ComboFix 07-07-30.2 - “Komputer” 2007-07-30 10:11:41.1 [GMT 2:00] - NTFS Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.Prawda * Created a new restore point ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Program Files\myglobalsearch C:\Program Files\myglobalsearch\bar\2.bin\M9FFXTBR.JAR C:\Program Files\myglobalsearch\bar\2.bin\M9FFXTBR.MANIFEST C:\Program Files\myglobalsearch\bar\2.bin\M9NTSTBR.JAR C:\Program Files\myglobalsearch\bar\2.bin\M9NTSTBR.MANIFEST C:\Program Files\myglobalsearch\bar\2.bin\M9PLUGIN.DLL C:\Program Files\myglobalsearch\bar\2.bin\MGSBAR.DLL C:\Program Files\myglobalsearch\bar\2.bin\NPMYGLSH.DLL C:\Program Files\myglobalsearch\bar\Cache\02201C8A C:\Program Files\myglobalsearch\bar\Cache\022020E0 C:\Program Files\myglobalsearch\bar\Cache\022022A5.bin C:\Program Files\myglobalsearch\bar\Cache\0220269C.bin C:\Program Files\myglobalsearch\bar\Cache\02202861.bin C:\Program Files\myglobalsearch\bar\Cache\files.ini C:\Program Files\myglobalsearch\bar\History\search C:\Program Files\myglobalsearch\bar\Settings\prevcfg.htm ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_WINIO ((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-30 ))))))))))))))))))))))))))))))) 2007-07-30 10:11 51,200 --a------ C:\SUPERXP\nircmd.exe 2007-07-27 01:10 2007-07-23 21:06 66,872 --a------ C:\SUPERXP\system32\PnkBstrA.exe 2007-07-23 21:06 22,328 --a------ C:\SUPERXP\system32\drivers\PnkBstrK.sys 2007-07-23 21:06 103,736 --a------ C:\SUPERXP\system32\PnkBstrB.exe 2007-07-23 20:02 2007-07-23 19:55 2007-07-23 16:05 2007-07-17 00:57 2007-07-10 14:16 2007-07-07 18:53 32,592 --a------ C:\SUPERXP\system32\msonpmon.dll 2007-07-07 18:49 2007-07-07 18:49 2007-07-07 18:47 2007-07-07 18:38 2007-06-28 12:27 31,616 --a------ C:\SUPERXP\system32\drivers\usbccgp.sys 2007-06-28 12:25 8,704 --a------ C:\SUPERXP\system32\drivers\ggsemc.sys 2007-06-28 11:39 2007-06-28 11:38 2007-06-28 11:38 2007-06-28 11:38 2007-06-28 11:38 2007-06-28 11:38 2007-06-28 11:33 94,064 --a------ C:\SUPERXP\system32\drivers\w810mdm.sys 2007-06-28 11:33 85,408 --a------ C:\SUPERXP\system32\drivers\w810mgmt.sys 2007-06-28 11:33 83,344 --a------ C:\SUPERXP\system32\drivers\w810obex.sys 2007-06-28 11:33 8,336 --a------ C:\SUPERXP\system32\drivers\w810mdfl.sys 2007-06-28 11:33 6,176 --a------ C:\SUPERXP\system32\drivers\w810cmnt.sys 2007-06-28 11:33 6,176 --a------ C:\SUPERXP\system32\drivers\w810cm.sys 2007-06-28 11:33 6,144 --a------ C:\SUPERXP\system32\drivers\k750cm.sys 2007-06-28 11:33 5,744 --a------ C:\SUPERXP\system32\drivers\k750wh.sys 2007-06-28 11:25 2007-06-28 11:19 58,288 -ra------ C:\SUPERXP\system32\drivers\w810bus.sys 2007-06-28 11:19 5,808 -ra------ C:\SUPERXP\system32\drivers\w810whnt.sys 2007-06-28 11:19 5,808 -ra------ C:\SUPERXP\system32\drivers\w810wh.sys 2007-06-25 22:50 2007-06-25 22:45 2007-06-13 15:08 2007-06-05 21:54 520,192 --------- C:\SUPERXP\system32\ati2sgag.exe 2007-06-05 21:35 2007-06-05 02:10 2007-06-03 03:33 68,888 --a------ C:\SUPERXP\system32\xinput1_3.dll 2007-06-03 03:33 62,744 --a------ C:\SUPERXP\system32\xinput1_2.dll 2007-06-03 03:33 3,426,072 --a------ C:\SUPERXP\system32\d3dx9_32.dll 2007-06-03 03:33 251,672 --a------ C:\SUPERXP\system32\xactengine2_5.dll 2007-06-03 03:33 237,848 --a------ C:\SUPERXP\system32\xactengine2_4.dll 2007-06-03 03:33 236,824 --a------ C:\SUPERXP\system32\xactengine2_3.dll 2007-06-03 03:33 2,414,360 --a------ C:\SUPERXP\system32\d3dx9_31.dll 2007-06-03 03:33 15,128 --a------ C:\SUPERXP\system32\x3daudio1_1.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-30 10:16 15660320 --ahs---- C:\SUPERXP\system32\drivers\fidbox.dat 2007-07-30 10:15 61580 --ahs---- C:\SUPERXP\system32\drivers\fidbox2.idx 2007-07-30 10:15 601120 --ahs---- C:\SUPERXP\system32\drivers\fidbox2.dat 2007-07-30 10:15 219092 --ahs---- C:\SUPERXP\system32\drivers\fidbox.idx 2007-07-30 10:13 --------- d-------- C:\Program Files\FlashGet 2007-07-28 02:05 --------- d-------- C:\DOCUME~1\Komputer\DANEAP~1\Skype 2007-07-26 12:50 --------- d-------- C:\Program Files\eMule 2007-07-24 15:18 --------- d–h----- C:\Program Files\InstallShield Installation Information 2007-07-22 09:27 --------- d-------- C:\Program Files\BearShare 2007-07-21 00:50 --------- d-------- C:\Program Files\Gadu-Gadu 2007-06-05 21:59 --------- d-------- C:\DOCUME~1\Komputer\DANEAP~1\ATI 2007-06-05 02:19 78364 --a------ C:\SUPERXP\system32\perfc015.dat 2007-06-05 02:19 457416 --a------ C:\SUPERXP\system32\perfh015.dat 2007-06-03 10:50 108144 --a------ C:\SUPERXP\system32\CmdLineExt.