ComboFix 07-10-23.2 - User 2007-10-23 23:48:38.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.67 [GMT 1:00] Running from: C:\Documents and Settings\Administrator\My Documents\antywirusy\ComboFix2.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-09-23 to 2007-10-23 ))))))))))))))))))))))))))))))) . 2007-10-21 16:38 82,061 --a------ C:\WINDOWS\system32\drivers\klick.dat 2007-10-21 16:38 81,549 --a------ C:\WINDOWS\system32\drivers\klin.dat 2007-10-21 16:37 2007-10-21 16:37 2,347,552 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2007-10-21 16:37 15,392 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat 2007-10-09 23:25 582,656 -----c— C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-09-26 22:33 2,647,172 --a------ C:\icytower(dobreprogramy.pl).exe 2007-09-23 18:23 2007-09-23 15:24 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-23 23:03 --------- d-----w C:\Documents and Settings\User\Application Data\Skype 2007-10-23 21:00 25,052 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2007-10-23 21:00 1,988 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx 2007-10-20 20:41 --------- d-----w C:\Program Files\Dl_cats 2007-10-08 22:56 --------- d-----w C:\Program Files\Jasc Software Inc 2007-09-20 20:38 --------- d-----w C:\Program Files\RM Converter 2007-09-20 20:37 --------- d-----w C:\Program Files\Yahoo! 2007-09-20 20:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-09-18 19:24 --------- d-----w C:\Program Files\Nokia 2007-09-15 06:21 --------- d-----w C:\Documents and Settings\User\Application Data\Yahoo! 2007-09-09 12:44 --------- d-----w C:\Documents and Settings\User\Application Data\Nokia 2007-09-08 21:13 --------- d-----w C:\Documents and Settings\User\Application Data\Nokia Multimedia Player 2007-09-08 20:52 --------- d-----w C:\Documents and Settings\User\Application Data\PC Suite 2007-09-08 20:51 --------- d-----w C:\Program Files\Common Files\PCSuite 2007-09-08 20:51 --------- d-----w C:\Program Files\Common Files\Nokia 2007-09-08 20:50 --------- d-----w C:\Program Files\PC Connectivity Solution 2007-09-08 20:50 --------- d-----w C:\Program Files\DIFX 2007-09-08 19:15 --------- d-----w C:\Program Files\3220 USB-Handset Manager 2007-09-08 19:14 --------- d-----w C:\Documents and Settings\User\Application Data\MobileAction 2007-09-03 18:00 --------- d-----w C:\Program Files\Windows Desktop Search 2007-09-03 17:16 --------- d-----w C:\Program Files\Real 2007-09-03 17:15 --------- d-----w C:\Program Files\Windows Live Toolbar 2007-09-02 21:57 --------- d-----w C:\Program Files\MarBit 2007-08-29 02:03 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2 2007-08-28 20:52 --------- d-----w C:\Program Files\Microsoft Works 2007-08-28 20:50 --------- d-----w C:\Program Files\Microsoft.NET . ((((((((((((((((((((((((((((( snapshot_2007-09-22_151917.29 ))))))))))))))))))))))))))))))))))))))))) . + 2007-08-20 10:02:09 124,928 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\advpack.dll + 2007-08-20 10:02:11 214,528 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\dxtrans.dll + 2007-08-20 10:02:09 132,608 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\extmgr.dll + 2007-08-20 10:02:09 63,488 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\icardie.dll + 2007-08-17 10:12:34 70,656 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\ie4uinit.exe + 2007-08-20 10:02:09 153,088 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\ieakeng.dll + 2007-08-20 10:02:09 230,400 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\ieaksie.dll + 2007-08-17 07:29:55 161,792 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\ieakui.dll + 2007-04-17 09:28:12 2,455,488 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\ieapfltr.dat + 2007-08-20 10:02:09 383,488 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\ieapfltr.dll + 2007-08-20 10:02:09 387,584 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\iedkcs32.dll + 2007-08-20 10:02:10 6,066,176 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\ieframe.dll + 2007-08-20 10:02:10 44,544 