HijackThis
Logfile of Trend Micro HijackThis v2.0.2Scan saved at 12:30:51, on 2008-05-30Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)Boot mode: NormalRunning processes:D:\WINDOWS\System32\smss.exeD:\WINDOWS\system32\winlogon.exeD:\WINDOWS\system32\services.exeD:\WINDOWS\system32\lsass.exeD:\WINDOWS\system32\svchost.exeD:\WINDOWS\System32\svchost.exeD:\Program Files\Alwil Software\Avast4\aswUpdSv.exeD:\Program Files\Alwil Software\Avast4\ashServ.exeD:\WINDOWS\system32\spoolsv.exeD:\WINDOWS\Explorer.EXED:\Program Files\Bonjour\mDNSResponder.exeD:\WINDOWS\system32\nvsvc32.exeD:\Program Files\Analog Devices\SoundMAX\SMAgent.exeD:\PROGRA~1\NEOSTR~1\CnxMon.exeD:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exeD:\PROGRA~1\NEOSTR~1\TaskbarIcon.exeD:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeD:\WINDOWS\system32\RUNDLL32.EXED:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exeD:\Program Files\Alwil Software\Avast4\ashMaiSv.exeD:\Program Files\Analog Devices\SoundMAX\Smax4.exeD:\Program Files\Alwil Software\Avast4\ashWebSv.exeD:\Program Files\Common Files\Real\Update_OB\realsched.exeD:\WINDOWS\system32\ctfmon.exeD:\Program Files\Windows Live\Messenger\MsnMsgr.ExeD:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeD:\Program Files\Gadu-Gadu\gg.exeD:\Program Files\Winamp Remote\bin\OrbTray.exeD:\PROGRA~1\NEOSTR~1\NeostradaTP.exeD:\PROGRA~1\NEOSTR~1\ComComp.exeD:\WINDOWS\system32\wuauclt.exeD:\PROGRA~1\NEOSTR~1\Watch.exeD:\Program Files\Internet Explorer\iexplore.exeD:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exeD:\Program Files\Windows Live\Messenger\usnsvc.exeD:\WINDOWS\system32\wuauclt.exeD:\Program Files\Internet Explorer\iexplore.exeD:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://www.google.pl"]http://www.google.pl[/url]R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TPR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ŁączaR3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - D:\PROGRA~1\NEOSTR~1\SEARCH~1.DLLO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [WooCnxMon] D:\PROGRA~1\NEOSTR~1\CnxMon.exeO4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "D:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /iconO4 - HKLM\..\Run: [WOOWATCH] D:\PROGRA~1\NEOSTR~1\Watch.exeO4 - HKLM\..\Run: [WOOTASKBARICON] D:\PROGRA~1\NEOSTR~1\TaskbarIcon.exeO4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exeO4 - HKLM\..\Run: [SoundMAX] "D:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /trayO4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /backgroundO4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [Gadu-Gadu] "D:\Program Files\Gadu-Gadu\gg.exe" /trayO4 - HKCU\..\Run: [Orb] "D:\Program Files\Winamp Remote\bin\OrbTray.exe" /backgroundO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exeO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [url="http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211118466624"]http://www.update.microsoft.com/windowsupd...b?1211118466624[/url]O17 - HKLM\System\CCS\Services\Tcpip\..\{E6DB18C7-916C-4A6F-9E88-418454FC3051}: NameServer = 194.204.159.1 217.98.63.164O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exeO23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - D:\Program Files\WinPcap\rpcapd.exeO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe--End of file - 6949 bytes