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “smapp”=“C:\Program Files\Analog Devices\SoundMAX\SMTray.exe” [2003-05-05 08:57] “DAEMON Tools”=“C:\Program Files\DAEMON Tools\daemon.exe” [2006-11-12 12:48] “kis”=“C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe” [2006-03-24 20:09] “QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-03-27 19:49] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2004-08-25 12:52] “ATICCC”=“C:\Program Files\ATI Technologies\ATI.ACE\cli.exe” [2005-08-12 14:43] “Sony Ericsson PC Suite”=“C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe” [2005-10-26 16:17] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\SUPERXP\system32\ctfmon.exe” [2004-08-04 00:44] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-01-25 18:10:58] VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2005-08-30 14:45:01] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] “appinit_dlls”=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll R0 BTHidMgr;Bluetooth HID Manager Service;C:\SUPERXP\system32\Drivers\BTHidMgr.sys R0 gagp30kx;Filtr rodzajowy AGPv3.0 firmy Microsoft dla platform procesora K8;C:\SUPERXP\system32\DRIVERS\gagp30kx.sys R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x);C:\SUPERXP\system32\drivers\sfsync02.sys R0 sfvfs02;StarForce Protection VFS Driver (version 2.x);C:\SUPERXP\system32\drivers\sfvfs02.sys R0 viamraid;viamraid;C:\SUPERXP\system32\DRIVERS\viamraid.sys R1 AmdK8;Sterownik procesora AMD;C:\SUPERXP\system32\DRIVERS\AmdK8.sys R1 cdrbsdrv;cdrbsdrv;C:\SUPERXP\system32\drivers\cdrbsdrv.sys R1 oreans32;oreans32;??\C:\SUPERXP\system32\drivers\oreans32.sys R2 atksgt;atksgt;C:\SUPERXP\system32\DRIVERS\atksgt.sys R2 lirsgt;lirsgt;C:\SUPERXP\system32\DRIVERS\lirsgt.sys R2 SoundMAX Agent Service (default);SoundMAX Agent Service;C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe R3 adiusbaw;USB ADSL WAN Adapter;C:\SUPERXP\system32\DRIVERS\adiusbaw.sys R3 FETNDIS;Sterownik NT karty VIA PCI 10/100Mb Fast Ethernet;C:\SUPERXP\system32\DRIVERS\fetnd5.sys S1 aslm75;aslm75;??\C:\SUPERXP\system32\drivers\aslm75.sys S2 ADILOADER;General Purpose USB Driver (adildr.sys);C:\SUPERXP\system32\Drivers\adildr.sys S3 BlueletAudio;Bluetooth Audio Service;C:\SUPERXP\system32\DRIVERS\blueletaudio.sys S3 BT;Bluetooth PAN Network Adapter;C:\SUPERXP\system32\DRIVERS\btnetdrv.sys S3 Btcsrusb;Bluetooth USB For Bluetooth Service;C:\SUPERXP\system32\Drivers\btcusb.sys S3 BTHidEnum;Bluetooth HID Enumerator;C:\SUPERXP\system32\DRIVERS\vbtenum.sys S3 dtscsi;dtscsi;C:\SUPERXP\system32\Drivers\dtscsi.sys S3 ggsemc;Sony Ericsson USB Flash Driver;C:\SUPERXP\system32\DRIVERS\ggsemc.sys S3 GVCplDrv;GVCplDrv;C:\SUPERXP\system32\drivers\GVCplDrv.sys S3 k750bus;Sony Ericsson 750 driver (WDM);C:\SUPERXP\system32\DRIVERS\k750bus.sys S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter;C:\SUPERXP\system32\DRIVERS\k750mdfl.sys S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers;C:\SUPERXP\system32\DRIVERS\k750mdm.sys S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers;C:\SUPERXP\system32\DRIVERS\k750mgmt.sys S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers;C:\SUPERXP\system32\DRIVERS\k750obex.sys S3 KS-959;MA-620 USB Infrared Adapter;C:\SUPERXP\system32\DRIVERS\KS-959.sys S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service;“C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe” S3 MSIRCOMM;Microsoft IR Communications Driver;C:\SUPERXP\system32\DRIVERS\MSIRCOMM.sys S3 odserv;Microsoft Office Diagnostics Service;“C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE” S3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\SUPERXP\system32\Drivers\RootMdm.sys S3 SF-620;Kingsun SF-620 USB Infrared Adapter;C:\SUPERXP\system32\DRIVERS\SF-620.sys S3 TVicHW32;TVicHW32;??\C:\SUPERXP\system32\DRIVERS\TVicHW32.SYS S3 VComm;Virtual Serial port driver;C:\SUPERXP\system32\DRIVERS\VComm.sys S3 VcommMgr;Bluetooth VComm Manager Service;C:\SUPERXP\system32\Drivers\VcommMgr.sys ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-30 10:16:09 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00 scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-30 10:17:43 - machine was rebooted C:\ComboFix-quarantined-files.txt … 2007-07-30 10:17 — E O F —