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\iernonce.dll + 2007-08-20 10:02:10 267,776 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\iertutil.dll + 2007-08-17 10:12:35 13,824 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\ieudinit.exe + 2007-08-17 10:12:49 625,152 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe + 2007-08-20 10:02:10 27,648 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\jsproxy.dll + 2007-08-20 10:02:10 459,264 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\msfeeds.dll + 2007-08-20 10:02:10 52,224 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\msfeedsbs.dll + 2007-08-20 10:02:11 3,592,192 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\mshtml.dll + 2007-08-20 10:02:11 478,208 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\mshtmled.dll + 2007-08-20 10:02:11 193,024 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\msrating.dll + 2007-08-20 10:02:11 671,232 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\mstime.dll + 2007-08-20 10:02:11 102,400 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\occache.dll + 2007-08-20 10:02:11 105,984 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\url.dll + 2007-08-20 10:02:11 1,161,728 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\urlmon.dll + 2007-08-20 10:02:11 232,960 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\webcheck.dll + 2007-08-20 10:02:11 825,344 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\spmsg.dll + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\spuninst.exe + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\update\spcustom.dll + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\update\update.exe + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS$hf_mig$\KB939653-IE7\update\updspapi.dll + 2007-08-21 06:25:02 683,520 ----a-w C:\WINDOWS$hf_mig$\KB941202\SP2QFE\inetcomm.dll + 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS$hf_mig$\KB941202\spmsg.dll + 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS$hf_mig$\KB941202\spuninst.exe + 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS$hf_mig$\KB941202\update\spcustom.dll + 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS$hf_mig$\KB941202\update\update.exe + 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS$hf_mig$\KB941202\update\updspapi.dll - 2007-07-19 23:47:22 109,056 ----a-w C:\WINDOWS\catchme.exe + 2007-10-20 05:03:30 136,192 ----a-w C:\WINDOWS\catchme.exe + 2007-09-23 07:52:19 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE + 2007-09-23 14:24:37 1,249,280 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT + 2007-09-23 14:24:37 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat + 2007-09-23 07:52:19 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE + 2007-09-23 14:24:26 1,249,280 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT + 2007-09-23 14:24:26 8,192 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat + 2007-06-27 14:34:51 124,928 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\advpack.dll + 2006-10-17 10:57:50 214,528 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\dxtrans.dll + 2007-06-27 14:34:51 132,608 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\extmgr.dll + 2006-10-17 10:58:20 61,952 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\icardie.dll + 2007-06-27 08:27:04 63,488 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe + 2007-06-27 14:34:51 153,088 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\ieakeng.dll + 2007-06-27 14:34:51 230,400 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\ieaksie.dll + 2007-06-27 07:00:33 161,792 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\ieakui.dll + 2007-06-27 14:34:51 383,488 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dll + 2007-06-27 14:34:51 384,512 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\iedkcs32.dll + 2007-06-27 14:34:55 6,058,496 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\ieframe.dll + 2007-06-27 14:34:55 44,544 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\iernonce.dll + 2007-06-27 14:34:55 267,776 