ComboFix
ComboFix 08-05-29.1 - User 1 2008-05-30 12:40:43.1 - NTFSx86Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.674 [GMT 2:00]Running from: D:\Documents and Settings\User 1\Moje dokumenty\@neostrada.pl\ComboFix.exe * Created a new restore point<strong class='bbc'>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED </strong>.((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-30 ))))))))))))))))))))))))))))))).2008-05-30 12:30 . 2008-05-30 12:30 <DIR> d-------- D:\Program Files\Trend Micro2008-05-30 12:19 . 2004-04-10 09:42 2,944 --a------ D:\WINDOWS\system32\mbmiodrvr.sys2008-05-30 12:18 . 2008-05-30 12:19 <DIR> d-------- D:\Program Files\Motherboard Monitor 52008-05-30 12:01 . 2008-05-30 12:01 <DIR> d-------- D:\Documents and Settings\All Users\Dane aplikacji\NVIDIA2008-05-29 14:57 . 2008-05-30 12:17 <DIR> d-------- D:\Program Files\SpeedFan2008-05-29 14:57 . 2008-05-29 14:57 45 --a------ D:\WINDOWS\system32\initdebug.nfo2008-05-29 14:55 . 2008-05-29 14:55 <DIR> d-------- D:\Program Files\Lavalys2008-05-27 19:14 . 2008-05-27 19:14 <DIR> dr-h----- D:\Documents and Settings\User 1\Dane aplikacji\SecuROM2008-05-27 18:52 . 2008-05-27 18:52 <DIR> d-------- D:\Program Files\KONAMI2008-05-27 17:50 . 2008-05-27 18:41 <DIR> d-------- D:\PES2008-05-27 17:17 . 2008-05-27 17:17 <DIR> d-------- D:\PES 20082008-05-27 14:01 . 2008-05-27 14:05 <DIR> d-------- D:\Program Files\Dziobas Rar Player2008-05-27 13:56 . 2008-05-27 13:56 <DIR> d-------- D:\Program Files\Common Files\xing shared2008-05-27 13:56 . 2008-05-27 13:56 <DIR> d-------- D:\Program Files\Common Files\Real2008-05-27 13:50 . 2008-04-14 22:51 221,184 --a------ D:\WINDOWS\system32\wmpns.dll2008-05-27 13:47 . 2008-05-27 13:47 <DIR> d-------- D:\Program Files\Winamp Remote2008-05-27 13:47 . 2008-05-27 13:47 <DIR> d-------- D:\Documents and Settings\All Users\Dane aplikacji\OrbNetworks2008-05-27 13:43 . 2008-05-27 13:47 <DIR> d-------- D:\Program Files\Winamp2008-05-27 13:43 . 2008-05-27 13:49 <DIR> d-------- D:\Documents and Settings\User 1\Dane aplikacji\Winamp2008-05-26 23:11 . 2008-05-27 14:13 754 --a------ D:\WINDOWS\WORDPAD.INI2008-05-26 21:39 . 2008-05-26 21:39 <DIR> d-------- D:\Documents and Settings\User 1\AbiSuite2008-05-26 21:38 . 2008-05-26 21:38 <DIR> d-------- D:\Program Files\AbiSuite22008-05-25 19:49 . 2008-05-25 19:49 <DIR> d-------- D:\WINDOWS\Cache2008-05-24 16:59 . 2008-05-24 16:59 <DIR> d-------- D:\Documents and Settings\User 1\Dane aplikacji\Gadu-Gadu2008-05-23 20:24 . 2008-05-23 20:24 <DIR> d-------- D:\Program Files\Gadu-Gadu2008-05-23 20:24 . 2008-05-23 20:30 <DIR> d-------- D:\Documents and Settings\User 1\Gadu-Gadu2008-05-22 18:02 . 2008-05-25 12:21 <DIR> d-------- D:\Documents and Settings\User 1\Dane aplikacji\skypePM2008-05-22 18:02 . 2008-05-22 18:02 56 --ah----- D:\WINDOWS\system32\ezsidmv.dat2008-05-22 18:01 . 