ComboFix 07-08-17.2 - "Administrator" 2007-08-22 23:25:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.613 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((( Files Created from 2007-07-22 to 2007-08-22 )))))))))))))))))))))))))))))))
2007-08-22 23:24 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-22 18:00 <DIR> d-------- C:\Program Files\Spyware Terminator
2007-08-22 17:48 <DIR> d-------- C:\Program Files\RegCleaner
2007-08-22 16:43 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-08-22 15:46 <DIR> d-------- C:\Program Files\SkanerOnline
2007-08-22 14:43 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-21 16:42 <DIR> d-------- C:\WINDOWS\system32\Lang
2007-08-19 13:05 <DIR> d-------- C:\Program Files\SubEdit-Player
2007-08-18 10:12 <DIR> d-------- C:\WINDOWS\RegisteredPackages
2007-08-16 23:24 <DIR> d-------- C:\Program Files\Tlen.pl
2007-08-16 23:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\DANEAP~1\Tlen.pl
2007-08-05 21:11 <DIR> d-------- C:\Program Files\NokiaFREE Unlock Codes Calculator
2007-08-05 13:23 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-08-05 10:56 384 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000001-00000000-00000007-00001102-00000004-20021102}.dat
2007-08-05 10:56 384 --a------ C:\WINDOWS\system32\DVCState-{00000001-00000000-00000007-00001102-00000004-20021102}.dat
2007-08-05 10:33 90,112 --------- C:\WINDOWS\Updreg.EXE
2007-08-05 10:33 84,992 --------- C:\WINDOWS\system32\SFCVRT32.DLL
2007-08-05 10:33 82,432 --------- C:\WINDOWS\system32\CTWFLT32.DLL
2007-08-05 10:33 54,784 --------- C:\WINDOWS\system32\INETWH32.DLL
2007-08-05 10:33 53,552 --------- C:\WINDOWS\CTCCW.DLL
2007-08-05 10:33 49,152 --a------ C:\WINDOWS\CTDCRES.DLL
2007-08-05 10:33 26,768 --------- C:\WINDOWS\system32\CTL3D.DLL
2007-08-05 10:33 24,976 --------- C:\WINDOWS\CTRES.DLL
2007-08-05 10:33 20,480 --a------ C:\WINDOWS\INRES.DLL
2007-08-05 10:33 1,247,400 --------- C:\WINDOWS\system32\CTAA1.DAT
2007-08-05 10:33 1,048,576 --------- C:\WINDOWS\system32\SFMAN.DAT
2007-08-05 10:33 <DIR> d-------- C:\WINDOWS\system32\Defaults
2007-08-05 10:32 94,208 --a------ C:\WINDOWS\DEVREG.DLL
2007-08-05 10:32 904,496 --a------ C:\WINDOWS\system32\drivers\ha10kx2k.sys
2007-08-05 10:32 77,824 --a------ C:\WINDOWS\system32\EAXAC3.DLL
2007-08-05 10:32 69,632 --a------ C:\WINDOWS\system32\ctcoinst.dll
2007-08-05 10:32 645,392 --a------ C:\WINDOWS\system32\drivers\ctac32k.sys
2007-08-05 10:32 606,208 --a------ C:\WINDOWS\system32\ctsblfx.dll
2007-08-05 10:32 6,096 --a------ C:\WINDOWS\system32\drivers\ctprxy2k.sys
2007-08-05 10:32 585,728 --a------ C:\WINDOWS\system32\ctaudfx.dll
2007-08-05 10:32 57,344 --a------ C:\WINDOWS\system32\CTAGENT.DLL
2007-08-05 10:32 53,932 --a------ C:\WINDOWS\system32\ctdaught.dat
2007-08-05 10:32 53,248 --a------ C:\WINDOWS\system32\KILLAPPS.EXE
2007-08-05 10:32 49,152 --a------ C:\WINDOWS\MIDIDEF.EXE
2007-08-05 10:32 466,944 --a------ C:\WINDOWS\system32\CTDC0001.DLL
2007-08-05 10:32 45,056 --a------ C:\WINDOWS\system32\CTSPKHLP.DLL
2007-08-05 10:32 366,160 --a------ C:\WINDOWS\system32\drivers\ctaud2k.sys
2007-08-05 10:32 36,864 --a------ C:\WINDOWS\system32\REGPLIB.EXE
2007-08-05 10:32 36,864 --a------ C:\WINDOWS\system32\CTEMUPIA.DLL
2007-08-05 10:32 327,680 --a------ C:\WINDOWS\system32\CTDC0000.DLL
2007-08-05 10:32 298,971 --a------ C:\WINDOWS\system32\ctstatic.dat
2007-08-05 10:32 28,672 --a------ C:\WINDOWS\system32\CTMMEP.DLL
2007-08-05 10:32 264,466 --a------ C:\WINDOWS\system32\ctsbas2w.dat
2007-08-05 10:32 24,576 --a------ C:\WINDOWS\system32\CTHELPER.EXE
2007-08-05 10:32 230,201 --a------ C:\WINDOWS\system32\CTSBASW.DAT
2007-08-05 10:32 217,272 --a------ C:\WINDOWS\system32\ctdlang.dat
2007-08-05 10:32 20,480 --a------ C:\WINDOWS\system32\ENSDEF.EXE
2007-08-05 10:32 184,320 --a------ C:\WINDOWS\PSCONV.EXE
2007-08-05 10:32 184 --a------ C:\WINDOWS\system32\e000003.dat
