“ťukasz” - 2007-05-10 21:07:54 Dodatek Service Pack 2 ComboFix 07-05.09.V - Running from: “D:\Downloads” ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-10 )))))))))))))))))))))))))))))))))) 2007-05-10 18:09 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-05-10 17:05 2007-05-10 01:03 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2007-05-10 00:18 2007-05-09 22:39 2007-05-09 13:35 2007-05-09 13:15 2007-05-08 22:36 2007-05-08 22:07 2007-05-08 21:57 2007-05-08 21:57 2007-05-08 21:57 2007-05-08 21:03 2007-05-08 20:36 2007-05-08 19:35 2007-05-08 17:39 2007-05-08 17:33 2007-05-08 17:26 2007-05-08 17:05 1,156 --a------ C:\WINDOWS\mozver.dat 2007-05-08 16:51 0 --a------ C:\WINDOWS\nsreg.dat 2007-05-08 16:37 87,768 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2007-05-08 16:37 108,168 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-05-08 16:37 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys 2007-05-08 16:37 2007-05-08 16:37 2007-05-08 14:49 2007-05-08 12:20 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-05-08 12:19 17,024 --a------ C:\WINDOWS\system32\drivers\usbohci.sys 2007-05-08 12:18 123,392 --a------ C:\WINDOWS\system32\dzip32.dll 2007-05-08 12:18 2007-05-08 12:18 2007-05-08 12:17 20,096 --a------ C:\WINDOWS\system32\drivers\PCASp50.SYS 2007-05-08 12:17 2007-05-08 12:17 2007-05-08 12:16 70,388 -ra------ C:\WINDOWS\system32\drivers\WS01UPH.BIN 2007-05-08 12:16 7,936 -ra------ C:\WINDOWS\system32\drivers\gtptser.sys 2007-05-08 12:16 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbser.sys 2007-05-08 12:16 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbmdm.sys 2007-05-08 12:16 65,152 --a------ C:\WINDOWS\system32\drivers\ewusbapp.sys 2007-05-08 12:16 53,248 -ra------ C:\WINDOWS\system32\drivers\CInsX500.dll 2007-05-08 12:16 53,040 -ra------ C:\WINDOWS\system32\drivers\nmwcdcls.dll 2007-05-08 12:16 4,990 -ra------ C:\WINDOWS\system32\drivers\PCX500MP.SYS 2007-05-08 12:16 4,960 -ra------ C:\WINDOWS\system32\drivers\nmwcdlog.dll 2007-05-08 12:16 38,656 -ra------ C:\WINDOWS\system32\drivers\ZD1UXP.SYS 2007-05-08 12:16 35 --a------ C:\WINDOWS\system32\RTELM.dll 2007-05-08 12:16 32,000 -ra------ C:\WINDOWS\system32\drivers\gtf32bus.sys 2007-05-08 12:16 280,576 -ra------ C:\WINDOWS\system32\drivers\Mrvw123.sys 2007-05-08 12:16 280,448 -ra------ C:\WINDOWS\system32\drivers\Mrvw125.sys 2007-05-08 12:16 18,944 -ra------ C:\WINDOWS\system32\drivers\gtscser.sys 2007-05-08 12:16 169,984 --a------ C:\WINDOWS\system32\drivers\pcx500.sys 2007-05-08 12:15 92,416 -ra------ C:\WINDOWS\system32\drivers\cfvn4c51.sys 2007-05-08 12:15 92,288 -ra------ C:\WINDOWS\system32\drivers\cfvn4c50.sys 2007-05-08 12:15 9,900 -ra------ C:\WINDOWS\system32\drivers\WCMLib2K.sys 2007-05-08 12:15 9,600 -ra------ C:\WINDOWS\system32\drivers\WCMLibXP.sys 2007-05-08 12:15 76,045 -ra------ C:\WINDOWS\system32\drivers\WCMBus2K.sys 2007-05-08 12:15 71,552 -ra------ C:\WINDOWS\system32\drivers\WCMBusXP.sys 2007-05-08 12:15 7,296 -ra------ C:\WINDOWS\system32\drivers\semwlntp.sys 2007-05-08 12:15 6,672 -ra------ C:\WINDOWS\system32\drivers\k600wh95.sys 2007-05-08 12:15 58,856 -ra------ C:\WINDOWS\system32\drivers\dpphys.sys 2007-05-08 12:15 57,536 -ra------ C:\WINDOWS\system32\drivers\WCMVmd2K.sys 2007-05-08 12:15 55,808 -ra------ C:\WINDOWS\system32\drivers\WCMVmdXP.sys 2007-05-08 12:15 52,864 -ra------ C:\WINDOWS\system32\drivers\GTEDGNet.sys 2007-05-08 12:15 51,328 -ra------ C:\WINDOWS\system32\drivers\uart0.sys 2007-05-08 12:15 5,744 -ra------ C:\WINDOWS\system32\drivers\k600whnt.sys 2007-05-08 12:15 4,480 -ra------ C:\WINDOWS\system32\drivers\g3grpm.sys 2007-05-08 12:15 368,896 -ra------ C:\WINDOWS\system32\drivers\semwl5.sys 2007-05-08 12:15 266,496 -ra------ C:\WINDOWS\system32\drivers\gtwl5.sys 