ComboFix 07-06-13.3 - E:\Instalki\ComboFix.exe “Ryszard Zieliäski” - 2004-06-17 0:06:33 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2004-05-16 to 2004-06-16 ))))))))))))))))))))))))))))))) 2004-06-22 13:45 2004-06-22 13:33 2004-06-20 10:01 2004-06-20 09:06 234 --a------ C:\WINDOWS\system32\WMV9VCM.dll 2004-06-20 09:06 234 --a------ C:\WINDOWS\system32\vorbisenc.dll 2004-06-20 09:06 234 --a------ C:\WINDOWS\system32\vorbis.dll 2004-06-20 09:06 234 --a------ C:\WINDOWS\system32\OggDS.dll 2004-06-20 09:06 234 --a------ C:\WINDOWS\system32\ogg.dll 2004-06-20 09:05 234 --a------ C:\WINDOWS\system32\mplvpx.dll 2004-06-20 09:05 234 --a------ C:\WINDOWS\system32\DivX.dll 2004-06-20 09:05 234 --a------ C:\WINDOWS\system32\cpuinf32.dll 2004-06-19 23:13 2004-06-19 23:13 2004-06-19 23:01 2004-06-19 06:40 2004-06-19 06:40 2004-06-19 04:24 208,384 --a------ C:\WINDOWS\ADS.exe 2004-06-19 04:22 2004-06-18 23:58 2004-06-18 05:17 2004-06-18 04:34 2004-06-18 04:33 545 --a------ C:\WINDOWS\UC.PIF 2004-06-18 04:33 545 --a------ C:\WINDOWS\RAR.PIF 2004-06-18 04:33 545 --a------ C:\WINDOWS\PKZIP.PIF 2004-06-18 04:33 545 --a------ C:\WINDOWS\PKUNZIP.PIF 2004-06-18 04:33 545 --a------ C:\WINDOWS\NOCLOSE.PIF 2004-06-18 04:33 545 --a------ C:\WINDOWS\LHA.PIF 2004-06-18 04:33 545 --a------ C:\WINDOWS\ARJ.PIF 2004-06-18 04:33 2004-06-17 19:15 2004-06-17 18:42 2004-06-17 18:41 1,073,664 --a------ C:\Program Files\drtweakxp1.75.exe 2004-06-17 18:24 48,640 -ra------ C:\WINDOWS\system32\drivers\ser2pl.sys 2004-06-17 17:12 2004-06-17 17:12 2004-06-17 17:12 2004-06-17 15:44 2004-06-17 15:43 0 -rahs---- C:\MSDOS.SYS 2004-06-17 15:43 0 -rahs---- C:\IO.SYS 2004-06-17 15:43 0 --a------ C:\WINDOWS\nsreg.dat 2004-06-17 15:43 0 --a------ C:\CONFIG.SYS 2004-06-17 15:43 0 --a------ C:\AUTOEXEC.BAT 2004-06-17 15:41 55,904 --a------ C:\WINDOWS\system32\drivers\pctfw.sys 2004-06-17 15:41 100,448 --a------ C:\WINDOWS\system32\drivers\pctfw1.sys 2004-06-17 15:41 2004-06-17 15:25 2004-06-17 15:03 2004-06-17 14:39 2004-06-17 10:57 2004-06-17 10:41 831,048 --a------ C:\WINDOWS\system32\WudfUpdate_01005.dll 2004-06-17 10:41 2004-06-17 10:28 2004-06-17 10:28 2004-06-17 10:27 2004-06-17 10:27 2004-06-17 10:26 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll 2004-06-17 10:26 2004-06-17 10:25 2004-06-17 09:42 89,728 --a------ C:\WINDOWS\system32\drivers\usbvsp.sys 2004-06-17 09:40 2004-06-17 09:40 2004-06-17 06:52 2004-06-17 03:36 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll 2004-06-17 03:36 8,192 --a------ C:\WINDOWS\system32\kbdkor.dll 2004-06-17 03:36 6,144 --a------ C:\WINDOWS\system32\kbd106.dll 2004-06-17 03:36 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll 2004-06-17 03:36 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll 2004-06-17 03:36 5,632 --a------ C:\WINDOWS\system32\kbd103.dll 2004-06-17 01:02 73,216 --a------ C:\WINDOWS\ST6UNST.EXE 2004-06-17 01:02 249,856 --------- C:\WINDOWS\Setup1.exe 2004-06-17 00:42 2004-06-17 00:34 2004-06-17 00:33 (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-27 22:07:21 783,224 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-07-27 22:02:49 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-07-27 22:02:34 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-07-27 22:00:39 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-07-27 21:59:57 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-07-27 21:58:36 