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\iertutil.dll + 2007-06-27 08:27:05 13,824 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\ieudinit.exe + 2007-06-27 08:27:30 625,152 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe + 2007-06-27 14:34:56 27,648 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\jsproxy.dll + 2007-06-27 14:34:56 459,264 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\msfeeds.dll + 2007-06-27 14:34:56 52,224 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\msfeedsbs.dll + 2007-07-19 06:59:59 3,583,488 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll + 2007-06-27 14:34:57 477,696 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\mshtmled.dll + 2007-06-27 14:34:58 193,024 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\msrating.dll + 2007-06-27 14:34:58 671,232 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\mstime.dll + 2007-06-27 14:34:58 102,400 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\occache.dll + 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe + 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\updspapi.dll + 2007-06-27 14:34:58 105,984 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\url.dll + 2007-06-27 14:34:58 1,152,000 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\urlmon.dll + 2007-06-27 14:34:59 232,960 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\webcheck.dll + 2007-06-27 14:34:59 823,808 -c----w C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll - 2007-09-19 11:52:48 20,240 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\cagicon.exe + 2007-10-10 06:00:08 20,240 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\cagicon.exe - 2007-09-19 11:52:48 217,864 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\misc.exe + 2007-10-10 06:00:08 217,864 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\misc.exe - 2007-09-19 11:52:48 18,704 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\mspicons.exe + 2007-10-10 06:00:08 18,704 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\mspicons.exe - 2007-09-19 11:52:48 35,088 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\oisicon.exe + 2007-10-10 06:00:09 35,088 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\oisicon.exe - 2007-09-19 11:52:47 845,584 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\outicon.exe + 2007-10-10 06:00:07 845,584 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\outicon.exe - 2007-09-19 11:52:48 922,384 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\pptico.exe + 2007-10-10 06:00:07 922,384 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\pptico.exe - 2007-09-19 11:52:48 888,080 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\wordicon.exe + 2007-10-10 06:00:08 888,080 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\wordicon.exe - 2007-09-19 11:52:47 1,172,240 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\xlicons.exe + 2007-10-10 06:00:07 1,172,240 ----a-r C:\WINDOWS\Installer{91120000-0012-0000-0000-0000000FF1CE}\xlicons.exe - 2007-06-27 14:34:51 124,928 ----a-w C:\WINDOWS\system32\advpack.dll + 2007-08-20 10:04:34 124,928 ----a-w C:\WINDOWS\system32\advpack.dll - 2007-09-19 20:53:27 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2007-10-21 15:42:03 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - 2007-09-19 20:53:27 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2007-10-21 15:42:03 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2007-09-19 20:53:27 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2007-10-21 15:42:03 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat - 2007-06-27 14:34:51 124,928 -c----w C:\WINDOWS\system32\dllcache\advpack.dll + 2007-08-20 10:04:34 124,928 -c----w C:\WINDOWS\system32\dllcache\advpack.dll - 2006-10-17 10:57:50 214,528 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll + 2007-08-20 10:04:34 214,528 -c–a-w C:\WINDOWS\system32\dllcache\dxtrans.dll - 2007-06-27 14:34:51 132,608 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll + 2007-08-20 10:04:34 132,608 -c–a-w