2007-05-08 12:15 26,496 -ra------ C:\WINDOWS\system32\drivers\g3grumdm.sys 2007-05-08 12:15 258,560 -ra------ C:\WINDOWS\system32\drivers\MRV8K51.sys 2007-05-08 12:15 258,432 -ra------ C:\WINDOWS\system32\drivers\MRV8K50.SYS 2007-05-08 12:15 23,296 -ra------ C:\WINDOWS\system32\drivers\g3gruser.sys 2007-05-08 12:15 22,284 -ra------ C:\WINDOWS\system32\drivers\WcmSc2K.sys 2007-05-08 12:15 21,888 -ra------ C:\WINDOWS\system32\drivers\GTEDGSC.sys 2007-05-08 12:15 21,224 -ra------ C:\WINDOWS\system32\drivers\DPFDrv.sys 2007-05-08 12:15 21,120 -ra------ C:\WINDOWS\system32\drivers\WcmScXP.sys 2007-05-08 12:15 16,256 -ra------ C:\WINDOWS\system32\drivers\g3grsc.sys 2007-05-08 12:15 107,904 -ra------ C:\WINDOWS\system32\drivers\GTEDG.sys 2007-05-08 12:14 87,456 -ra------ C:\WINDOWS\system32\drivers\k600mdm.sys 2007-05-08 12:14 79,248 -ra------ C:\WINDOWS\system32\drivers\k600mgmt.sys 2007-05-08 12:14 77,952 -ra------ C:\WINDOWS\system32\drivers\nwusbmdm.sys 2007-05-08 12:14 77,072 -ra------ C:\WINDOWS\system32\drivers\k600obex.sys 2007-05-08 12:14 67,840 -ra------ C:\WINDOWS\system32\drivers\NWADIEnum.sys 2007-05-08 12:14 63,360 -ra------ C:\WINDOWS\system32\drivers\nwusbser.sys 2007-05-08 12:14 6,112 -ra------ C:\WINDOWS\system32\drivers\k600cmnt.sys 2007-05-08 12:14 6,096 -ra------ C:\WINDOWS\system32\drivers\k600mdfl.sys 2007-05-08 12:14 57,344 -ra------ C:\WINDOWS\system32\drivers\V620.dll 2007-05-08 12:14 53,248 -ra------ C:\WINDOWS\system32\drivers\GCXXNet.sys 2007-05-08 12:14 52,384 -ra------ C:\WINDOWS\system32\drivers\k600bus.sys 2007-05-08 12:14 50,206 -ra------ C:\WINDOWS\system32\drivers\Serialnw.sys 2007-05-08 12:14 45,161 -ra------ C:\WINDOWS\system32\drivers\GCXXLog.exe 2007-05-08 12:14 3,984 -ra------ C:\WINDOWS\system32\drivers\k600cr.sys 2007-05-08 12:14 269,056 -ra------ C:\WINDOWS\system32\drivers\NWVNdis.sys 2007-05-08 12:14 241,792 -ra------ C:\WINDOWS\system32\drivers\nw620.sys 2007-05-08 12:14 21,888 -ra------ C:\WINDOWS\system32\drivers\GCXXSC.sys 2007-05-08 12:14 114,944 -ra------ C:\WINDOWS\system32\drivers\GCXX.sys 2007-05-08 12:14 10,672 -ra------ C:\WINDOWS\system32\drivers\k600cm95.sys 2007-05-08 12:14 2007-05-07 22:55 2007-05-07 22:48 2007-05-07 22:48 2007-05-07 22:47 2007-05-07 22:37 2007-05-07 22:35 2007-05-07 22:35 2007-05-07 22:34 7,278 -ra------ C:\WINDOWS\system32\drivers\nmwcdc.sys 2007-05-07 22:34 50,688 --a------ C:\WINDOWS\system32\nmwcdcls.dll 2007-05-07 22:34 4,608 --a------ C:\WINDOWS\system32\nmwcdlog.dll 2007-05-07 22:34 30,720 --a------ C:\WINDOWS\system32\nmwcdcocls.dll 2007-05-07 22:34 128,797 -ra------ C:\WINDOWS\system32\drivers\nmwcd.sys 2007-05-07 22:34 10,991 -ra------ C:\WINDOWS\system32\drivers\nmwcdcm.sys 2007-05-07 22:34 10,991 -ra------ C:\WINDOWS\system32\drivers\nmwcdcj.sys 2007-05-07 22:34 2007-05-07 22:34 2007-05-07 22:34 2007-05-07 22:34 2007-05-07 22:34 2007-05-07 22:34 2007-05-07 22:33 2007-05-05 21:54 2007-05-02 12:07 17,920 --a------ C:\WINDOWS\system32\mdimon.dll 2007-05-02 12:05 2007-05-02 12:05 2007-05-02 12:04 2007-04-30 21:37 1,835,008 --ah----- C:\DOCUME~1\Ania\NTUSER.DAT 2007-04-30 21:37 2007-04-30 21:37 2007-04-30 21:37 2007-04-30 21:37 2007-04-30 21:37 2007-04-30 21:37 2007-04-30 21:37 2007-04-30 21:37 2007-04-30 18:39 (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-05-10 18:28:56 68,242 ----a-w C:\WINDOWS\system32\perfc015.dat 2007-05-10 18:28:56 438,056 ----a-w C:\WINDOWS\system32\perfh015.dat 2007-05-10 18:23:26 12 ----a-w C:\WINDOWS\bthservsdp.dat 2007-03-28 16:51:54 538,256 ----a-w C:\WINDOWS\system32\SymNeti.dll 2007-03-28 16:51:52 161,424 ----a-w C:\WINDOWS\system32\SymRedir.dll 2007-03-28 16:51:48 189,584 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys 2007-03-28 16:51:42 24,208 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys 2007-03-28 16:51:36 31,888 ----a-w C:\WINDOWS\system32\drivers\symids.sys 2007-03-28 16:51:32 28,304 ----a-w C:\WINDOWS\system32\drivers\symndis.sys 2007-03-28 16:51:26 97,936 ----a-w C:\WINDOWS\system32\drivers\symfw.sys 2007-03-28 16:51:20 12,944 ----a-w C:\WINDOWS\system32\drivers\symdns.sys 2007-03-17 13:45:36 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll 2007-03-08 15:38:48 579,072 ----a-w C:\WINDOWS\system32\user32.dll 2007-03-08 15:38:48 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll 2007-03-08 15:38:48 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll 2007-03-08 15:37:34 1,843,840 ----a-w C:\WINDOWS\system32\win32k.sys 2007-02-05 20:19:48 185,856 ----a-w C:\WINDOWS\system32\upnphost.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] “{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}”=“c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll” “{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}”=“C:\Program Files\Norton AntiVirus\NavShExt.dll” [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] “AzMixerSel”=“C:\Program Files\Realtek\InstallShield\AzMixerSel.exe” “SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” “IMJPMIG8.1”="“C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32" “MSPY2002”=“C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC” “PHIME2002ASync”=“C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC” “PHIME2002A”=“C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName” “PCMService”="“C:\Program Files\Acer\Acer Arcade\PCMService.exe”" “igfxhkcmd”=“C:\WINDOWS\system32\hkcmd.exe” “igfxpers”=“C:\WINDOWS\system32\igfxpers.exe” “eDataSecurity Loader”=“C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe” “ADMTray.exe”="“C:\Acer\Empowering Technology\admtray.exe”" “ntiMUI”=“C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe” “SkyTel”=“SkyTel.EXE” “Alcmtr”=“ALCMTR.EXE” “BluetoothAuthenticationAgent”=“rundll32.exe bthprops.cpl,BluetoothAuthenticationAgent” “ePower_DMC”=“C:\Acer\Empowering Technology\ePower\ePower_DMC.exe” “Acer ePower Management”=“C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot” “LManager”=“C:\PROGRA~1\LAUNCH~1\LManager.exe” “eRecoveryService”=“C:\Acer\Empowering Technology\eRecovery\Monitor.exe” “PCSuiteTrayApplication”=“C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup” “ccApp”="“C:\Program Files\Common Files\Symantec Shared\ccApp.exe”" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] “CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” “MSMSGS”="“C:\Program Files\Messenger\msmsgs.exe” /background" “RTEGPRS”="“C:\Program Files\Common Files\SmartCom\RTEGPRS.exe” tray" “Gadu-Gadu”="“C:\Program Files\Gadu-Gadu\gg.exe” /tray" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages msv1_0\0\0 Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages scecli\0\0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter HTTPFilter\0\0 LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService DnsCache\0\0 DcomLaunch DcomLaunch\0TermService\0\0 rpcss RpcSs\0\0 imgsvc StiSvc\0\0 termsvcs TermService\0\0 bthsvcs BthServ\0\0 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F] Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_INT15.SYS Contents of the ‘Scheduled Tasks’ folder C:\WINDOWS\tasks\Symantec NetDetect.job C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - ťukasz.job ******************************************************************** catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-10 21:09:58 Windows 5.1.2600 Dodatek Service Pack 2 FAT scanning hidden processes … scanning hidden services … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 2007-05-10 21:10:01 C:\ComboFix-quarantined-files.txt … 2007-05-10 21:10 C:\ComboFix2.txt … 2007-05-10 18:09