2008-05-22 18:01 <DIR> d-------- D:\Program Files\Google2008-05-22 18:00 . 2008-05-25 13:05 <DIR> d-------- D:\Documents and Settings\All Users\Dane aplikacji\Skype2008-05-22 17:43 . 2008-05-22 17:43 <DIR> d-------- D:\Program Files\Teamspeak2_RC22008-05-22 17:43 . 2008-05-22 17:49 <DIR> d-------- D:\Documents and Settings\User 1\Dane aplikacji\teamspeak22008-05-22 17:43 . 2008-05-22 17:43 34,064 --a------ D:\WINDOWS\system32\lhacm.acm2008-05-22 16:36 . 2008-05-22 16:39 <DIR> d-------- D:\Program Files\FastStone Screen Capture2008-05-22 13:31 . 2008-05-22 13:31 <DIR> d-------- D:\Documents and Settings\All Users\Dane aplikacji\FLEXnet2008-05-22 13:25 . 2008-05-22 13:25 <DIR> d-------- D:\Program Files\Bonjour2008-05-22 13:16 . 2008-05-22 13:16 <DIR> d-------- D:\Program Files\Common Files\Macrovision Shared2008-05-21 16:44 . 2008-05-21 16:44 <DIR> d-------- D:\Program Files\Analog Devices2008-05-21 16:43 . 2000-03-29 08:17 5,824 --a------ D:\WINDOWS\system32\drivers\ASUSHWIO.SYS2008-05-21 16:43 . 2008-05-21 16:43 3,455 --a------ D:\WINDOWS\Ascd_tmp.ini2008-05-20 18:26 . 2005-01-22 21:12 679,936 --a------ D:\WINDOWS\system32\D3DX81ab.dll2008-05-20 15:32 . 2008-05-20 15:32 <DIR> d-------- D:\Program Files\WinPcap2008-05-20 15:32 . 2008-05-20 22:47 <DIR> d-------- D:\Program Files\WC3Banlist2008-05-20 13:54 . 2008-05-25 19:52 <DIR> d-------- D:\Program Files\Common Files\Adobe2008-05-19 21:43 . 2008-05-19 21:43 0 --a------ D:\WINDOWS\nsreg.dat2008-05-18 17:45 . 2008-05-18 18:05 139,264 --a------ D:\WINDOWS\War3Unin.exe2008-05-18 17:45 . 2008-05-18 19:13 77,705 --a------ D:\WINDOWS\War3Unin.dat2008-05-18 17:45 . 2008-05-18 18:05 2,829 --a------ D:\WINDOWS\War3Unin.pif2008-05-18 17:40 . 2008-05-28 21:01 <DIR> d-------- D:\Program Files\Warcraft III2008-05-18 17:00 . 2008-04-14 02:17 25,856 --a------ D:\WINDOWS\system32\drivers\usbprint.sys2008-05-18 17:00 . 2001-08-17 23:59 3,072 --a------ D:\WINDOWS\system32\drivers\audstub.sys2008-04-15 00:51 . 2008-04-14 23:09 483,840 --a------ D:\WINDOWS\system32\wzcsvc.dll2008-04-15 00:51 . 2008-04-14 23:09 294,912 --a------ D:\WINDOWS\system32\msh263.drv2008-04-15 00:51 . 2008-04-14 23:09 52,736 --a------ D:\WINDOWS\system32\wzcsapi.dll2008-04-15 00:51 . 2008-04-14 22:51 23,552 --a------ D:\WINDOWS\system32\wdmaud.drv2008-04-15 00:51 . 2008-04-14 22:51 23,552 --a--c--- D:\WINDOWS\system32\dllcache\wdmaud.drv2008-04-15 00:50 . 2008-04-14 23:09 55,296 --a------ D:\WINDOWS\system32\dmutil.dll2008-04-15 00:50 . 2008-04-14 23:09 49,152 --a------ D:\WINDOWS\system32\cnbjmon.dll2008-04-15 00:50 . 2008-04-14 23:09 47,616 --a------ D:\WINDOWS\system32\iyuv_32.dll2008-04-15 00:50 . 2008-04-14 23:09 35,328 --a------ D:\WINDOWS\system32\pid.dll2008-04-15 00:50 . 2008-04-14 23:09 20,992 --a------ D:\WINDOWS\system32\hid.dll2008-04-15 00:50 . 2008-04-14 23:09 16,896 --a------ D:\WINDOWS\system32\msyuv.dll2008-04-15 00:50 . 2008-04-14 23:09 15,360 --a------ D:\WINDOWS\system32\pjlmon.dll2008-04-15 00:03 . 2008-04-14 23:09 80,256 --a------ D:\WINDOWS\system32\drivers\parport.sys2008-04-15 00:03 . 