ComboFix 07-09-21.2 - “Daras” 2007-09-27 17:05:31.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.875 [GMT 2:00] * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-08-27 to 2007-09-27 ))))))))))))))))))))))))))))))) . 2007-09-27 16:26 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-09-26 20:04 664 --a------ C:\WINDOWS\system32\d3d9caps.dat 2007-09-26 20:04 552 --a------ C:\WINDOWS\system32\d3d8caps.dat 2007-09-26 19:50 2007-09-26 19:21 2007-09-25 18:46 2007-09-25 18:46 2007-09-25 18:45 2007-09-24 20:46 765,952 -ra------ C:\WINDOWS\system\crlds3d.dll 2007-09-24 20:46 720,896 -ra------ C:\WINDOWS\system32\Audio3D.dll 2007-09-24 20:46 57,344 -ra------ C:\WINDOWS\SOUNDMAN.EXE 2007-09-24 20:46 462,684 -ra------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS 2007-09-24 20:46 404,736 -ra------ C:\WINDOWS\system32\drivers\ALCXSENS.SYS 2007-09-23 14:30 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe 2007-09-23 10:51 23,040 -----c— C:\WINDOWS\system32\dllcache\fltmc.exe 2007-09-23 10:51 16,896 -----c— C:\WINDOWS\system32\dllcache\fltlib.dll 2007-09-23 10:51 128,896 -----c— C:\WINDOWS\system32\dllcache\fltmgr.sys 2007-09-23 10:10 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-09-23 10:10 2007-09-23 10:09 2007-09-23 10:09 2007-09-22 23:55 43,352 --a------ C:\WINDOWS\system32\wups2.dll 2007-09-22 23:17 2007-09-22 23:01 2007-09-22 21:55 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-09-22 21:46 5,888 --------- C:\WINDOWS\system32\drivers\imagedrv.sys 2007-09-22 21:46 127,488 --------- C:\WINDOWS\system32\drivers\imagesrv.sys 2007-09-22 21:45 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll 2007-09-22 21:43 2007-09-22 21:24 103,557 --a------ C:\WINDOWS\GXTranscoder v2 Uninstaller.exe 2007-09-22 21:09 2007-09-22 19:44 2007-09-22 18:57 2007-09-22 13:03 2007-09-21 21:00 2007-09-21 20:54 2007-09-21 20:52 83,968 --a------ C:\WINDOWS\system32\Skbase40.dll 2007-09-21 20:52 8,704 --a------ C:\WINDOWS\system32\vidccleaner.exe 2007-09-21 20:52 552,960 --a------ C:\WINDOWS\system32\xvidcore.dll 2007-09-21 20:52 217,088 --a------ C:\WINDOWS\system32\skjpeg40.dll 2007-09-21 20:52 159,744 --a------ C:\WINDOWS\system32\xvidvfw.dll 2007-09-21 20:46 2007-09-21 19:13 2007-09-21 19:13 2007-09-21 19:12 2007-09-21 19:11 2007-09-21 19:10 2007-09-21 19:10 2007-09-21 18:41 22,016 --a------ C:\WINDOWS\system32\drivers\MSIRCOMM.sys 2007-09-21 18:16 40,960 --a------ C:\Program Files\Uninstall_CDS.exe 2007-09-21 18:16 2007-09-21 18:16 2007-09-21 18:12 22,016 -ra------ C:\WINDOWS\system32\drivers\bttuner.sys 2007-09-21 18:12 172,032 -ra------ C:\WINDOWS\DRVCFG.exe 2007-09-21 18:12 13,312 -ra------ C:\WINDOWS\system32\drivers\btxbar.sys 2007-09-21 18:11 69,632 -ra------ C:\WINDOWS\system32\AVerTV2K.dll 2007-09-21 18:11 49,152 -ra------ C:\WINDOWS\system32\IOCtrl.dll 2007-09-21 18:11 261,696 -ra------ C:\WINDOWS\system32\drivers\BT848.sys 2007-09-20 22:22 1,212 --a------ C:\WINDOWS\mozver.dat 2007-09-20 22:00 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll 2007-09-20 22:00 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll 2007-09-20 22:00 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll 2007-09-20 22:00 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe 2007-09-20 22:00 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll 2007-09-20 22:00 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll 2007-09-20 22:00 2007-09-20 21:46 2007-09-20 21:42 2007-09-20 21:40 58,624 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-09-20 21:40 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-09-20 21:38 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll 2007-09-20 21:38 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll 2007-09-20 21:38 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll 2007-09-20 21:38 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:37 2007-09-20 21:19 0 --a------ C:\WINDOWS\nsreg.dat 2007-09-20 21:10 2007-09-20 21:10 2007-09-20 21:06 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll 2007-09-20 21:06 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll 2007-09-20 21:06 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-09-20 21:05 2007-09-20 21:01 87,424 --a------ C:\WINDOWS\system32\drivers\irda.sys 2007-09-20 21:01 8,192 --a------ C:\WINDOWS\system32\wshirda.dll 2007-09-20 21:01 27,648 --a------ C:\WINDOWS\system32\irmon.dll 2007-09-20 21:01 19,584 --a------ C:\WINDOWS\system32\drivers\rasirda.sys 2007-09-20 21:01 19,034 -ra------ C:\WINDOWS\system32\drivers\KS-959.sys 2007-09-20 21:01 153,088 --a------ C:\WINDOWS\system32\irftp.