2007-08-05 10:32 180,224 --a------ C:\WINDOWS\READREG.EXE
2007-08-05 10:32 159,744 --a------ C:\WINDOWS\system32\CTOSUSER.DLL
2007-08-05 10:32 148,432 --a------ C:\WINDOWS\system32\drivers\haP16v2k.sys
2007-08-05 10:32 145,488 --a------ C:\WINDOWS\system32\drivers\emupia2k.sys
2007-08-05 10:32 143,360 --a------ C:\WINDOWS\system32\ctdvinst.dll
2007-08-05 10:32 140,643 --a------ C:\WINDOWS\system32\ctbas2w.dat
2007-08-05 10:32 139,264 --a------ C:\WINDOWS\system32\CTDCIFCE.DLL
2007-08-05 10:32 126,976 --a------ C:\WINDOWS\system32\CTASIO.DLL
2007-08-05 10:32 12,160 --a------ C:\WINDOWS\system32\drivers\CTGAME.SYS
2007-08-05 10:32 118,784 --a------ C:\WINDOWS\system32\CTSCAL.DLL
2007-08-05 10:32 114,688 --a------ C:\WINDOWS\system32\PIAPROXY.DLL
2007-08-05 10:32 114,688 --a------ C:\WINDOWS\system32\commonfx.dll
2007-08-05 10:32 112,411 --a------ C:\WINDOWS\system32\CTBASICW.DAT
2007-08-05 10:32 110,592 --a------ C:\WINDOWS\system32\CTDPROXY.DLL
2007-08-05 10:32 106,496 --a------ C:\WINDOWS\system32\CTTHXCAL.DLL
2007-08-05 10:31 77,824 --a------ C:\WINDOWS\system32\ctdvda32.dll
2007-08-05 10:31 12,288 --a------ C:\WINDOWS\system32\AHQCpURes.dll
2007-08-05 10:30 62,976 --a------ C:\WINDOWS\system32\CTDetres.dll
2007-08-05 10:30 44,032 --a------ C:\WINDOWS\system32\CTSVCCDA.EXE
2007-08-05 10:30 331,776 --------- C:\WINDOWS\system32\CTMEDENG.DLL
2007-08-05 10:30 25,088 --a------ C:\WINDOWS\system32\CTSVCCTL.EXE
2007-08-05 10:30 <DIR> d-------- C:\WINDOWS\system32\Win9X
2007-08-05 10:29 24,576 --a------ C:\WINDOWS\system32\CTMERes.DLL
2007-08-05 10:22 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-08-05 10:11 184 --a------ C:\WINDOWS\system32\e000002.dat
2007-08-05 09:49 31,744 --a------ C:\WINDOWS\system32\drivers\ZDPSp50a64.sys
2007-08-05 09:49 29,184 --a------ C:\WINDOWS\system32\drivers\BRGSp50a64.sys
2007-08-05 09:49 20,608 --a------ C:\WINDOWS\system32\drivers\BRGSp50.sys
2007-08-05 09:49 17,664 --a------ C:\WINDOWS\system32\drivers\ZDPSp50.sys
2007-08-05 09:49 <DIR> d-------- C:\Program Files\SAGEM WiFi manager
2007-08-05 09:49 <DIR> d-------- C:\Program Files\SAGEM
2007-08-05 09:48 493,440 --a------ C:\WINDOWS\system32\drivers\WlanBZ64.SYS
2007-08-05 09:48 402,432 --a------ C:\WINDOWS\system32\drivers\WlanBZXP.sys
2007-08-05 09:22 82,432 -ra------ C:\WINDOWS\system32\MSXML4r.dll
2007-08-05 09:22 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2007-08-05 09:22 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2007-08-05 09:22 44,544 -ra------ C:\WINDOWS\system32\MSXML4a.dll
2007-08-05 09:22 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2007-08-05 09:22 <DIR> d-------- C:\Program Files\HP
2007-08-05 09:22 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-07-28 15:55 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-07-22 14:19 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-07-22 14:19 5,120 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-07-22 14:19 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-22 14:19 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-07-22 14:19 1,415,680 --a------ C:\WINDOWS\system32\WMV9VCM.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-22 22:29 --------- d-------- C:\DOCUME~1\ADMINI~1\DANEAP~1\Skype
2007-08-22 21:45 --------- d-------- C:\Program Files\eMule
2007-08-19 01:48 --------- d-------- C:\Program Files\Winamp
2007-08-05 10:33 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-05 10:33 --------- d-------- C:\Program Files\Creative
2007-08-05 10:33 --------- d-------- C:\DOCUME~1\ADMINI~1\DANEAP~1\Creative
2007-08-05 10:16 --------- d-------- C:\Program Files\Gadu-Gadu
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-28 00:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-28 00:02 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-28 00:02 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-28 00:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 23:59 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 23:58 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 23:57 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-07-17 22:26 --------- d-------- C:\Program Files\Common Files\snp2std