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-07-27 21:57:49 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr 2007-07-02 17:35:02 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\OpenOffice.ux.pl2 2007-06-26 18:20:10 -------- d-----w C:\Program Files\WinASO 2007-06-26 18:11:14 23 --sha-w C:\WINDOWS\system32\cdbcdcdd4_r.dll 2007-06-26 17:27:10 -------- d-----w C:\Program Files\XP Codec Pack 2007-06-26 14:42:34 -------- d-----w C:\Program Files\Futuremark 2007-06-22 13:16:02 -------- d-----w C:\Program Files\RegSeeker 2007-06-22 13:02:20 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Uniblue 2007-06-22 12:39:17 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS 2007-06-20 11:28:58 -------- d-----w C:\Program Files\Messenger 2007-06-19 16:52:14 -------- d-----w C:\Program Files\Google 2007-06-14 20:16:27 8,773 ----a-w C:\dnsbak.reg 2007-06-14 15:39:46 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Draco Organizer 2007-06-07 19:10:48 20,480 ----a-w C:\WINDOWS\system32\ac3config.exe 2007-06-03 16:51:47 -------- d-----w C:\Program Files\Ahead 2007-06-03 16:50:43 -------- d-----w C:\Program Files\LanHelper 2007-06-01 21:24:13 -------- d-----w C:\Program Files\Nsauditor 2007-06-01 21:14:25 -------- d-----w C:\Program Files\Windows Communicator 2007-06-01 19:31:56 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Windows Communicator 2007-05-29 15:31:19 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Gadu-Gadu 2007-05-29 15:07:12 -------- d-----w C:\Program Files\Gadu-Gadu 2007-05-16 15:18:58 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-05-06 20:16:58 -------- d-----w C:\Program Files\OpenOffice.ux.pl 2.2.0 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-24 13:14:12 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\MusicIP 2007-04-24 13:13:56 -------- d-----w C:\Program Files\Winamp 2007-04-18 16:14:32 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-04-16 19:48:29 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Google 2007-04-13 01:21:14 271,360 ----a-w C:\WINDOWS\system32\mscoree.dll 2007-04-05 07:53:37 -------- d-----w C:\Program Files\microsoft frontpage 2007-03-29 21:00:40 203,264 ----a-r C:\WINDOWS\system32\CddbCdda.dll 2007-03-27 20:49:25 -------- d-----w C:\Program Files\Windows Media Connect 2 2007-03-18 20:06:01 -------- d-----w C:\Program Files\HT NETWORKS 2007-03-17 13:45:36 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll 2007-03-17 11:22:02 -------- d-----w C:\Program Files\Dictionary 2000 4.0 2007-03-10 20:36:57 41 ----a-w C:\WINDOWS\system32\ddfacaebf9_s.dll 2007-03-10 17:37:15 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Skype 2007-03-08 15:38:47 579,072 ----a-w C:\WINDOWS\system32\user32.dll 2007-03-08 15:38:47 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll 2007-03-08 15:38:47 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll 2007-03-08 15:37:33 1,843,840 ----a-w C:\WINDOWS\system32\win32k.sys 2007-03-07 23:51:00 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys 2007-03-07 23:51:00 129,784 ------w C:\WINDOWS\system32\pxafs.dll 2007-03-04 17:18:46 -------- d-----w C:\Program Files\IPSPI 2007-03-04 12:58:36 719 ----a-w C:\WINDOWS\unins000.dat 2007-03-04 07:51:41 -------- d-----w C:\Program Files\Look@LAN 2007-03-03 11:12:10 720,896 ----a-w C:\WINDOWS\iun6002.exe 2007-03-02 08:31:32 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Opera 2007-03-01 18:33:31 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Lavasoft 