ComboFix 08-01-16.4 - piotrek 2008-01-17 9:44:40.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.101 [GMT 1:00]
Running from: C:\Documents and Settings\piotrek\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.
2008-01-17 09:29 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-17 09:29 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-17 09:29 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-17 09:28 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-01-17 09:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-01-17 09:28 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-01-17 09:28 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-17 09:28 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-16 23:26 . 2008-01-16 23:35 <DIR> d-------- C:\VundoFix Backups
2008-01-16 23:16 . 2008-01-16 23:21 1,296 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-16 21:52 . 2008-01-16 21:52 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-01-16 21:52 . 2008-01-16 21:52 <DIR> d-------- C:\Program Files\ACD Systems
2008-01-16 21:52 . 2008-01-16 21:53 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ACD Systems
2008-01-16 21:52 . 2008-01-16 21:52 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-01-16 21:48 . 2008-01-16 21:48 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-01-16 16:53 . 2008-01-16 16:54 <DIR> d-------- C:\Documents and Settings\piotrek\Dane aplikacji\Tibia
2008-01-16 16:52 . 2008-01-16 16:52 <DIR> d-------- C:\Program Files\Tibia
2008-01-16 16:03 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 16:00 . 2008-01-17 09:30 0 --a------ C:\adware.exe
2008-01-16 15:57 . 2008-01-16 15:57 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-16 11:02 . 2008-01-16 15:49 82,882 --a------ C:\WINDOWS\system32\explorer .exe
2008-01-16 09:32 . 2008-01-16 09:32 82,882 --a------ C:\WINDOWS\system32\winamp .exe
2008-01-16 09:18 . 2008-01-16 09:18 82,882 --a------ C:\WINDOWS\system32\uaxhodqt.exe
2008-01-16 09:18 . 2008-01-16 09:18 19,711 --a------ C:\WINDOWS\system32\chpwwben.exe
2008-01-16 09:18 . 2008-01-16 09:18 19,711 --a------ C:\WINDOWS\system32\acvdzo.exe
2008-01-16 09:18 . 2008-01-16 09:18 6,696 --a------ C:\WINDOWS\system32\yxllikxi.exe
2008-01-16 09:18 . 2008-01-16 09:18 6,696 --a------ C:\WINDOWS\system32\lhccrb.exe
2008-01-16 09:00 . 2008-01-16 09:00 82,882 --a------ C:\WINDOWS\system32\dcnls.exe
2008-01-16 09:00 . 2008-01-16 09:00 19,711 --a------ C:\WINDOWS\system32\mylcn.exe
2008-01-16 09:00 . 2008-01-16 09:00 19,711 --a------ C:\WINDOWS\system32\gjtxresk.exe
2008-01-16 09:00 . 2008-01-16 09:00 6,696 --a------ C:\WINDOWS\system32\uytm.exe
2008-01-16 09:00 . 2008-01-16 09:00 6,696 --a------ C:\WINDOWS\system32\czsgd.exe
2008-01-16 08:59 . 2008-01-16 15:49 82,882 --a------ C:\WINDOWS\system32\iexplore .exe
2008-01-16 08:59 . 2008-01-16 09:32 64,816 --a------ C:\WINDOWS\system32\logon .exe
2008-01-16 08:09 . 2008-01-16 08:09 82,882 --a------ C:\WINDOWS\system32\dksmx.exe
2008-01-16 08:09 . 2008-01-16 08:09 19,711 --a------ C:\WINDOWS\system32\hnvxzdbu.exe
2008-01-16 08:09 . 2008-01-16 08:09 6,696 --a------ C:\WINDOWS\system32\wbdcmqyg.exe
2008-01-15 23:01 . 2008-01-15 23:01 82,882 --a------ C:\WINDOWS\system32\dlneuwfp.exe
2008-01-15 23:01 . 2008-01-15 23:01 19,711 --a------ C:\WINDOWS\system32\dkfksuws.exe
2008-01-15 23:01 . 2008-01-15 23:01 6,696 --a------ C:\WINDOWS\system32\jrpeupeq.exe
2008-01-15 22:02 . 2008-01-15 22:02 19,711 --a------ C:\WINDOWS\system32\xzlpyjlj.exe
2008-01-15 22:02 . 2008-01-15 22:02 6,696 --a------ C:\WINDOWS\system32\rxtr.exe
2008-01-15 22:01 . 2008-01-15 22:01 82,882 --a------ C:\WINDOWS\system32\winIogon .exe
2008-01-15 21:46 . 2008-01-15 21:46 1,158 --a------ C:\WINDOWS\mozver.dat
2008-01-15 20:06 . 2003-10-28 11:02 20,016 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-01-15 20:05 . 2008-01-16 16:06 <DIR> d-------- C:\Program Files\Winamp
2008-01-15 20:05 . 2008-01-17 09:25 192 --a------ C:\WINDOWS\winamp.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 15:06 --------- d-----w C:\Program Files\Gadu-Gadu
2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
2003-07-11 21:20 1,138,688 --sh--w C:\WINDOWS\system32\wingatey32.exe
.
