ComboFix 07-10-16.1 - mimi 2007-10-18 0:14:37.5 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1048 [GMT 2:00] Running from: C:\Documents and Settings\mimi\Pulpit\diagnostykas kompa\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-09-17 to 2007-10-17 ))))))))))))))))))))))))))))))) . 2007-10-18 00:08 2007-10-18 00:08 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-10-18 00:08 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-10-18 00:08 739,840 --a------ C:\WINDOWS\system32\divx.dll 2007-10-18 00:08 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-10-18 00:08 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll 2007-10-18 00:08 164,352 --a------ C:\WINDOWS\system32\unrar.dll 2007-10-18 00:08 81,920 --a------ C:\WINDOWS\system32\dpl100.dll 2007-10-18 00:08 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2007-10-17 23:26 2007-10-17 10:48 2007-10-16 09:10 2007-10-10 10:28 584,192 -----c— C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-10-04 22:00 2007-10-01 22:45 2007-09-28 22:14 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-09-27 22:48 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys 2007-09-27 22:48 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll 2007-09-27 22:48 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys 2007-09-27 22:48 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys 2007-09-27 22:48 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys 2007-09-27 00:26 2007-09-20 16:00 13,291,552 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2007-09-20 15:57 2007-09-19 09:44 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-17 22:08 --------- d-----w C:\Documents and Settings\mimi\Dane aplikacji\Skype 2007-10-17 22:04 160,460 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2007-09-27 20:51 --------- d-----w C:\Program Files\Nokia 2007-09-27 20:51 --------- d-----w C:\Program Files\Common Files\Nokia 2007-09-19 07:41 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\PC Suite 2007-09-13 01:51 --------- d-----w C:\Program Files\eMule 2007-09-06 14:14 75,248 ----a-w C:\WINDOWS\zllsputility.exe 2007-09-06 14:14 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll 2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr 2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-03-07 20:36 30,240 ----a-w C:\Documents and Settings\mimi\Dane aplikacji\GDIPFONTCACHEV1.DAT 2004-03-11 12:27 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe 2007-04-30 10:24:45 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-09-06 12:06] “PCSuiteTrayApplication”=“C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe” [2007-03-23 13:20] “ZoneAlarm Client”=“C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe” [2007-09-06 16:14] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg.exe” [2006-02-17 15:03] “Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-05-28 14:52] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 01:44] “H/PC Connection Agent”=“C:\Program Files\Microsoft ActiveSync\wcescomm.exe” [2006-06-27 02:54] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Nokia.PCSync”=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog R0 viamraid;viamraid;C:\WINDOWS\system32\DRIVERS\viamraid.sys R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys S3 GT680x;BearPaw 2448TA Plus Usb Scanner;C:\WINDOWS\system32\Drivers\Gt680x.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{7c24a54b-15e0-11dc-98ec-000e509168cd}] AutoRun\command - H:\InstallTomTomHOME.exe . Contents of the ‘Scheduled Tasks’ folder “2007-10-17 18:26:02 C:\WINDOWS\Tasks\HP Usg Daily.job” . ************************************************************************** catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-18 00:17:12 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-18 0:18:06 C:\ComboFix-quarantined-files.txt … 2007-09-29 10:52 C:\ComboFix2.txt … 2007-10-16 21:00 C:\ComboFix3.txt … 2007-09-29 10:52 . — E O F —