2007-07-05 19:03 1714 --ah----- C:\coolbits_forceware.reg
2007-07-05 19:00 --------- d-------- C:\Program Files\Common Files\SpeechEngines
2007-07-05 19:00 --------- d-------- C:\Program Files\Common Files\ODBC
2007-07-05 18:55 --------- d-------- C:\Program Files\Realtek Sound Manager
2007-07-05 18:55 --------- d-------- C:\Program Files\AvRack
2007-07-05 18:33 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-07-05 18:26 --------- d-------- C:\Program Files\Skype
2007-07-05 18:26 --------- d-------- C:\Program Files\MarBit
2007-07-05 18:26 --------- d-------- C:\Program Files\IrfanView
2007-07-05 18:26 --------- d-------- C:\Program Files\Common Files\Skype
2007-07-05 18:26 --------- d-------- C:\Program Files\AIDA32 - Enterprise System Information
2007-07-05 18:23 --------- d-------- C:\Program Files\MozBackup
2007-07-05 18:22 --------- d-------- C:\Program Files\Alwil Software
2007-07-05 18:21 --------- d-------- C:\Program Files\Microsoft.NET
2007-07-05 18:18 --------- d-------- C:\Program Files\Microsoft Works
2007-07-05 18:02 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-07-05 18:02 2426 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2007-07-05 17:59 --------- d-------- C:\Program Files\Messenger
2007-07-05 17:34 0 -rahs---- C:\MSDOS.SYS
2007-07-05 17:34 0 -rahs---- C:\IO.SYS
2007-07-05 17:34 0 --a------ C:\CONFIG.SYS
2007-07-05 17:34 0 --a------ C:\AUTOEXEC.BAT
2007-07-05 17:34 --------- d-------- C:\Program Files\microsoft frontpage
2007-07-05 17:33 --------- d--h----- C:\Program Files\WindowsUpdate
2007-07-05 17:32 --------- d-------- C:\Program Files\Movie Maker
2007-07-05 17:32 --------- d-------- C:\Program Files\Common Files\MSSoap
2007-07-05 17:30 --------- d-------- C:\Program Files\Windows NT
2007-07-05 17:30 --------- d-------- C:\Program Files\MSN Gaming Zone
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 15:23 1034752 --a------ C:\WINDOWS\explorer.exe
--------- C:\Program Files\Usługi online
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 17:22]
"nwiz"="nwiz.exe" [2006-06-01 17:22 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 17:22 C:\WINDOWS\system32\nvmctray.dll]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 12:20 C:\WINDOWS\SOUNDMAN.EXE]
"NVRaidService"="C:\WINDOWS\system32\nvraidservice.exe" [2004-09-02 09:25]
"FixCamera"="C:\WINDOWS\FixCamera.exe" [2005-12-06 13:08]
"tsnp2std"="C:\WINDOWS\tsnp2std.exe" [2006-01-06 17:39]
"snp2std"="C:\WINDOWS\vsnp2std.exe" [2006-01-06 13:57]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 17:46]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43]
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 01:00]
"CTHelper"="CTHELPER.EXE" [2003-10-06 08:57 C:\WINDOWS\system32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2006-11-14 11:12]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-01-12 13:57]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2006-09-14 16:15]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 14:44:06]
Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk - C:\Program Files\SAGEM WiFi manager\WLANUTL.exe [2007-08-05 09:49:48]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
R2 PfDetNT;PfDetNT;\??\C:\WINDOWS\system32\drivers\PfModNT.sys
R3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys
R3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys
S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\C:\WINDOWS\system32\ZDCndis5.SYS
S3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\ZDPNDIS5.SYS
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-22 23:25:46
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-22 23:26:11
--- E O F ---