2008-04-14 23:09 46,848 --a------ D:\WINDOWS\system32\drivers\p3.sys2008-04-14 23:59 . 2008-04-14 23:09 2,067,200 --a------ D:\WINDOWS\system32\ntkrnlpa.exe2008-04-14 23:47 . 2008-04-14 23:09 40,832 --a------ D:\WINDOWS\system32\drivers\crusoe.sys2008-04-14 23:30 . 2008-04-14 23:09 39,936 --a------ D:\WINDOWS\system32\drivers\processr.sys2008-04-14 23:28 . 2008-04-14 23:09 41,856 --a------ D:\WINDOWS\system32\drivers\amdk7.sys2008-04-14 23:28 . 2008-04-14 23:09 41,472 --a------ D:\WINDOWS\system32\drivers\amdk6.sys2008-04-14 23:25 . 2008-04-14 23:09 23,296 --a------ D:\WINDOWS\system32\drivers\mouclass.sys2008-04-14 23:24 . 2008-04-14 23:09 30,208 --a------ D:\WINDOWS\system32\drivers\modem.sys2008-04-14 23:16 . 2008-04-14 23:16 1,804 --a------ D:\WINDOWS\system32\Dcache.bin2008-04-14 22:56 . 2008-04-14 22:56 332,288 --a------ D:\WINDOWS\system32\netsetup.exe2008-04-14 22:56 . 2008-04-14 22:56 332,288 --a--c--- D:\WINDOWS\system32\dllcache\netsetup.exe2008-04-14 22:55 . 2008-04-14 22:55 1,202,774 --a--c--- D:\WINDOWS\system32\dllcache\sysmain.sdb2008-04-14 22:55 . 2008-04-14 22:55 785,972 --a--c--- D:\WINDOWS\system32\dllcache\apph_sp.sdb2008-04-14 22:55 . 2008-04-14 22:55 204,396 --a--c--- D:\WINDOWS\system32\dllcache\msimain.sdb2008-04-14 22:55 . 2008-04-14 22:55 85,628 --a--c--- D:\WINDOWS\system32\dllcache\apps.chm2008-04-14 22:55 . 2008-04-14 22:55 9,424 --a--c--- D:\WINDOWS\system32\dllcache\drvmain.sdb2008-04-14 22:54 . 2008-04-14 22:54 237,870 --a--c--- D:\WINDOWS\system32\dllcache\apphelp.sdb2008-04-14 22:49 . 2008-04-14 22:49 1,852,928 --a--c--- D:\WINDOWS\system32\dllcache\acgenral.dll2008-04-14 22:48 . 2008-04-14 22:48 1,449,472 --a------ D:\WINDOWS\system32\winntbbu.dll2008-04-14 22:48 . 2008-04-14 22:48 1,449,472 --a--c--- D:\WINDOWS\system32\dllcache\winntbbu.dll2008-04-14 22:48 . 2008-04-14 22:48 219,648 --a------ D:\WINDOWS\system32\sysmon.ocx2008-04-14 22:48 . 2008-04-14 22:48 219,648 --a--c--- D:\WINDOWS\system32\dllcache\sysmon.ocx2008-04-14 22:48 . 2008-04-14 22:48 61,440 --a------ D:\WINDOWS\system32\tdc.ocx2008-04-14 22:48 . 2008-04-14 22:48 61,440 --a--c--- D:\WINDOWS\system32\dllcache\tdc.ocx2008-04-14 22:48 . 2008-04-14 22:48 5,632 --a------ D:\WINDOWS\system32\wmi.dll2008-04-14 22:48 . 2008-04-14 22:48 5,632 --a--c--- D:\WINDOWS\system32\dllcache\wmi.dll2008-04-14 22:47 . 2008-04-14 22:47 103,424 --a------ D:\WINDOWS\system32\dpcdll.dll2008-04-14 22:47 . 2008-04-14 22:47 103,424 --a--c--- D:\WINDOWS\system32\dllcache\dpcdll.dll2008-04-14 22:47 . 2008-04-14 22:47 86,016 --a------ D:\WINDOWS\system32\sl_anet.acm2008-04-14 22:47 . 2008-04-14 22:47 81,920 --a------ D:\WINDOWS\system32\proctexe.ocx2008-04-14 22:47 . 2008-04-14 22:47 81,920 --a--c--- D:\WINDOWS\system32\dllcache\proctexe.ocx2008-04-14 22:47 . 2008-04-14 22:47 57,375 --a------ D:\WINDOWS\system32\odbcji32.dll2008-04-14 22:47 . 2008-04-14 22:47 57,375 --a--c--- D:\WINDOWS\system32\dllcache\odbcji32.dll2008-04-14 22:46 . 2008-04-14 22:46 110,592 --a------ D:\WINDOWS\system32\msscript.ocx2008-04-14 22:46 . 