- Kod: Zaznacz wszystko
<pre>
----a-w 82,882 2008-01-16 14:49:29 C:\WINDOWS\system32\explorer .exe
----a-w 82,882 2008-01-16 14:49:27 C:\WINDOWS\system32\iexplore .exe
----a-w 64,816 2008-01-16 08:32:05 C:\WINDOWS\system32\logon .exe
----a-w 82,882 2008-01-16 08:32:08 C:\WINDOWS\system32\winamp .exe
----a-w 82,882 2008-01-15 21:01:22 C:\WINDOWS\system32\winIogon .exe
</pre>
((((((((((((((((((((((((((((( snapshot@2008-01-16_16.07.19.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-16 20:53:12 61,440 ----a-r C:\WINDOWS\Installer\{271B64EE-3E1B-4381-A8FE-012390050492}\ACDSeeDesktopShortcu_FD88D5011F0A4DA4A13A6437411EE0C3.exe
+ 2008-01-16 20:53:12 61,440 ----a-r C:\WINDOWS\Installer\{271B64EE-3E1B-4381-A8FE-012390050492}\ACDSeePMShortcut_FD88D5011F0A4DA4A13A6437411EE0C3.exe
+ 2008-01-16 20:53:12 61,440 ----a-r C:\WINDOWS\Installer\{271B64EE-3E1B-4381-A8FE-012390050492}\ARPPRODUCTICON.exe
+ 2008-01-16 20:53:12 45,056 ----a-r C:\WINDOWS\Installer\{271B64EE-3E1B-4381-A8FE-012390050492}\DevDetectPMShortcut.exe
+ 2008-01-16 20:53:12 61,440 ----a-r C:\WINDOWS\Installer\{271B64EE-3E1B-4381-A8FE-012390050492}\FotoCanvasDesktopSho_FD88D5011F0A4DA4A13A6437411EE0C3.exe
+ 2008-01-16 20:53:12 61,440 ----a-r C:\WINDOWS\Installer\{271B64EE-3E1B-4381-A8FE-012390050492}\FotoCanvasProgramMen_FD88D5011F0A4DA4A13A6437411EE0C3.exe
+ 2008-01-16 20:53:12 57,344 ----a-r C:\WINDOWS\Installer\{271B64EE-3E1B-4381-A8FE-012390050492}\FotoSlateDesktopShor_FD88D5011F0A4DA4A13A6437411EE0C3.exe
+ 2008-01-16 20:53:12 57,344 ----a-r C:\WINDOWS\Installer\{271B64EE-3E1B-4381-A8FE-012390050492}\FotoSlateProgramFile_FD88D5011F0A4DA4A13A6437411EE0C3.exe
+ 2004-03-04 11:51:46 307,200 ----a-w C:\WINDOWS\system32\ACDSee.scr
- 2008-01-16 15:04:10 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NtUser.dat
+ 2008-01-17 08:44:38 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NtUser.dat
+ 2002-05-13 14:05:32 167,936 ----a-r C:\WINDOWS\system32\czs_ui.dll
+ 2002-03-20 20:01:18 45,568 ----a-w C:\WINDOWS\system32\DC210.dll
+ 2002-03-20 20:01:18 114,688 ----a-w C:\WINDOWS\system32\DC240.dll
+ 2002-03-20 20:01:06 230,400 ----a-w C:\WINDOWS\system32\DC265.dll
+ 2002-03-20 20:01:18 122,880 ----a-w C:\WINDOWS\system32\DC280.dll
+ 2002-05-13 14:05:32 168,960 ----a-r C:\WINDOWS\system32\deimg.dll
+ 2002-05-13 14:05:34 212,992 ----a-r C:\WINDOWS\system32\deImg010.dll
+ 2002-05-13 14:05:34 172,032 ----a-r C:\WINDOWS\system32\deImg110.dll
+ 2002-05-13 14:05:34 161,280 ----a-r C:\WINDOWS\system32\deimg301.dll
+ 2002-05-13 14:05:34 161,792 ----a-r C:\WINDOWS\system32\deimg401.dll
+ 2002-05-13 14:05:34 360,448 ----a-r C:\WINDOWS\system32\deImg404.dll
+ 2002-05-13 14:05:34 162,816 ----a-r C:\WINDOWS\system32\deimg602.dll
+ 2002-05-13 14:05:34 167,936 ----a-r C:\WINDOWS\system32\Deimg603.dll
+ 2002-03-20 20:01:06 6,688 ----a-w C:\WINDOWS\system32\Digita.sys
+ 2002-03-20 20:01:18 44,544 ----a-w C:\WINDOWS\system32\ekfpixaudio.dll
+ 2002-03-20 20:01:06 138,240 ----a-w C:\WINDOWS\system32\ekfpixexif.dll