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-09-26 19:47 --------- d–h----- C:\Program Files\InstallShield Installation Information 2007-09-20 20:27 --------- d-------- C:\Program Files\Common Files\InstallShield 2007-09-20 19:50 --------- d-------- C:\Program Files\microsoft frontpage 2007-09-06 12:09 801144 --a------ C:\WINDOWS\system32\aswBoot.exe 2007-09-06 12:05 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys 2007-09-06 12:05 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys 2007-09-06 12:03 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys 2007-09-06 12:02 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys 2007-09-06 12:00 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr 2007-09-06 12:00 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys 2007-08-22 04:09 352256 --a------ C:\WINDOWS\system32\ATIDEMGX.dll 2007-08-22 03:48 8306688 --a------ C:\WINDOWS\system32\atioglx2.dll 2007-08-22 03:15 172032 --a------ C:\WINDOWS\system32\atiok3x2.dll 2007-08-21 02:26 81920 --a------ C:\WINDOWS\system32\dpl100.dll 2007-08-21 02:26 196608 --a------ C:\WINDOWS\system32\dtu100.dll 2007-08-16 00:33 524288 --a------ C:\WINDOWS\system32\DivXsm.exe 2007-08-16 00:33 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2007-08-16 00:33 200704 --a------ C:\WINDOWS\system32\ssldivx.dll 2007-08-16 00:33 1044480 --a------ C:\WINDOWS\system32\libdivx.dll 2007-08-16 00:31 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll 2007-08-16 00:31 57344 --a------ C:\WINDOWS\system32\dpv11.dll 2007-08-16 00:31 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll 2007-08-16 00:31 344064 --a------ C:\WINDOWS\system32\dpus11.dll 2007-08-16 00:31 294912 --a------ C:\WINDOWS\system32\dpu11.dll 2007-08-16 00:31 294912 --a------ C:\WINDOWS\system32\dpu10.dll 2007-08-16 00:30 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll --------- C:\Program Files\Usługi online . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “avast!”=“D:\Programy\Avast4\ashDisp.exe” [2007-09-06 12:06] “SoundMan”=“SOUNDMAN.EXE” [2003-08-15 09:34 C:\WINDOWS\SOUNDMAN.EXE] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2006-01-02 16:41] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Creative MediaSource Go”=“D:\Programy\Creative\MediaSource\Go\CTCMSGo.exe” [2004-11-30 11:00] “AtiTrayTools”=“D:\Programy\ATI Tray Tools\atitray.exe” [2007-05-22 11:04] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-02 14:00] C:\DOCUME~1\ALLUSE~1\MENUST~1\Programy\AUTOST~1\ Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk - C:\Program Files\SAGEM WiFi manager\WLANUTL.exe [2007-09-20 20:16:24] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^QuickTV.lnk] path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\QuickTV.lnk backup=C:\WINDOWS\pss\QuickTV.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wengo] “D:/Programy/Wengo/wengophone.exe” -background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] “wuauserv”=2 (0x2) “UPS”=3 (0x3) “srservice”=2 (0x2) “Spooler”=2 (0x2) “RDSessMgr”=3 (0x3) “RasMan”=3 (0x3) “mnmsrvc”=3 (0x3) R1 atitray;atitray;??\D:\Programy\ATI Tray Tools\atitray.sys R2 BT848;AVerMedia, AVerTV WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys R3 P17;Sound Blaster Audigy;C:\WINDOWS\system32\drivers\P17.sys R3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys R3 V0260VID;Live! Cam Vista IM;C:\WINDOWS\system32\DRIVERS\V0260Vid.sys S0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys S3 KS-959;Kingsun KS-959 USB Infrared Adapter;C:\WINDOWS\system32\DRIVERS\KS-959.sys S3 MSIRCOMM;Microsoft IR Communications Driver;C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys S3 ZDCndis5;ZDCndis5 Protocol Driver;??\C:\WINDOWS\system32\ZDCndis5.SYS *Newly Created Service* - CATCHME . ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-09-27 17:06:51 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … ************************************************************************** . Completion time: 2007-09-27 17:08:06 . — E O F —