 11:59 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe 2007-03-12 11:59 605,696 --a------ C:\WINDOWS\system32\getuname.dll 2007-03-12 11:59 60,928 --a------ C:\WINDOWS\system32\remotepg.dll 2007-03-12 11:59 60,416 --a------ C:\WINDOWS\system32\colbact.dll 2007-03-12 11:59 6,144 --a------ C:\WINDOWS\system32\msdtc.exe 2007-03-12 11:59 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll 2007-03-12 11:59 58,880 --a------ C:\WINDOWS\system32\licwmi.dll 2007-03-12 11:59 57,344 --a------ C:\WINDOWS\system32\sol.exe 2007-03-12 11:59 56,320 --a------ C:\WINDOWS\system32\servdeps.dll 2007-03-12 11:59 55,808 --a------ C:\WINDOWS\system32\freecell.exe 2007-03-12 11:59 540,160 --a------ C:\WINDOWS\system32\comuid.dll 2007-03-12 11:59 54,272 --a------ C:\WINDOWS\system32\stclient.dll 2007-03-12 11:59 539,136 --a------ C:\WINDOWS\system32\spider.exe 2007-03-12 11:59 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe 2007-03-12 11:59 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll 2007-03-12 11:59 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe 2007-03-12 11:59 44,544 --a------ C:\WINDOWS\system32\hticons.dll 2007-03-12 11:59 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll 2007-03-12 11:59 408,576 --a------ C:\WINDOWS\system32\mstsc.exe 2007-03-12 11:59 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys 2007-03-12 11:59 4,608 --a------ C:\WINDOWS\system32\rdpcfgex.dll 2007-03-12 11:59 4,096 --a------ C:\WINDOWS\system32\mtxex.dll 2007-03-12 11:59 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll 2007-03-12 11:59 351,744 --a------ C:\WINDOWS\system32\hypertrm.dll 2007-03-12 11:59 35,328 --a------ C:\WINDOWS\system32\winchat.exe 2007-03-12 11:59 345,088 --a------ C:\WINDOWS\system32\mspaint.exe 2007-03-12 11:59 33,792 --a------ C:\WINDOWS\system32\regini.exe 2007-03-12 11:59 296,448 --a------ C:\WINDOWS\system32\termsrv.dll 2007-03-12 11:59 25,600 --a------ C:\WINDOWS\system32\comaddin.dll 2007-03-12 11:59 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll 2007-03-12 11:59 231,424 --a------ C:\WINDOWS\system32\avtapi.dll 2007-03-12 11:59 225,792 --a------ C:\WINDOWS\system32\catsrv.dll 2007-03-12 11:59 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe 2007-03-12 11:59 22,528 --a------ C:\WINDOWS\system32\msg.exe 2007-03-12 11:59 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys 2007-03-12 11:59 20,992 --a------ C:\WINDOWS\system32\qprocess.exe 2007-03-12 11:59 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll 2007-03-12 11:59 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys 2007-03-12 11:59 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll 2007-03-12 11:59 187,904 --a------ C:\WINDOWS\system32\cmprops.dll 2007-03-12 11:59 187,904 --a------ C:\WINDOWS\system32\accwiz.exe 2007-03-12 11:59 17,920 --a------ C:\WINDOWS\system32\tsshutdn.exe 2007-03-12 11:59 17,920 --a------ C:\WINDOWS\system32\mmfutil.dll 2007-03-12 11:59 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe 2007-03-12 11:59 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll 2007-03-12 11:59 16,384 --a------ C:\WINDOWS\system32\tskill.exe 2007-03-12 11:59 16,384 --a------ C:\WINDOWS\system32\rwinsta.exe 2007-03-12 11:59 16,384 --a------ C:\WINDOWS\system32\avmeter.dll 2007-03-12 11:59 15,872 --a------ C:\WINDOWS\system32\logoff.exe 2007-03-12 11:59 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll 2007-03-12 11:59 15,360 --a------ C:\WINDOWS\system32\tsdiscon.exe 2007-03-12 11:59 15,360 --a------ C:\WINDOWS\system32\tscon.exe 2007-03-12 11:59 15,360 --a------ C:\WINDOWS\system32\shadow.exe 2007-03-12 11:59 147,968 --a------ C:\WINDOWS\system32\rdchost.dll 2007-03-12 11:59 147,456 --a------ C:\WINDOWS\system32\comsnap.dll 2007-03-12 11:59 141,824 --a------ C:\WINDOWS\system32\sessmgr.exe 2007-03-12 11:59 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys 2007-03-12 11:59 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe 2007-03-12 11:59 132,608 --a------ C:\WINDOWS\system32\sndrec32.exe 2007-03-12 11:59 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe 2007-03-12 11:59 128,000 --a------ C:\WINDOWS\system32\mshearts.exe 2007-03-12 11:59 124,928 --a------ C:\WINDOWS\system32\mplay32.exe 2007-03-12 11:59 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys 2007-03-12 11:59 119,808 --a------ C:\WINDOWS\system32\winmine.exe 2007-03-12 11:59 115,200 --a------ C:\WINDOWS\system32\calc.exe 2007-03-12 11:59 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll 2007-03-12 11:59 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll 2007-03-12 11:59 11,264 --a------ C:\WINDOWS\system32\icaapi.dll 2007-03-12 11:59 103,424 --a------ C:\WINDOWS\system32\clipbrd.exe 2007-03-12 11:59 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll 2007-03-12 11:59 1,225 --a------ C:\WINDOWS\system32\usrlogon.cmd 2007-03-12 11:59 2007-03-12 11:59 2007-03-12 11:59 2007-03-12 10:54 351,776 --a------ C:\WINDOWS\system32\drivers\ar5211.sys 2007-03-12 10:50 59,392 --a------ C:\WINDOWS\system32\a3d.dll 2007-03-12 10:50 47,897 --a------ C:\WINDOWS\system32\AudCtrl.dll 2007-03-12 10:50 1,152,916 --a------ C:\WINDOWS\system32\drivers\sbext.sys (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-03-22 19:31 -------- d-------- C:\Program Files\msi 2007-03-22 15:57 49696 --a------ C:\WINDOWS\system32\perfc015.dat 2007-03-22 15:57 355816 --a------ C:\WINDOWS\system32\perfh015.dat 2007-03-12 12:51 62 --ahs---- C:\DOCUME~1\ADMINI~1\DANEAP~1\desktop.ini 2007-03-12 12:02 -------- d-------- C:\Program Files\usˆugi online 2007-01-22 12:00 719088 --a------ C:\WINDOWS\system32\skaneronline.dll 2007-01-19 09:40 89088 --a------ C:\WINDOWS\system32\skaneronlineuninstall.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “AudCtrl”=“RunDll32 AudCtrl.dll,RCMonitor” “NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup” “nwiz”=“nwiz.exe /install” “SW20”=“C:\WINDOWS\system32\sw20.exe” “SW24”=“C:\WINDOWS\system32\sw24.exe” “NvMediaCenter”=“RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit” “WireLessKeyboard”=“C:\Program Files\Multimedia Keyboard Driver\StartAutorun.exe PS2USBKbdDrv.exe” “SunJavaUpdateSched”="“C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe”" “LiveMonitor”=“C:\Program Files\MSI\Live Update 3\LMonitor.exe” “SoundMan”=“SOUNDMAN.EXE” “APVXDWIN”="“C:\Program Files\Panda Software\Panda Antivirus 2007\APVXDWIN.EXE” /s" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“eraser” “hkey”=“HKCU” “command”=“C:\Program Files\Eraser\eraser.exe -hide” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“fwupdate” “hkey”=“HKLM” “command”="“C:\Program Files\lg_fwupdate\fwupdate.exe”" “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“NeroCheck” “hkey”=“HKLM” “command”=“C:\WINDOWS\system32\NeroCheck.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon] “key”=“SOFTWARE\Microsoft\Windows\CurrentVersion\Run” “item”=“hpgs2wnd” “hkey”=“HKLM” “command”=“C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe” “inimapping”=“0” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] “{C3AE80DC-CE36-41E6-A011-E498F909614B}”="" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] “WPDShServiceObj”="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] “SecurityProviders”=“msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll” [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 ******************************************************************** catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-03-23 19:58:54 C:\ComboFix2.txt … 04-01-01 03:53