+ 2002-03-20 20:01:20 4,096 ----a-w C:\WINDOWS\system32\ekfpixguid.dll
+ 2002-03-20 20:01:20 449,536 ----a-w C:\WINDOWS\system32\ekfpixio130.dll
+ 2002-03-20 20:01:20 100,352 ----a-w C:\WINDOWS\system32\ekfpixjpeg.dll
+ 2002-03-20 20:01:20 67,584 ----a-w C:\WINDOWS\system32\ekfpixpsets.dll
+ 2002-03-20 20:01:20 36,864 ----a-w C:\WINDOWS\system32\F210.dll
+ 2002-03-20 20:01:58 446,464 ----a-w C:\WINDOWS\system32\HHActiveX.dll
+ 2002-05-13 15:13:58 19,968 ----a-r C:\WINDOWS\system32\JGA1500.DLL
+ 2002-05-13 15:13:58 10,752 ----a-r C:\WINDOWS\system32\JGAA500.DLL
+ 2002-05-13 15:13:58 16,896 ----a-r C:\WINDOWS\system32\JGAD500.DLL
+ 2002-05-13 15:13:58 9,216 ----a-r C:\WINDOWS\system32\JGAP500.DLL
+ 2002-05-13 15:13:58 11,264 ----a-r C:\WINDOWS\system32\JGAR500.DLL
+ 2002-05-13 15:13:58 31,744 ----a-r C:\WINDOWS\system32\JGAU500.DLL
+ 2002-05-13 15:13:58 6,144 ----a-r C:\WINDOWS\system32\JGDR500.DLL
+ 2002-05-13 15:13:58 144,896 ----a-r C:\WINDOWS\system32\JGDW500.DLL
+ 2002-05-13 15:13:58 15,360 ----a-r C:\WINDOWS\system32\JGEA500.DLL
+ 2002-05-13 15:13:58 39,424 ----a-r C:\WINDOWS\system32\JGED500.DLL
+ 2002-05-13 15:13:58 11,264 ----a-r C:\WINDOWS\system32\JGEM500.DLL
+ 2002-05-13 15:13:58 10,752 ----a-r C:\WINDOWS\system32\JGFI500.DLL
+ 2002-05-13 15:13:58 67,072 ----a-r C:\WINDOWS\system32\JGFR500.DLL
+ 2002-05-13 15:13:58 24,576 ----a-r C:\WINDOWS\system32\JGFS500.DLL
+ 2002-05-13 15:13:58 12,800 ----a-r C:\WINDOWS\system32\JGGI500.DLL
+ 2002-05-13 15:13:58 19,456 ----a-r C:\WINDOWS\system32\JGI1500.DLL
+ 2002-05-13 15:13:58 41,984 ----a-r C:\WINDOWS\system32\JGI3500.DLL
+ 2002-05-13 15:13:58 60,416 ----a-r C:\WINDOWS\system32\JGI5500.DLL
+ 2002-05-13 15:13:58 11,264 ----a-r C:\WINDOWS\system32\JGID500.DLL
+ 2002-05-13 15:13:58 34,304 ----a-r C:\WINDOWS\system32\JGIP500.DLL
+ 2002-05-13 15:13:58 6,656 ----a-r C:\WINDOWS\system32\JGIQ500.DLL
+ 2002-05-13 15:13:58 24,064 ----a-r C:\WINDOWS\system32\JGIT500.DLL
+ 2002-05-13 15:13:58 74,240 ----a-r C:\WINDOWS\system32\JGM1500.DLL
+ 2002-05-13 15:13:58 29,696 ----a-r C:\WINDOWS\system32\JGMC500.DLL
+ 2002-05-13 15:13:58 7,168 ----a-r C:\WINDOWS\system32\JGME500.DLL
+ 2002-05-13 15:13:58 24,576 ----a-r C:\WINDOWS\system32\JGMI500.DLL
+ 2002-05-13 15:13:58 11,264 ----a-r C:\WINDOWS\system32\JGMP500.DLL
+ 2002-05-13 15:13:58 24,064 ----a-r C:\WINDOWS\system32\JGN1500.DLL
+ 2002-05-13 15:13:58 80,384 ----a-r C:\WINDOWS\system32\JGOS500.DLL
+ 2002-05-13 15:13:58 13,824 ----a-r C:\WINDOWS\system32\JGPD500.DLL
+ 2002-05-13 15:13:58 15,872 ----a-r C:\WINDOWS\system32\JGPL500.DLL
+ 2002-05-13 15:13:58 12,288 ----a-r C:\WINDOWS\system32\JGPP500.DLL
+ 2002-05-13 15:13:58 33,280 ----a-r C:\WINDOWS\system32\JGS1500.DLL
+ 2002-05-13 15:13:58 15,360 ----a-r C:\WINDOWS\system32\JGS3500.DLL
+ 2002-05-13 15:13:58 21,504 ----a-r C:\WINDOWS\system32\JGSN500.DLL
+ 2002-05-13 15:13:58 13,312 ----a-r C:\WINDOWS\system32\JGST500.DLL
+ 2002-01-05 03:48:16 974,848 ----a-w C:\WINDOWS\system32\mfc70.dll
+ 2002-01-05 03:36:38 964,608 ----a-w C:\WINDOWS\system32\mfc70u.dll