C:\WINDOWS\system32\dllcache\extmgr.dll + 2007-08-20 10:04:34 63,488 -c----w C:\WINDOWS\system32\dllcache\icardie.dll - 2007-06-27 08:27:04 63,488 -c----w C:\WINDOWS\system32\dllcache\ie4uinit.exe + 2007-08-17 10:20:54 63,488 -c----w C:\WINDOWS\system32\dllcache\ie4uinit.exe - 2007-06-27 14:34:51 153,088 -c----w C:\WINDOWS\system32\dllcache\ieakeng.dll + 2007-08-20 10:04:34 153,088 -c----w C:\WINDOWS\system32\dllcache\ieakeng.dll - 2007-06-27 14:34:51 230,400 -c----w C:\WINDOWS\system32\dllcache\ieaksie.dll + 2007-08-20 10:04:35 230,400 -c----w C:\WINDOWS\system32\dllcache\ieaksie.dll - 2007-06-27 07:00:33 161,792 -c----w C:\WINDOWS\system32\dllcache\ieakui.dll + 2007-08-17 07:34:25 161,792 -c----w C:\WINDOWS\system32\dllcache\ieakui.dll - 2007-06-27 14:34:51 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll + 2007-08-20 10:04:35 383,488 -c----w C:\WINDOWS\system32\dllcache\ieapfltr.dll - 2007-06-27 14:34:51 384,512 -c----w C:\WINDOWS\system32\dllcache\iedkcs32.dll + 2007-08-20 10:04:35 384,512 -c----w C:\WINDOWS\system32\dllcache\iedkcs32.dll - 2007-06-27 14:34:55 6,058,496 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll + 2007-08-20 10:04:37 6,058,496 -c----w C:\WINDOWS\system32\dllcache\ieframe.dll - 2007-06-27 14:34:55 44,544 -c----w C:\WINDOWS\system32\dllcache\iernonce.dll + 2007-08-20 10:04:38 44,544 -c----w C:\WINDOWS\system32\dllcache\iernonce.dll - 2007-06-27 14:34:55 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll + 2007-08-20 10:04:38 267,776 -c----w C:\WINDOWS\system32\dllcache\iertutil.dll - 2007-06-27 08:27:05 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe + 2007-08-17 10:20:54 13,824 -c----w C:\WINDOWS\system32\dllcache\ieudinit.exe - 2007-06-27 08:27:30 625,152 -c----w C:\WINDOWS\system32\dllcache\iexplore.exe + 2007-08-17 10:21:21 625,152 -c----w C:\WINDOWS\system32\dllcache\iexplore.exe - 2007-05-16 15:12:02 683,520 -c----w C:\WINDOWS\system32\dllcache\inetcomm.dll + 2007-08-21 06:15:44 683,520 -c----w C:\WINDOWS\system32\dllcache\inetcomm.dll - 2007-06-27 14:34:56 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll + 2007-08-20 10:04:39 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jsproxy.dll - 2007-06-27 14:34:56 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll + 2007-08-20 10:04:39 459,264 -c----w C:\WINDOWS\system32\dllcache\msfeeds.dll - 2007-06-27 14:34:56 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll + 2007-08-20 10:04:39 52,224 -c----w C:\WINDOWS\system32\dllcache\msfeedsbs.dll - 2007-07-19 06:59:59 3,583,488 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll + 2007-08-20 10:04:41 3,584,512 -c–a-w C:\WINDOWS\system32\dllcache\mshtml.dll - 2007-06-27 14:34:57 477,696 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll + 2007-08-20 10:04:41 477,696 -c–a-w C:\WINDOWS\system32\dllcache\mshtmled.dll - 2007-06-27 14:34:58 193,024 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll + 2007-08-20 10:04:41 193,024 -c–a-w C:\WINDOWS\system32\dllcache\msrating.dll - 2007-06-27 14:34:58 671,232 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll + 2007-08-20 10:04:42 671,232 -c–a-w C:\WINDOWS\system32\dllcache\mstime.dll - 2007-06-27 14:34:58 102,400 -c----w C:\WINDOWS\system32\dllcache\occache.dll + 2007-08-20 10:04:42 102,400 -c----w C:\WINDOWS\system32\dllcache\occache.dll - 2007-06-27 14:34:58 105,984 -c----w C:\WINDOWS\system32\dllcache\url.dll + 2007-08-20 10:04:42 105,984 -c----w C:\WINDOWS\system32\dllcache\url.dll - 2007-06-27 14:34:58 1,152,000 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll + 2007-08-20 10:04:42 1,152,000 -c–a-w C:\WINDOWS\system32\dllcache\urlmon.dll - 2007-06-27 14:34:59 232,960 -c----w C:\WINDOWS\system32\dllcache\webcheck.dll + 2007-08-20 10:04:42 232,960 -c----w C:\WINDOWS\system32\dllcache\webcheck.dll - 2007-06-27 14:34:59 823,808 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll + 2007-08-20 10:04:43 824,832 -c–a-w C:\WINDOWS\system32\dllcache\wininet.dll - 2006-10-17 10:57:50 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll + 2007-08-20 10:04:34 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll - 2007-06-27 14:34:51 132,608 ----a-w C:\WINDOWS\system32\extmgr.dll + 2007-08-20 10:04:34 132,608 ----a-w C:\WINDOWS\system32\extmgr.dll - 2006-10-17 10:58:20 61,952 ------w C:\WINDOWS\system32\icardie.dll + 2007-08-20 10:04:34 63,488 ----a-w C:\WINDOWS\system32\icardie.dll - 2007-06-27 08:27:04 63,488 ----a-w C:\WINDOWS\system32\ie4uinit.exe + 2007-08-17 10:20:54 63,488 ----a-w C:\WINDOWS\system32\ie4uinit.exe - 2007-06-27 14:34:51 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll + 2007-08-20 10:04:34 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll - 2007-06-27 14:34:51 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll + 2007-08-20 10:04:35 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll - 2007-06-27 07:00:33 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll + 2007-08-17 07:34:25 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll - 2007-06-27 14:34:51 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll + 2007-08-20 10:04:35 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll - 2007-06-27 14:34:51 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll + 2007-08-20 10:04:35 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll - 2007-06-27 14:34:55 6,058,496 ----a-w C:\WINDOWS\system32\ieframe.dll + 2007-08-20 10:04:37 6,058,496 ----a-w C:\WINDOWS\system32\ieframe.dll - 2007-06-27 14:34:55 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll + 2007-08-20 10:04:38 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll - 2007-06-27 14:34:55 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll + 2007-08-20 10:04:38 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll - 2007-06-27 08:27:05 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe + 2007-08-17 10:20:54 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe - 2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll + 2007-08-21 06:15:44 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll - 2007-06-27 14:34:56 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll + 2007-08-20 10:04:39 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll - 2007-09-06 02:50:42 17,474,680 ----a-w C:\WINDOWS\system32\MRT.exe + 2007-09-28 05:19:39 18,089,592 ----a-w C:\WINDOWS\system32\MRT.exe - 2007-06-27 14:34:56 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll + 2007-08-20 10:04:39 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll - 2007-06-27 14:34:56 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll + 2007-08-20 10:04:39 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll - 2007-07-19 06:59:59 3,583,488 ----a-w C:\WINDOWS\system32\mshtml.dll + 2007-08-20 10:04:41 3,584,512 ----a-w C:\WINDOWS\system32\mshtml.dll - 2007-06-27 14:34:57 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll + 2007-08-20 10:04:41 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll - 2007-06-27 14:34:58 193,024 ----a-w C:\WINDOWS\system32\msrating.dll + 2007-08-20 10:04:41 193,024 ----a-w C:\WINDOWS\system32\msrating.dll - 2007-06-27 14:34:58 671,232 ----a-w C:\WINDOWS\system32\mstime.dll + 2007-08-20 10:04:42 671,232 ----a-w C:\WINDOWS\system32\mstime.dll - 2007-06-27 14:34:58 102,400 ----a-w C:\WINDOWS\system32\occache.dll + 2007-08-20 10:04:42 102,400 ----a-w C:\WINDOWS\system32\occache.dll - 2004-08-04 07:56:44 581,120 ----a-w C:\WINDOWS\system32\rpcrt4.dll + 2007-07-09 13:16:16 582,656 ----a-w C:\WINDOWS\system32\rpcrt4.dll - 2007-07-22 17:39:27 279,552 ----a-w C:\WINDOWS\system32\swreg.exe + 2007-04-02 13:21:27 139,776 ----a-w C:\WINDOWS\system32\swreg.exe - 2007-06-27 14:34:58 105,984 ----a-w C:\WINDOWS\system32\url.dll + 2007-08-20 10:04:42 105,984 ----a-w C:\WINDOWS\system32\url.dll - 2007-06-27 14:34:58 1,152,000 ------w C:\WINDOWS\system32\urlmon.dll + 2007-08-20 10:04:42 1,152,000 ----a-w C:\WINDOWS\system32\urlmon.dll - 2007-06-27 14:34:59 232,960 ----a-w C:\WINDOWS\system32\webcheck.dll + 2007-08-20 10:04:42 232,960 ----a-w C:\WINDOWS\system32\webcheck.dll - 2007-06-27 14:34:59 823,808 ------w C:\WINDOWS\system32\wininet.dll + 2007-08-20 10:04:43 824,832 ----a-w C:\WINDOWS\system32\wininet.dll - 2007-04-18 10:07:59 248,320 ----a-w C:\WINDOWS\system32\xpsp3res.dll + 2007-06-19 07:24:36 350,720 ----a-w C:\WINDOWS\system32\xpsp3res.dll . – Snapshot reset to current date – . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “00THotkey”=“C:\WINDOWS\System32\00THotkey.exe” [2003-11-21 23:49] “000StTHK”=“000StTHK.exe” [2001-06-24 05:28 C:\WINDOWS\system32\000StTHK.exe] “NvCplDaemon”=“C:\WINDOWS\System32\NvCpl.dll” [2003-12-10 15:50] “nwiz”=“nwiz.exe” [2003-12-10 15:50 C:\WINDOWS\system32\nwiz.exe] “LtMoh”=“C:\Program Files\ltmoh\Ltmoh.exe” [2003-01-03 01:16] “AGRSMMSG”=“AGRSMMSG.exe” [2003-04-18 20:20 C:\WINDOWS\agrsmmsg.exe] “Apoint”=“C:\Program Files\Apoint2K\Apoint.exe” [2003-10-31 01:46] “TMESRV.EXE”=“C:\Program Files\TOSHIBA\TME3\TMESRV31.exe” [2003-12-10 05:50] “TMERzCtl.EXE”=“C:\Program Files\TOSHIBA\TME3\TMERzCtl.exe” [2003-10-07 02:43] “TMESBS.EXE”=“C:\Program Files\TOSHIBA\TME3\TMESBS32.exe” [2003-08-01 23:56] “DpUtil”=“C:\Program Files\TOSHIBA\DualPointUtility\TEDTray.exe” [2003-11-12 05:19] “TFNF5”=“TFNF5.exe” [2003-11-18 04:42 C:\WINDOWS\system32\TFNF5.exe] “TPSMain”=“TPSMain.exe” [2003-12-15 20:54 C:\WINDOWS\system32\TPSMain.exe] “TFncKy”=“TFncKy.exe” [] “TosHKCW.exe”=“C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe” [2002-09-10 00:07] “SmoothView”=“C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe” [2003-12-03 21:26] “TAudEffect”=“C:\Program Files\Toshiba\TAudEffect\TAudEff.exe” [2003-12-26 01:17] “ezShieldProtector for Px”=“C:\WINDOWS\System32\ezSP_Px.exe” [2002-08-20 19:29] “Pinger”=“C:\TOSHIBA\IVP\ISM\pinger.exe” [2005-03-17 16:37] “PRONoMgr.exe”=“c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe” [2003-12-10 10:36] “dlccmon.exe”=“C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe” [2005-07-22 20:03] “WinampAgent”=“C:\Program Files\Winamp\winampa.exe” [2007-05-14 23:22] “RealTray”=“C:\Program Files\Real\RealPlayer\RealPlay.exe” [2004-01-15 00:32] “DLCCCATS”=“C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll” [2005-06-07 19:38] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2004-01-15 00:33] “Picasa Media Detector”=“C:\Program Files\Picasa2\PicasaMediaDetector.exe” [2007-06-16 00:15] “PCSuiteTrayApplication”=“C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe” [2007-06-18 15:10] “AVP”=“C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe” [2007-06-28 12:51] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “NVIEW”=“nview.dll” [2003-12-10 15:50 C:\WINDOWS\system32\nview.dll] “TOSCDSPD”=“C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe” [2003-09-05 12:24] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 08:56] “swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-07-25 18:05] “ares”=“C:\Program Files\Ares\Ares.exe” [2007-05-04 01:32] [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Nokia.PCSync”=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog “DWQueuedReporting”=“C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe” -t C:\Documents and Settings\User\Start Menu\Programs\Startup\ Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2005-03-17 14:06:14] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring] c:\WINDOWS\System32\LgNotify.dll 2003-12-17 00:49 110592 c:\WINDOWS\system32\LgNotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “appinit_dlls”=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll R1 TMEI3E;TMEI3E;C:\WINDOWS\system32\Drivers\TMEI3E.SYS R2 Tmesbs;Tmesbs32;“C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe” /Service R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys R3 TEchoCan;Toshiba Audio Effect;C:\WINDOWS\system32\DRIVERS\TEchoCan.sys S3 portio;TPM Service;C:\WINDOWS\system32\DRIVERS\NscTpmDD.sys S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys . ************************************************************************** catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-24 00:03:55 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCCCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16??? scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-10-24 0:06:37 . — E O F —]