2008-04-14 22:46 110,592 --a--c--- D:\WINDOWS\system32\dllcache\msscript.ocx2008-04-14 22:43 . 2008-04-14 22:43 847,386 --a------ D:\WINDOWS\system32\msdxm.ocx2008-04-14 22:43 . 2008-04-14 22:43 847,386 --a--c--- D:\WINDOWS\system32\dllcache\msdxm.ocx2008-04-14 22:43 . 2008-04-14 22:43 177,152 --a------ D:\WINDOWS\system32\MSCTFIME.IME2008-04-14 22:43 . 2008-04-14 22:43 177,152 --a--c--- D:\WINDOWS\system32\dllcache\msctfime.ime2008-04-14 22:43 . 2008-04-14 22:43 4,126 --a------ D:\WINDOWS\system32\msdxmlc.dll2008-04-14 22:43 . 2008-04-14 22:43 4,126 --a--c--- D:\WINDOWS\system32\dllcache\msdxmlc.dll2008-04-14 22:42 . 2008-04-14 22:42 294,912 --a------ D:\WINDOWS\system32\msaud32.acm2008-04-14 22:42 . 2008-04-14 22:42 14,848 --a------ D:\WINDOWS\system32\msadp32.acm2008-04-14 22:42 . 2008-04-14 22:42 3,584 --a------ D:\WINDOWS\system32\msafd.dll2008-04-14 22:42 . 2008-04-14 22:42 3,584 --a--c--- D:\WINDOWS\system32\dllcache\msafd.dll2008-04-14 22:40 . 2008-04-14 22:40 290,816 --a------ D:\WINDOWS\system32\l3codeca.acm2008-04-14 22:36 . 2008-04-14 22:36 16,384 --a------ D:\WINDOWS\system32\imaadp32.acm2008-04-14 22:36 . 2008-04-14 22:36 3,584 --a------ D:\WINDOWS\system32\icmp.dll2008-04-14 22:36 . 2008-04-14 22:36 3,584 --a--c--- D:\WINDOWS\system32\dllcache\icmp.dll2008-04-14 22:35 . 2008-04-14 22:35 569,856 --a------ D:\WINDOWS\system32\gpedit.dll2008-04-14 22:35 . 2008-04-14 22:35 569,856 --a--c--- D:\WINDOWS\system32\dllcache\gpedit.dll2008-04-14 22:35 . 2008-04-14 22:35 545,280 --a------ D:\WINDOWS\system32\hhctrl.ocx2008-04-14 22:35 . 2008-04-14 22:35 545,280 --a--c--- D:\WINDOWS\system32\dllcache\hhctrl.ocx2008-04-14 22:35 . 2008-04-14 22:35 9,344 --a------ D:\WINDOWS\system32\framebuf.dll2008-04-14 22:35 . 2008-04-14 22:35 9,344 --a--c--- D:\WINDOWS\system32\dllcache\framebuf.dll2008-04-14 22:33 . 2008-04-14 22:33 24,064 --a------ D:\WINDOWS\system32\pidgen.dll2008-04-14 22:33 . 2008-04-14 22:33 24,064 --a--c--- D:\WINDOWS\system32\dllcache\pidgen.dll2008-04-14 22:33 . 2008-04-14 22:33 3,072 --a------ D:\WINDOWS\system32\dpnlobby.dll2008-04-14 22:33 . 2008-04-14 22:33 3,072 --a------ D:\WINDOWS\system32\dpnaddr.dll2008-04-14 22:33 . 2008-04-14 22:33 3,072 --a--c--- D:\WINDOWS\system32\dllcache\dpnlobby.dll2008-04-14 22:33 . 2008-04-14 22:33 3,072 --a--c--- D:\WINDOWS\system32\dllcache\dpnaddr.dll.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2008-05-30 10:38 --------- d-----w D:\Program Files\Neostrada TP2008-05-27 17:14 107,888 ----a-w D:\WINDOWS\system32\CmdLineExt.dll2008-05-27 17:14 --------- d--h--w D:\Program Files\InstallShield Installation Information2008-05-18 13:59 --------- d-----w D:\Program Files\Windows Live2008-05-18 13:56 --------- dcsh--w D:\Program Files\Common Files\WindowsLiveInstaller2008-05-18 13:54 --------- d-----w D:\Documents and Settings\All Users\Dane aplikacji\WLInstaller2008-05-18 13:47 --------- d-----w D:\Program Files\Common Files\InstallShield2008-05-18 13:40 --------- d-----w D:\Program Files\Alwil Software2008-05-18 13:27 --------- d-----w D:\Program Files\Thomson2008-05-18 13:26 --------- d-----w D:\Program Files\Java Web