ComboFix 07-06-18.2 - C:\Documents and Settings\Comp\Pulpit\PULPIT\ComboFix.exe “Comp” - 2007-07-05 12:24:31 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2007-06-05 to 2007-07-05 ))))))))))))))))))))))))))))))) 2007-07-03 21:24 2007-07-03 17:27 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-07-03 14:38 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-07-03 10:38 2007-07-03 00:07 23 --ahs---- C:\WINDOWS\system32\bbfad5_r.dll 2007-07-03 00:07 2007-07-02 01:20 33,340 --------- C:\WINDOWS\system32\dbmsqlgc.dll 2007-07-02 01:20 306,688 --a------ C:\WINDOWS\IsUninst.exe 2007-07-02 01:20 24,576 --------- C:\WINDOWS\system32\dbmsgnet.dll 2007-07-02 01:19 2007-07-01 23:16 2007-07-01 21:51 2007-07-01 21:51 2007-07-01 21:48 2007-07-01 21:47 2007-07-01 21:43 2007-07-01 21:21 2007-07-01 21:21 2007-06-30 16:52 2007-06-30 16:51 2007-06-29 22:13 2007-06-29 22:13 2007-06-28 00:07 86,016 --a------ C:\WINDOWS\unvise32.exe 2007-06-28 00:07 2007-06-28 00:03 2007-06-26 20:01 2007-06-25 14:02 2007-06-24 19:27 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-06-23 21:32 2007-06-23 15:05 2007-06-23 14:01 2007-06-23 14:01 2007-06-22 18:31 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-06-22 18:30 2007-06-22 18:30 2007-06-22 18:29 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL 2007-06-22 18:29 2007-06-22 18:29 2007-06-22 18:28 307,200 --a------ C:\WINDOWS\IsUn0415.exe 2007-06-22 18:28 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll 2007-06-22 18:27 57,344 --a------ C:\WINDOWS\system32\CNCI160.DLL 2007-06-22 18:27 161,792 --a------ C:\WINDOWS\system32\CNMLM83.DLL 2007-06-22 18:27 135,168 --a------ C:\WINDOWS\system32\CNCL160.DLL 2007-06-22 18:27 106,496 --a------ C:\WINDOWS\system32\cnco160.dll 2007-06-22 18:27 1,134,592 --a------ C:\WINDOWS\system32\CNCC160.DLL 2007-06-22 18:27 2007-06-22 18:27 2007-06-22 18:27 2007-06-22 18:27 2007-06-22 18:25 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-06-22 18:25 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-06-22 17:57 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-06-22 17:56 2007-06-22 17:56 2007-06-22 17:54 2007-06-21 22:08 684,248 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys 2007-06-21 22:06 281,816 --a------ C:\WINDOWS\system32\cfosspeed.dll 2007-06-21 22:06 2007-06-21 21:37 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-06-21 21:36 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-06-21 21:36 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS 2007-06-21 21:36 4,529,408 --a------ C:\WINDOWS\system32\nv4_disp.dll 2007-06-21 21:36 3,925,920 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys 2007-06-21 21:35 77,312 --a------ C:\WINDOWS\system32\usbui.dll 2007-06-21 21:35 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys 2007-06-21 21:35 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys 2007-06-21 21:34 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL 2007-06-21 21:34 9,168 --a------ C:\WINDOWS\system\VER.DLL 2007-06-21 21:34 85,532 --a------ C:\WINDOWS\system32\dgsetup.dll 2007-06-21 21:34 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL 2007-06-21 21:34 8,704 --a------ C:\WINDOWS\system32\batt.dll 2007-06-21 21:34 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll 2007-06-21 21:34 75,776 --a------ C:\WINDOWS\system32\storprop.dll 2007-06-21 21:34 70,144 --a------ C:\WINDOWS\NOTEPAD.EXE 2007-06-21 21:34 70,096 --a------ C:\WINDOWS\system\AVICAP.DLL 2007-06-21 21:34 7,168 --a------ C:\WINDOWS\system32\kbdcz.dll 2007-06-21 21:34 69,552 --a------ C:\WINDOWS\system\MMSYSTEM.DLL 2007-06-21 21:34 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll 2007-06-21 21:34 6,656 --a------ C:\WINDOWS\system32\kbdycl.dll 2007-06-21 21:34 6,656 --a------ C:\WINDOWS\system32\kbdsl1.dll 2007-06-21 21:34 6,656 --a------ C:\WINDOWS\system32\kbdsl.dll 2007-06-21 21:34 6,656 --a------ C:\WINDOWS\system32\kbdhu.dll 2007-06-21 21:34 6,656 --a------ C:\WINDOWS\system32\kbdcz2.dll 2007-06-21 21:34 6,656 --a------ C:\WINDOWS\system32\kbdcz1.dll 2007-06-21 21:34 6,656 --a------ C:\WINDOWS\system32\kbdcr.dll 2007-06-21 21:34 6,656 --a------ C:\WINDOWS\system32\KBDAL.DLL 2007-06-21 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-06-21 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-06-21 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll 2007-06-21 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll 2007-06-21 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll 2007-06-21 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll 2007-06-21 21:34 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll 2007-06-21 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll 2007-06-21 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll 2007-06-21 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll 2007-06-21 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll 2007-06-21 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll 2007-06-21 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll 2007-06-21 21:34 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-03 08:50:26 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-07-01 23:20:54 86,872 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-07-01 23:20:54 475,508 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-30 14:52:08 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll 2007-06-21 18:43:10 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll 2007-06-21 17:46:38 -------- d-----w C:\Program Files\Usługi online ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=C:\Program Files\BitComet\tools\BitCometBHO_1.1.5.19.dll [2007-05-18 20:17] {68F9551E-0411-48E4-9AAF-4BC42A6A46BE}=C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [2006-04-18 19:04] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “nwiz”=“nwiz.exe” [2006-06-01 17:22 C:\WINDOWS\system32\nwiz.exe] “C-Media Mixer”=“Mixer.exe” [2003-03-20 09:21 C:\WINDOWS\mixer.exe] “cFosSpeed”=“C:\Program Files\cFosSpeed\cFosSpeed.exe” [2007-06-19 10:19] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 14:00] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] “NoRemoteRecursiveEvents”=1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “NoRecentDocsMenu”=1 (0x1) “NoSaveSettings”=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll” [2007-05-30 14:29] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard] ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-05 12:25:20 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-05 12:25:45 C:\ComboFix-quarantined-files.txt … 2007-07-05 12:25 C:\ComboFix2.txt … 2007-07-03 17:29 — E O F —