ComboFix 07-06-13.3 - D:\Programy\convert\ComboFix.exe “Gilberss” - 2007-06-16 17:31:18 - Dodatek Service Pack 2 NTFS ((((((((((((((((((((((((( Files Created from 2007-05-16 to 2007-06-16 ))))))))))))))))))))))))))))))) ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\koos.exe C:\WINDOWS\system32\kprof C:\WINDOWS\system32\poof ((((((((((((((((((((((((( Files Created from 2007-05-16 to 2007-06-16 ))))))))))))))))))))))))))))))) 2007-06-16 16:16 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-16 16:16 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-15 15:48 2007-06-15 15:48 2007-06-15 15:48 2007-06-15 15:48 2007-06-15 06:26 2007-06-15 06:26 2007-06-15 06:22 2007-06-13 12:55 2007-06-13 12:30 2007-06-13 12:30 2007-06-12 21:59 2007-06-11 16:13 2007-06-03 12:51 2007-05-26 11:56 2007-05-26 11:44 2007-05-26 11:42 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-05-26 11:42 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll 2007-05-26 11:41 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll 2007-05-26 11:41 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll 2007-05-26 11:41 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll 2007-05-26 11:41 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll 2007-05-26 11:41 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll 2007-05-26 11:41 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll 2007-05-26 11:41 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll 2007-05-26 11:41 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll 2007-05-26 11:41 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll 2007-05-26 11:41 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll 2007-05-26 11:41 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll 2007-05-26 11:41 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll 2007-05-26 11:41 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll 2007-05-26 11:41 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll 2007-05-26 11:41 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-05-26 11:41 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll 2007-05-26 11:41 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll 2007-05-26 11:41 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll 2007-05-26 11:41 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll 2007-05-26 11:41 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll 2007-05-26 11:41 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-05-26 11:41 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-05-26 11:41 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-05-26 11:41 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll 2007-05-26 11:41 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll 2007-05-26 11:41 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll 2007-05-22 11:53 2007-05-18 13:39 2007-05-16 18:17 737,280 --a------ C:\WINDOWS\iun6002.exe 2007-05-16 18:17 737,280 --a------ C:\WINDOWS\iun6002.exe 2007-05-16 18:17 135,168 --a------ C:\WINDOWS\system32\DSKernel2.dll 2007-05-16 18:17 135,168 --a------ C:\WINDOWS\system32\DSKernel2.dll 2007-05-16 18:17 1,936,528 --a------ C:\WINDOWS\system32\ltmm15.dll 2007-05-16 18:17 1,936,528 --a------ C:\WINDOWS\system32\ltmm15.dll 2007-05-16 17:57 2007-05-16 16:58 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll 2007-05-16 16:58 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll 2007-05-16 08:45 102,400 --a------ C:\WINDOWS\system32\unzip32.dll 2007-05-16 08:45 102,400 --a------ C:\WINDOWS\system32\unzip32.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-16 14:45:15 -------- d-----w C:\Program Files\eMule 2007-06-16 14:22:29 -------- d-----w C:\Program Files\Google 2007-06-15 17:29:45 -------- d-----w C:\Program Files\Lx_cats 2007-06-15 07:59:43 50,748 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-15 07:59:43 358,834 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-15 04:04:22 -------- d-----w C:\Program Files\Windows Media Connect 2 2007-06-13 04:37:01 -------- d-----w C:\DOCUME~1\Gilberss\DANEAP~1\OpenOffice.ux.pl2 2007-05-23 19:50:36 -------- d-----w C:\Program Files\Common Files\Art Plus Uninstall 2007-05-16 15:18:58 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-05-12 13:05:17 -------- d-----w C:\DOCUME~1\Gilberss\DANEAP~1\Serif 2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe 2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys 2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr 2007-04-25 15:27:59 -------- d-----w C:\Program Files\USB Vibration Joystick 2007-04-25 14:23:30 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-25 09:11:47 -------- d-----w C:\Program Files\Ahead 2007-04-25 09:07:07 -------- d-----w C:\Program Files\Common Files\Ahead 2007-04-18 16:14:32 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-04-13 16:42:20 200 -c–a-w C:\WINDOWS\AUDC70UI.dat 2007-04-13 16:12:47 245,760 -c----w C:\WINDOWS\Setup1.exe 2007-04-13 16:12:45 73,216 -c–a-w C:\WINDOWS\ST6UNST.EXE 2007-04-08 07:34:02 3,350 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys 2007-04-01 15:02:03 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll 2007-04-01 08:49:08 8,464 -c–a-w C:\WINDOWS\system32\sporder.dll 2007-03-20 17:51:40 2,478,080 ----a-w C:\WINDOWS\system32\Sharon Stone.scr 2007-03-17 13:45:36 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {72853161-30C5-4D22-B7F9-0BBC1D38A37E}=D:\Programy\NEWFOL~1\Office12\GRA8E1~1.DLL [2006-10-27 00:48] {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-29 05:59] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “SoundMan”=“SOUNDMAN.EXE” [2005-08-17 12:39 C:\WINDOWS\SOUNDMAN.EXE] “nwiz”=“nwiz.exe” [2005-08-02 10:35 C:\WINDOWS\system32\nwiz.exe] “lxbumon.exe”=“C:\Program Files\Lexmark 6200 Series\lxbumon.exe” [2005-01-18 16:39] “@”="" [] “EzPrint”=“C:\Program Files\Lexmark 6200 Series\ezprint.exe” [2004-09-17 19:24] “avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-04-30 17:42] “AT-Watch”="" [] “DownloadAccelerator”=“D:\Programy\DAP\DAP.exe” [2007-05-16 16:58] “ISUSPM”=“C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe” [] “GrooveMonitor”=“D:\Programy\New Folder\Office12\GrooveMonitor.exe” [2006-10-27 00:47] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “odk_mcd”="" [] “Gadu-Gadu”=“D:\Programy\GG\Gadu-Gadu\gg.exe” [2006-11-14 11:12] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 14:00] “TaskSwitchXP”=“C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe” [2006-08-05 00:29] “AdobeUpdater”=“C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe” [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] “{B5A7F190-DDA6-4420-B3BA-52453494E6CD}”=“D:\Programy\NEWFOL~1\Office12\GRA8E1~1.DLL” [2006-10-27 00:48] ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-16 17:33:14 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … cmd.exe [3604] scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-16 17:33:39 — E O F —