+ 2002-01-05 02:38:38 54,784 ----a-w C:\WINDOWS\system32\msvci70.dll
+ 2002-01-05 02:40:20 487,424 ----a-w C:\WINDOWS\system32\msvcp70.dll
+ 2002-01-05 02:37:28 344,064 ----a-w C:\WINDOWS\system32\msvcr70.dll
+ 2002-05-13 14:05:34 57,344 ----a-r C:\WINDOWS\system32\pscAdimg.dll
+ 2002-05-13 14:05:34 135,168 ----a-r C:\WINDOWS\system32\pscCllct.dll
+ 2002-05-13 14:05:34 462,848 ----a-r C:\WINDOWS\system32\pscCStUI.dll
+ 2002-05-13 14:05:34 331,776 ----a-r C:\WINDOWS\system32\pscDcd.dll
+ 2002-05-13 14:05:34 180,224 ----a-r C:\WINDOWS\system32\pscDevUI.dll
+ 2002-05-13 14:05:34 90,112 ----a-r C:\WINDOWS\system32\pscDvlp.dll
+ 2002-05-13 14:05:34 167,936 ----a-r C:\WINDOWS\system32\Pscl2STI.dll
+ 2002-05-13 14:05:34 180,224 ----a-r C:\WINDOWS\system32\pscll.dll
+ 2002-05-13 14:05:34 200,704 ----a-r C:\WINDOWS\system32\pscParse.dll
+ 2002-05-13 14:05:34 98,304 ----a-r C:\WINDOWS\system32\pscSetup.dll
+ 2002-05-13 14:05:36 389,120 ----a-r C:\WINDOWS\system32\psdkdll.dll
+ 2002-05-13 14:05:36 57,344 ----a-r C:\WINDOWS\system32\psdkReg.dll
+ 2002-05-13 14:05:36 102,400 ----a-r C:\WINDOWS\system32\psParse.dll
+ 2002-03-20 20:00:18 49,152 ----a-w C:\WINDOWS\system32\TransportIrCOMM.dll
+ 2002-03-20 20:00:18 49,152 ----a-w C:\WINDOWS\system32\TransportIrDA.dll
+ 2002-03-20 20:00:20 49,152 ----a-w C:\WINDOWS\system32\TransportSerial.dll
+ 2002-03-20 20:00:20 49,152 ----a-w C:\WINDOWS\system32\TransportUSB.dll
+ 2002-03-21 13:39:02 73,728 ----a-w C:\WINDOWS\system32\UNACEV2.DLL
+ 2008-01-17 08:30:08 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_414.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-10-26 18:29 13312]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-16 16:00 1077277]
"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL" [2003-10-06 13:16 49152]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-01-16 16:00 2396160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 13:16 5058560]
"nwiz"="nwiz.exe" [2003-10-06 13:16 741376 C:\WINDOWS\system32\nwiz.exe]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2008-01-16 16:00 888832]
"WinDLL (wingatey32.exe)"="C:\WINDOWS\System32\wingatey32.exe" [2003-07-11 22:20 1138688]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-16 16:00 33792]
"Device Detector"="C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe" [2003-11-26 18:54 217088]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 18:29 13312]
R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2003-07-11 22:20]
S3 GVCplDrv;GVCplDrv;C:\WINDOWS\System32\drivers\GVCplDrv.sys [2003-09-30 06:25]
*Newly Created Service* - ASWUPDSV
*Newly Created Service* - AVAST!_ANTIVIRUS
*Newly Created Service* - AVAST!_MAIL_SCANNER
*Newly Created Service* - AVAST!_WEB_SCANNER
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-17 09:45:33
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2600.0000]
-> C:\Program Files\Gadu-Gadu\ggwhook.dll
.
Completion time: 2008-01-17 9:46:32
ComboFix-quarantined-files.txt 2008-01-17 08:45:46
ComboFix2.txt 2008-01-16 15:07:46