2007-03-01 18:33:16 -------- d-----w C:\Program Files\Lavasoft 2007-03-01 18:32:44 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2007-03-01 08:49:06 -------- d-----w C:\Program Files\Common Files\Panda Software 2007-03-01 08:47:02 -------- d-----w C:\Program Files\Alwil Software 2007-02-28 12:32:47 -------- d-----w C:\Program Files\SiGSOFT 2007-02-27 22:45:37 69,632 ----a-w C:\WINDOWS\uinst001.exe 2007-02-26 18:09:38 1,168 ----a-w C:\WINDOWS\mozver.dat 2007-02-26 15:20:26 -------- d-----w C:\Program Files\Common Files\Onet.pl 2007-02-22 17:06:23 -------- d-----w C:\Program Files\Ares 2007-02-21 17:16:52 639,224 ----a-w C:\WINDOWS\system32\drivers\sptd.sys 2007-02-13 19:48:02 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Hamachi 2007-02-13 19:37:32 17,480 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2007-02-13 19:14:56 -------- d-----w C:\Program Files\GFI 2007-02-13 14:30:28 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Kamerzysta 2007-02-13 14:30:28 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\AutoUpdate 2007-02-12 17:48:40 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\XnView 2007-02-12 15:27:48 -------- d-----w C:\Program Files\Stacksoft 2007-02-11 16:02:10 -------- d-----w C:\DOCUME~1\RYSZAR~1\DANEAP~1\Microsoft Web Folders 2007-02-10 19:05:27 -------- d-----w C:\Program Files\Common Files\ODBC 2007-02-10 19:05:22 -------- d-----w C:\Program Files\Common Files\SpeechEngines 2007-02-10 18:58:26 -------- d-----w C:\Program Files\VIA Technologies, INC 2007-02-10 18:16:38 -------- d–h--w C:\Program Files\WindowsUpdate 2007-02-10 18:16:32 -------- d-----w C:\Program Files\Usługi online 2007-02-10 18:15:20 -------- d-----w C:\Program Files\Common Files\MSSoap 2007-02-10 18:15:08 -------- d-----w C:\Program Files\Movie Maker 2007-02-10 18:14:31 21,856 ----a-w C:\WINDOWS\system32\emptyregdb.dat 2007-02-10 18:12:52 -------- d-----w C:\Program Files\MSN Gaming Zone 2007-02-10 18:12:39 -------- d-----w C:\Program Files\Windows NT 2007-02-09 11:10:35 574,464 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys 2007-02-05 20:19:48 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll 2006-12-04 13:21:50 414,720 ----a-w C:\WINDOWS\system32\msscp.dll 2006-12-01 10:01:50 8,277,504 ----a-w C:\WINDOWS\system32\wmploc.dll 2006-12-01 09:46:18 99,840 ----a-w C:\WINDOWS\system32\wmpshell.dll 2006-12-01 09:45:42 258,560 ----a-w C:\WINDOWS\system32\wmerror.dll 2006-11-04 19:25:50 1,321,744 ----a-w C:\WINDOWS\system32\msxml6.dll 2006-11-02 15:10:16 80,912 ----a-w C:\WINDOWS\system32\sherlock2.exe 2006-11-02 09:52:52 42,496 ------w C:\WINDOWS\system32\wpdshextres.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-11-04 01:17] {53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “00PCTFW”=“C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe” [2007-04-28 08:13] “PCSuiteTrayApplication”=“C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe” [2007-06-18 15:10] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Nokia.PCSync”=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoSaveSettings”=00000000 “ClearRecentDocsOnExit”=0000000000000000 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2004-06-17 00:09:10 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2004-06-17 0:10:16 C:\ComboFix-quarantined-files.txt … 2004-06-17 00:10 C:\ComboFix2.txt … 2004-06-17 04:56 C:\ComboFix3.txt … 2007-06-20 12:43 — E O F —