Start2008-05-18 13:07 --------- d-----w D:\Program Files\microsoft frontpage2008-05-18 13:04 --------- d-----w D:\Program Files\Usługi online2008-04-14 23:04 1,246,357 ----a-r D:\WINDOWS\SET3.tmp2008-04-14 22:56 16,825 ----a-r D:\WINDOWS\SET8.tmp2008-04-14 22:56 1,088,840 ----a-r D:\WINDOWS\SET4.tmp2008-04-14 22:50 77,312 ----a-w D:\WINDOWS\system32\usbui.dll2008-04-14 22:50 75,776 ----a-w D:\WINDOWS\system32\storprop.dll2008-04-14 21:46 5,504 ----a-w D:\WINDOWS\system32\drivers\intelide.sys2008-04-14 21:35 58,880 ----a-w D:\WINDOWS\system32\drivers\redbook.sys2008-04-14 20:52 92,424 ----a-w D:\WINDOWS\system32\rdpdd.dll2008-04-14 20:52 87,176 ----a-w D:\WINDOWS\system32\rdpwsx.dll2008-04-14 20:52 40,840 ----a-w D:\WINDOWS\system32\drivers\termdd.sys2008-04-14 20:52 21,896 ----a-w D:\WINDOWS\system32\drivers\tdtcp.sys2008-04-14 20:52 139,656 ----a-w D:\WINDOWS\system32\drivers\rdpwd.sys2008-04-14 20:52 12,168 ----a-w D:\WINDOWS\system32\tsddd.dll2008-04-14 20:52 12,040 ----a-w D:\WINDOWS\system32\drivers\tdpipe.sys2008-04-14 20:50 999,936 ----a-w D:\WINDOWS\system32\syssetup.dll2008-04-14 20:49 98,304 ----a-w D:\WINDOWS\system32\actxprxy.dll2008-04-14 20:39 7,680 ----a-w D:\WINDOWS\system32\kbdsmsno.dll2008-04-14 20:04 73,472 ----a-w D:\WINDOWS\system32\drivers\sr.sys2008-04-14 19:45 49,664 ----a-w D:\WINDOWS\system32\inetres.dll2008-04-14 00:06 42,368 ----a-w D:\WINDOWS\system32\drivers\AGP440.SYS2008-04-13 22:49 146,048 ----a-w D:\WINDOWS\system32\drivers\portcls.sys2008-04-13 22:47 83,072 ----a-w D:\WINDOWS\system32\drivers\wdmaud.sys2008-04-13 22:45 60,800 ----a-w D:\WINDOWS\system32\drivers\sysaudio.sys2008-04-13 22:27 41,472 ----a-w D:\WINDOWS\system32\drivers\raspppoe.sys2008-04-13 22:27 40,576 ----a-w D:\WINDOWS\system32\drivers\ndproxy.sys2008-04-13 22:27 34,560 ----a-w D:\WINDOWS\system32\drivers\wanarp.sys2008-04-13 22:27 20,864 ----a-w D:\WINDOWS\system32\drivers\ipinip.sys2008-04-13 22:27 152,832 ----a-w D:\WINDOWS\system32\drivers\ipnat.sys2008-04-13 22:27 14,336 ----a-w D:\WINDOWS\system32\drivers\asyncmac.sys2008-04-13 22:27 10,112 ----a-w D:\WINDOWS\system32\drivers\ndistapi.sys2008-04-13 22:26 69,120 ----a-w D:\WINDOWS\system32\drivers\psched.sys2008-04-13 22:26 35,072 ----a-w D:\WINDOWS\system32\drivers\msgpc.sys2008-04-13 22:26 34,688 ----a-w D:\WINDOWS\system32\drivers\netbios.sys2008-04-13 22:26 30,592 ----a-w D:\WINDOWS\system32\drivers\rndismp.sys2008-04-13 22:26 12,800 ----a-w D:\WINDOWS\system32\drivers\usb8023.sys2008-04-13 22:24 11,264 ----a-w D:\WINDOWS\system32\drivers\irenum.sys2008-04-13 22:15 60,160 ----a-w D:\WINDOWS\system32\drivers\drmk.sys2008-04-13 22:15 6,272 ----a-w D:\WINDOWS\system32\drivers\splitter.sys2008-04-13 22:15 56,576 ----a-w D:\WINDOWS\system32\drivers\swmidi.sys2008-04-13 22:15 52,864 ----a-w D:\WINDOWS\system32\drivers\DMusic.sys2008-04-13 22:15 2,944 ----a-w D:\WINDOWS\system32\drivers\drmkaud.sys2008-04-13 22:15 172,416 ----a-w D:\WINDOWS\system32\drivers\kmixer.sys2008-04-13 22:09 7,552 ----a-w D:\WINDOWS\system32\drivers\MSKSSRV.sys2008-04-13 22:09 5,376 ----a-w D:\WINDOWS\system32\drivers\MSPCLOCK.sys2008-04-13 22:09 4,992 ----a-w D:\WINDOWS\system32\drivers\MSPQM.sys2008-04-13 22:03 129,792 ----a-w D:\WINDOWS\system32\drivers\fltMgr.sys2008-04-13 22:02 196,224 ----a-w D:\WINDOWS\system32\drivers\rdpdr.sys2008-04-13 20:09 142,592 ----a-w D:\WINDOWS\system32\drivers\aec.sys.