((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Program Files\internet optimizer C:\WINDOWS\system32\msxml3a.dll ((((((((((((((((((((((((( Files Created from 2007-05-24 to 2007-06-24 ))))))))))))))))))))))))))))))) 2007-06-24 14:19 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-24 14:15 2,220 --a------ C:\WINDOWS\system32\tmp.reg 2007-06-24 14:14 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-06-24 14:14 524,288 --ah----- C:\DOCUME~1\ADMINI~1.SER\NTUSER.DAT 2007-06-24 14:14 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2007-06-24 14:14 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2007-06-24 14:14 2007-06-24 14:14 2007-06-24 14:14 2007-06-24 14:14 2007-06-24 14:14 2007-06-24 14:14 2007-06-24 14:14 2007-06-23 15:53 2007-06-23 15:52 2007-06-23 15:42 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-06-23 15:39 9,728 --------- C:\WINDOWS\system32\proxycfg.exe 2007-06-23 15:39 60,928 --------- C:\WINDOWS\system32\logman.exe 2007-06-23 15:38 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys 2007-06-23 15:38 88,064 --------- C:\WINDOWS\system32\p2pnetsh.dll 2007-06-23 15:38 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll 2007-06-23 15:38 86,016 --------- C:\WINDOWS\system32\p2pgasvc.dll 2007-06-23 15:38 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll 2007-06-23 15:38 81,920 --------- C:\WINDOWS\system32\ieencode.dll 2007-06-23 15:38 81,408 --------- C:\WINDOWS\system32\wscsvc.dll 2007-06-23 15:38 8,192 --------- C:\WINDOWS\system32\smbinst.exe 2007-06-23 15:38 78,464 --------- C:\WINDOWS\system32\drivers\usbvideo.sys 2007-06-23 15:38 75,776 --------- C:\WINDOWS\system32\strmfilt.dll 2007-06-23 15:38 73,832 --------- C:\WINDOWS\system32\slcoinst.dll 2007-06-23 15:38 73,796 --------- C:\WINDOWS\system32\slserv.exe 2007-06-23 15:38 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys 2007-06-23 15:38 71,680 --------- C:\WINDOWS\system32\blastcln.exe 2007-06-23 15:38 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys 2007-06-23 15:38 7,680 --------- C:\WINDOWS\system32\kbdsmsno.dll 2007-06-23 15:38 7,680 --------- C:\WINDOWS\system32\kbdsmsfi.dll 2007-06-23 15:38 7,168 --------- C:\WINDOWS\system32\kbdukx.dll 2007-06-23 15:38 7,168 --------- C:\WINDOWS\system32\kbdno1.dll 2007-06-23 15:38 7,168 --------- C:\WINDOWS\system32\kbdfi1.dll 2007-06-23 15:38 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys 2007-06-23 15:38 67,584 --------- C:\WINDOWS\system32\drivers\sdbus.sys 2007-06-23 15:38 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys 2007-06-23 15:38 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys 2007-06-23 15:38 60,416 --------- C:\WINDOWS\system32\fwcfg.dll 2007-06-23 15:38 6,656 --------- C:\WINDOWS\system32\kbdinmal.dll 2007-06-23 15:38 6,656 --------- C:\WINDOWS\system32\kbdinben.dll 2007-06-23 15:38 6,144 --------- C:\WINDOWS\system32\kbdmlt48.dll 2007-06-23 15:38 6,144 --------- C:\WINDOWS\system32\kbdmlt47.dll 2007-06-23 15:38 6,144 --------- C:\WINDOWS\system32\kbdinbe1.dll 2007-06-23 15:38 6,016 --------- C:\WINDOWS\system32\drivers\smbali.sys 2007-06-23 15:38 59,648 --------- C:\WINDOWS\system32\drivers\rfcomm.sys 2007-06-23 15:38 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys 2007-06-23 15:38 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys 2007-06-23 15:38 526,848 --------- C:\WINDOWS\system32\p2psvc.dll 2007-06-23 15:38 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys 2007-06-23 15:38 516,768 --------- C:\WINDOWS\system32\ativvaxx.dll 2007-06-23 15:38 50,688 --------- C:\WINDOWS\system32\btpanui.dll 2007-06-23 15:38 50,176 --------- C:\WINDOWS\system32\xmlprovi.dll 2007-06-23 15:38 5,632 --------- C:\WINDOWS\system32\kbdmaori.dll 2007-06-23 15:38 49,152 --------- C:\WINDOWS\system32\powercfg.exe 2007-06-23 15:38 48,640 --------- C:\WINDOWS\system32\pnrpnsp.dll 2007-06-23 15:38 46,464 --------- C:\WINDOWS\system32\drivers\gagp30kx.sys 2007-06-23 15:38 452,736 --------- C:\WINDOWS\system32\drivers\mtxparhm.sys 2007-06-23 15:38 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys 2007-06-23 15:38 44,672 --------- C:\WINDOWS\system32\drivers\uagp35.sys 2007-06-23 15:38 44,032 --------- C:\WINDOWS\system32\twext.dll 2007-06-23 15:38 43,008 --------- C:\WINDOWS\system32\drivers\amdagp.sys 2007-06-23 15:38 42,752 --------- C:\WINDOWS\system32\drivers\alim1541.sys 2007-06-23 15:38 42,368 --------- C:\WINDOWS\system32\drivers\agp440.sys 2007-06-23 15:38 42,240 --------- C:\WINDOWS\system32\drivers\viaagp.sys 2007-06-23 15:38 41,088 --------- C:\WINDOWS\system32\drivers\sisagp.sys 2007-06-23 15:38 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys 2007-06-23 15:38 40,320 --------- C:\WINDOWS\system32\drivers\intelppm.sys 2007-06-23 15:38 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll 2007-06-23 15:38 397,056 --------- C:\WINDOWS\system32\s3gnb.dll 2007-06-23 15:38 384,512 --------- C:\WINDOWS\system32\mp4sdmod.dll 2007-06-23 15:38 38,016 --------- C:\WINDOWS\system32\drivers\bthmodem.sys 2007-06-23 15:38 377,984 --------- C:\WINDOWS\system32\ati2dvaa.dll 2007-06-23 15:38 36,463 --------- C:\WINDOWS\system32\drivers\ati1tuxx.sys 2007-06-23 15:38 35,456 --------- C:\WINDOWS\system32\drivers\bthprint.sys 2007-06-23 15:38 34,735 --------- C:\WINDOWS\system32\drivers\ati1xsxx.sys 2007-06-23 15:38 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys 2007-06-23 15:38 32,866 --------- C:\WINDOWS\system32\slrundll.exe 2007-06-23 15:38 32,866 --------- C:\WINDOWS\slrundll.exe 2007-06-23 15:38 32,768 --------- C:\WINDOWS\system32\ativtmxx.dll 2007-06-23 15:38 32,285 --------- C:\WINDOWS\system32\hsfcisp2.dll 2007-06-23 15:38 312,320 --------- C:\WINDOWS\system32\p2pgraph.dll 2007-06-23 15:38 310,272 --------- C:\WINDOWS\system32\mp43dmod.dll 2007-06-23 15:38 31,744 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys 2007-06-23 15:38 30,671 --------- C:\WINDOWS\system32\drivers\ati1raxx.sys 2007-06-23 15:38 30,208 --------- C:\WINDOWS\system32\bthserv.dll 2007-06-23 15:38 30,080 --------- C:\WINDOWS\system32\drivers\rndismpx.sys 2007-06-23 15:38 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll 2007-06-23 15:38 3,901 --------- C:\WINDOWS\system32\drivers\siint5.dll 2007-06-23 15:38 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll 2007-06-23 15:38 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll 2007-06-23 15:38 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll 2007-06-23 15:38 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll 2007-06-23 15:38 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll 2007-06-23 15:38 29,455 --------- C:\WINDOWS\system32\drivers\ati1xbxx.sys 2007-06-23 15:38 29,184 --------- C:\WINDOWS\system32\sdhcinst.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-23 13:56:46 507,298 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-06-23 13:56:45 97,134 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-06-23 13:51:56 -------- d-----w C:\Program Files\Messenger 2007-06-23 13:51:10 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd8381.sys 2007-06-23 13:38:30 -------- d-----w C:\Program Files\Movie Maker 2007-06-23 13:32:44 -------- d-----w C:\Program Files\Windows NT 2007-06-20 16:04:09 -------- d-----w C:\Program Files\Kaspersky Lab ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {00000010-6F7D-442C-93E3-4A4827C2E4C8}=C:\WINDOWS\nem220.dll [] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 13:02] {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4}=c:\program files\180searchassistant\saishook.dll [] {52D06F97-5511-43FA-8FDA-C481864FD26E}=C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll [2007-02-03 22:22] {5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\system32\dla\tfswshx.dll [2003-02-07 01:03] {A3FDD654-A057-4971-9844-4ED8E67DBBB8}=C:\Program Files\SideFind\sfbho.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “nwiz”=“nwiz.exe” [2004-03-24 11:04 C:\WINDOWS\system32\nwiz.exe] “IST Service”=“C:\Program Files\ISTsvc\istsvc.exe” [] “VersaLaser”=“C:\Program Files\ULS\VersaLaser.exe” [2005-06-29 22:55] “TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [2006-05-03 12:57] “PhilipsDM”=“C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe” [2006-09-28 10:33] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [2004-08-04 00:44] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices] “Compaq Service Drivers”=winsvc32.exe [HKEY_USERS.default\software\microsoft\windows\currentversion\runservices] “Compaq Service Drivers”=winsvc32.exe [HKEY_USERS.default\software\microsoft\windows\currentversion\run] “Compaq Service Drivers”=winsvc32.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] “{54645654-2225-4455-44A1-9F4543D34545}”=“C:\WINDOWS\System32\vbsys2.dll” [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Repair Registry Pro] C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe -s [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Resume copy] copyfstq.exe /startup *Newly Created Service* - OSE *Newly Created Service* - VERSALDR ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-24 14:21:19 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … cmd.exe [1492] scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-24 14:21:44 C:\ComboFix-quarantined-files.txt … 2007-06-24 14:21 — E O F —