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2008-04-14 22:51 15360]"MsnMsgr"="D:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-24 12:43 68856]"Gadu-Gadu"="D:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 12:04 2127296]"Orb"="D:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 03:54 507904][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"WooCnxMon"="D:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 18:07 24576]"SpeedTouch USB Diagnostics"="D:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38 866816]"WOOWATCH"="D:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 18:07 20480]"WOOTASKBARICON"="D:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 18:07 53248]"avast!"="D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]"NvCplDaemon"="D:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]"nwiz"="nwiz.exe" [2006-08-11 21:43 1519616 D:\WINDOWS\system32\nwiz.exe]"NvMediaCenter"="D:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 21:43 86016]"SoundMAXPnP"="D:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 16:28 790528]"TkBellExe"="D:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-27 13:56 185896][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 22:51 15360][HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\system32\\sessmgr.exe"="D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="D:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="D:\\Program Files\\Bonjour\\mDNSResponder.exe"="D:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="D:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="D:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="D:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"="D:\\Program Files\\Gadu-Gadu\\gg.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"6112:TCP"= 6112:TCP:Warcraft IIIR1 aswSP;avast! Self Protection;D:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]R2 aswFsBlk;aswFsBlk;D:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]S3 EverestDriver;Lavalys EVEREST Kernel Driver;D:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt [2005-08-18 00:00]S3 NPF;NetGroup Packet Filter Driver;D:\WINDOWS\system32\drivers\npf.sys [2005-08-02 23:10]*Newly Created Service* - CATCHME.**************************************************************************catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url="http://www.gmer.net"]http://www.gmer.net[/url]Rootkit scan 2008-05-30 12:43:18Windows 5.1.2600 Dodatek Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\EverestDriver]"ImagePath"="\??\D:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt".Completion time: 2008-05-30 12:44:35ComboFix-quarantined-files.txt 2008-05-30 10:44:27Pre-Run: 32,371,056,640 bajtów wolnychPost-Run: 32,649,875,456 bajtów wolnych257